Back Infosecurity-Magazine NCSC and Allies Warn of Iranian Spyware Campaign
The UK and its allies have warned opponents of the Iranian regime that they may be subject to targeting by a Tehran-backed spyware campaign.
An advisory published yesterday by the National Cyber Security Centre (NCSC), the FBI and the Netherlands' General Intelligence and Security Service (AIVD) is designed to help dissidents, activists and journalists critical of the regime.
It warned that, in some cases, information stolen by the spyware has appeared on pro-Iranian leak sites, increasing the risk to victims’ personal safety.
“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” said NCSC director of operations, Paul Chichester.
“With our international partners, we strongly encourage individuals at risk to familiarize themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice.”
The campaign itself revolves around the delivery of Chosen Brick: spyware designed to harvest targets’ contacts, emails and social media messages, to enable tracking of their movements, repression or worse.
The malware itself uses Windows registry keys for persistence and adds exclusions to Microsoft Defender antivirus in order to evade detection, the report revealed.
It connects to Telegram for command & control (C2) and has a wide variety of functionality including enumeration of running processes and system info, screen capture, harvesting Telegram and WhatsApp data from browsers, stealing emails and enabling the device mic for audio capture.
It can also delete files, download additional malware, and wipe the entire system, the NCSC said.
Chosen Brick is delivered via social engineering. The threat actor builds rapport with their victim on social media – usually by impersonating a or social messaging technical support. Then they persuade the victim to download a legitimate app (eg Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player) or file (e.g. MRI scan).
The advisory urged organizations concerned infection to internal or external IT providers to investigate.
“As this actor targets personal devices, not just corporate devices, organizations are recommended to circulate this with their staff that are likely to be targeted and support them in checking their personal devices too,” it added.
On the plus side, the spyware interacts with numerous legitimate web services, so it’s likely to appear in corporate logs through DNS and web proxy services, the NCSC noted.
Best practice mitigations include:
Following NCSC advice on staying safe online , such as not clicking on download links or attachments
Switching on automatic updates for device OS and software
Enabling trusted AV and ensuring it’s up to date
Not disabling or ignoring smart screen warnings on file downloads
Network admins should also consider enabling phishing-resistant MFA, managing and protecting device fleets with AV, app allowlisting and other controls, and installing endpoint and network monitoring, the report advised.
The campaign has been running since at least 2025, the NCSC said.
UK and US Warn of Growing Iranian Spear Phishing Threat News 30 September 2024
UK and US Warn of Growing Iranian Spear Phishing Threat
NCSC: Iranian and Russian Groups Targeting Government, Activists and Journalists With Spearphishing News 26 January 2023
NCSC: Iranian and Russian Groups Targeting Government, Activists and Journalists With Spearphishing
NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts News 2 April 2026
NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts
NCSC Warns of Spyware Targeting Chinese and Taiwanese Diaspora News 9 April 2025
NCSC Warns of Spyware Targeting Chinese and Taiwanese Diaspora
Meta Takes Down Over 200 Covert Influence Operations Since 2017 News 19 December 2022
Meta Takes Down Over 200 Covert Influence Operations Since 2017
What’s Hot on Infosecurity Magazine?
Microsoft Releases Emergency Patch to Fix RDS Vulnerability
Revolut Confirms Data Breach Through Fake Government Requests
Hackers Exploit Maximum Severity Flaw in GitLab
OpenAI Agent Swarm Hacks RubyGems Package Manager
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Anthropic Reveals Yet Another Cybersecurity Incident
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
NHIs Now the Number One Corporate Entry Point for Hackers
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How To Enhance Security Operations with AI-Powered Defenses
How to Manage Enterprise Cyber Resilience in the Age of AI
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
