Skip to content
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and ...

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and ...

Ncsc.Uk September 15, 2026

GCHQ’s National Cyber Security Centre and international partners issue warning over Iranian cyber actors’ spear-phishing and spyware campaign

CHOSEN BRICKmalware family used to collect information, including screen captures and messaging history, from targets around the world

UK and allies provide advice to help organisations and individuals at risk detect malicious activity and reduce chances of their devices falling victim

INDIVIDUALS at risk of digital surveillance by the Iranian regime are being provided with fresh advice today (Tuesday) to help them identify and counter the threat from spear-phishing and spyware attacks.

The UK National Cyber Security Centre – a part of GCHQ – alongside partners in the US and the Netherlands has shared details how Iranian state cyber attackers have been observed trying to trick targets into downloading software that can enable tracking of their movements.

Dissidents, activists and journalists around the world, including in the UK, that are perceived to pose a threat to Iran are among those that have been targeted with the spyware dubbed ‘CHOSEN BRICK’.

CHOSEN BRICK allows attackers to collect information on a target’s contacts, emails and social media messages, and includes functionality to capture screen content and access the device microphone.

A new joint advisory from the NCSC and partners says Iranian state actors have been observed impersonating contacts over messaging apps such as WhatsApp and Telegram, building rapport with targets before deploying CHOSEN BRICK, and stealing sensitive information, which has appeared on leak sites.

The actors are known to tailor their social engineering to include areas of relevance or interest to their targets and have even included fake MRI test results to lure victims in.

The government has been clear that any attempt by a foreign power to intimidate, harass, surveil, or otherwise target individuals in the UK will never be tolerated.

In addition to security support for those at risk, clear guidance is available online , giving those who believe themselves to be at risk of transnational repression more widely practical steps to protect themselves - both in person and online.

Specialist training on how to spot state threats activity has been rolled out across all UK police forces and, along with our intelligence agencies, they have the powers they need to detect and disrupt any such activity and will use the full force of the law against any perpetrators.

The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices. “With our international partners, we strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice. “We will continue to call out malicious cyber activity by the Iranian state and support communities with practical advice to strengthen their online personal security. Paul Chichester, National Cyber Security Centre Director of Operations

The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices.

“With our international partners, we strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice.

“We will continue to call out malicious cyber activity by the Iranian state and support communities with practical advice to strengthen their online personal security.

The NCSC assesses that Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime.

Personal details of some victims have appeared on pro-Iranian leak sites, potentially increasing the risk to personal safety of those affected.

To reduce the chances of compromise, the NCSC recommends individuals at risk to follow the mitigation steps in the advisory and to take up the NCSC’s dedicated support for high-risk individuals , including signing up for free cyber defence services.

The malware has been exclusively targeted at the Windows operating system. The advisory warns CHOSEN BRICK is persistent and will survive a reboot of the target device.

The new advisory has been produced by the NCSC, the US Federal Bureau of Investigation and the Netherlands' General Intelligence and Security Service - Algemene Inlichtingen- en Veiligheidsdienst (AIVD).

The FBI has published further technical analysis of the malware in a new report today:

What to do when cyber attacks disrupt your organisation

How to recover from disruption, get ready for future incidents and make them less likely.

Iranian cyber targeting of dissidents, activists and journalists

Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.

International cyber agencies fresh advice to defend against China-linked covert networks

New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.

Extracted Entities

Attack Types (2)

Countries (2)

Malware (1)

MITRE ATT&CK (1)