Back Middle-East-Online UK, US and Netherlands issue advisory on Iran spyware
LONDON - Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by Iranian state-linked actors to target dissidents, activists and journalists.
Britain's National Cyber Security Centre said Iranian state-linked cyber actors had used a spyware family known as "CHOSEN BRICK" to steal emails, messages and other sensitive information through "spear-phishing" campaigns on messaging platforms including WhatsApp and Telegram.
According to security officials, the hackers routinely established direct with victims by impersonating trusted acquaintances, technical support personnel, or professional peers. Over extended interactions, the operatives worked to build personal rapport before tricking targets into downloading malicious files containing the CHOSEN BRICK malware.
Once executed on a target machine—primarily Windows-based systems—the spyware achieves persistence, allowing it to survive device reboots. From there, operators gained deep access into compromised environments, enabling them to harvest emails, extract private messaging histories, capture real-time screen activity, and covertly activate device microphones.
NCSC Director of Operations Paul Chichester stressed that the campaign demonstrates how digital surveillance has become central to state- repression abroad.
Western intelligence agencies assessed that Tehran almost certainly relies on these targeted intrusions to track perceived political opponents and disrupt independent reporting.
Allied cybersecurity authorities have urged high-risk individuals, media organizations, and civil society groups to enforce robust credential hygiene and scrutinize unsolicited files received through encrypted messaging platforms.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
