Skip to content
UK, US and Netherlands warn over Iranian state spyware campaign

UK, US and Netherlands warn over Iranian state spyware campaign

Computerweekly September 15, 2026

Iranian state hackers are targeting dissidents, activists and journalists with spyware capable of tracking their movements, GCHQ’s National Cyber Security Centre has warned.

The Iranian spear-phishing campaign has targeted people around the world, including the UK, according to alerts from the UK’s National Cyber Security Centre (NCSC), the Netherlands and the USA.

Iranian cyber attackers have used social engineering techniques to persuade people to download files containing hidden malware which infects Windows based devices.

The malware, identified as Chosen Brick in the UK or Heavygram in the US has been used to target individuals in the UK, US and the Netherlands from at least 2025.

Personal information leaked

Once deployed it enables Iranian state cyber attackers to collect information a target’s contacts, emails and social media messages.

The personal details of victims have been published on pro-Iranian leak sites, potentially putting the personal safety of victims at risk.

According to UK intelligence assessments, Iran is almost certainly using cyber attacks to repress individuals seen as a threat to the regime.

In some cases, Iranian intelligence services have plotted to kidnap or conduct lethal operations against people they perceive as a threat outside of Iran.

Social engineering attack

Attackers victims through social media platforms and messaging services, such as WhatsApp, Telegram and Instagram, to build-up a rapport with victims before tricking them into downloading the malware.

The attackers have deep knowledge of the target and often purport to be an individual known to them or pose as technical support from the social media platform.

They used their relationship with the victim to persuade them to download what appear to be legitimate files.

Malicious files have been disguised as the AI video generating software Pictory, Norton Antivirus, the messaging app Telegram, or the password management tool KeePass. In other cases, malicious files have been disguised as MRI scan results.

The attackers often initiate using the target’s work device, but if that fails or is thought too risky, they will attempt to ask the target to open files on their own devices to bypass corporate security, according to the NCSC’s advisory.

Once downloaded, the malware connects to the messaging app Telegram to receive instructions. Each compromised device connects to a different Telegram Bot ID to reduce the risk of detection.

The malware has the capability to download additional malware files to the infected machine but has so far not been observed trying to spread to other machines.

It can be tasked with capturing the content of screens, enabling a microphone to capture audio, or capturing Telegram and WhatsApp data from browsers.

It can also delete files, steal the content of emails and wipe the infected computer system.

Ruthless digital survieillance

Paul Chichester, NCSC Director of Operations, said that the UK would continue to call out malicious cyber activity by the Iranian state.

“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” he added.

Advice on how to detect the Iranian malware can be found here and here .

NCSC: No increase in cyber threat from Iran, but be prepared - While cyber threat levels remain stable following the outbreak of war in the Middle East at the weekend, at-risk organisations in the UK should take steps to ward off potential reprisals from Iran-linked threat actors

US CISA agency extends Iran cyber alert, warns of CNI threat - The US Cybersecurity and Infrastructure Security Agency reiterates guidance for operators of critical national infrastructure as it eyes the possibility of cyber attacks from Iran

Iranian hacktivists muster their forces but state APTs lay low - Hacktivist activity surrounding the Iran war is sky-high but Iran’s state-backed cyber espionage actors have yet to show their hands, giving security teams a valuable window of time to shore up their defences

Nation states responsible for ‘nationally significant’ cyber attacks against UK, says NCSC chief By: Bill Goodwin

News brief: Iran cyberattacks escalate, U.S. targets named By: Staff report

UK Cyber Monitoring Centre plans expansion in US amid risk of Category 5 attack By: Bill Goodwin

Cisa tells US organisations to harden endpoint management after Stryker attack By: Alex Scroxton

CIOs looking for ways to say yes to the iPad in the enterprise CIOs are looking for ways to say yes to the iPad in the enterprise, despite the technological and cultural challenges associated ...

CIOs are looking for ways to say yes to the iPad in the enterprise, despite the technological and cultural challenges associated ...

What CISOs should take from the Hugging Face-OpenAI incident Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems ...

Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems ...

Red agents vs. blue agents: How to make AI better at defense The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their ...

The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their ...

When AppSec scanners become a supply chain attack vector New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for ...

New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for ...

5G Quiz - Can you speak 5G? -generation 5G wireless technology will offer faster speeds and increased capacity. Do you speak the language well enough to ...

-generation 5G wireless technology will offer faster speeds and increased capacity. Do you speak the language well enough to ...

5G expansion is coming, but where will operators reap profits? In this recap of industry blogs, networking pundits examine the profit potential of 5G expansion, responsible use of AI and some ...

In this recap of industry blogs, networking pundits examine the profit potential of 5G expansion, responsible use of AI and some ...

5G, cloud embolden network outsourcing and ultimate virtualization Could the cloud, 5G, small cell technology, BYOD and carrier-provisioned networks completely virtualize network infrastructure? ...

Could the cloud, 5G, small cell technology, BYOD and carrier-provisioned networks completely virtualize network infrastructure? ...

Distributed computing: The infrastructure shift AI demands The hyperscale era is ending. AI's energy and latency demands are driving infrastructure toward the edge -- closer to users, ...

The hyperscale era is ending. AI's energy and latency demands are driving infrastructure toward the edge -- closer to users, ...

Why and the NSA love graph databases Graph databases play six degrees of separation to find real connections. See how IT teams can use the database approach for ...

Graph databases play six degrees of separation to find real connections. See how IT teams can use the database approach for ...

DevOps and Agile IT save mainframe training from skills quagmire The problem isn't that new hires aren't familiar with the complex, custom daily tasks of mainframe ops. The problem is that ...

The problem isn't that new hires aren't familiar with the complex, custom daily tasks of mainframe ops. The problem is that ...

HR makes major strides toward improving employee engagement

Cloud vs. legacy ERP systems: Tug of war intensifies for SMBs Aging legacy ERP systems at SMBs seem to be getting plenty of scrutiny these days. Heightened consumer demands, shifting ...

Aging legacy ERP systems at SMBs seem to be getting plenty of scrutiny these days. Heightened consumer demands, shifting ...

Develop smart AI in CRM strategies to win and keep customers Of the three words that comprise customer relationship management , one word binds the other two. As necessity and ...

Of the three words that comprise customer relationship management , one word binds the other two. As necessity and ...