Ncsc.Uk Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents
Article Content
- •CHOSEN BRICK spyware targets dissidents, activists, and journalists globally.
- •Attackers use social engineering via WhatsApp and Telegram to deliver malware.
- •Victims' personal details have been leaked on pro-Iranian sites, heightening risks.
On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram. Attackers impersonate trusted contacts to convince victims to download malicious files disguised as legitimate applications, including Norton Antivirus and KeePass. Once installed, CHOSEN BRICK can access sensitive information, including emails, contacts, and screen content, and can activate the device's microphone. The malware has been in use since at least 2025, and personal details of victims have appeared on pro-Iranian leak sites, increasing their risk. The advisory highlights the Iranian regime's use of digital surveillance to repress critics and outlines mitigation strategies for potential targets.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (85)
Following this threat?
Track Bad Rabbit, Apt32 and Fin13 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered external Teams tenants with names resembling internal IT departments to gain trust. The campaign…
Spearphishing Campaigns Exploit Malicious Links for User Execution Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information, including credentials. Notable threat actors such as APT28, APT29, and FIN7 have been identified as…