Skip to content
Iranian Cyber Actors Deploy CHOSEN BRICK Spyware Against Dissidents

Iranian Cyber Actors Deploy CHOSEN BRICK Spyware Against Dissidents

First seen 15 Sep 2026, 15:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 17:55 UTC
  • CHOSEN BRICK spyware targets dissidents and journalists globally.
  • Attackers use social engineering via WhatsApp and Telegram to deliver malware.
  • Iran's cyber operations aim to suppress critics of the regime.

On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding the CHOSEN BRICK malware, used by Iranian state-linked actors to target dissidents, activists, and journalists. This spyware is delivered through spear-phishing campaigns on messaging platforms like WhatsApp and Telegram, enabling attackers to steal sensitive information such as emails, messages, and contacts. The malware can also capture screen content and activate device microphones. The advisory highlights that the Iranian regime utilizes such cyber operations to suppress perceived threats, with some victims' personal details appearing on pro-Iranian leak sites. The campaign has been active since at least 2025, with a focus on individuals in the UK, US, and the Netherlands. Attackers often impersonate trusted contacts to build rapport before delivering the malware disguised as legitimate software. The FBI attributes the malware to Iran's Ministry of Intelligence and Security (MOIS).

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-08
CVE-2025-0282 published
CVE-2025-0282 was published, related to a vulnerability exploited by malware.
N/A
2026-03-01
First alert on CHOSEN BRICK
The FBI issued an initial alert detailing the CHOSEN BRICK malware campaign targeting dissidents.
Thehackernews
2026-09-15
Joint advisory issued
The UK, US, and Netherlands released a joint advisory on CHOSEN BRICK, detailing its capabilities and targets.
Ncsc.Uk

More articles in this cluster (18)

Following this threat?

Track Black Basta, Apt32 and Fin13 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed