Ncsc.Uk Iranian Cyber Actors Deploy CHOSEN BRICK Spyware Against Dissidents
Article Content
- •CHOSEN BRICK spyware targets dissidents and journalists globally.
- •Attackers use social engineering via WhatsApp and Telegram to deliver malware.
- •Iran's cyber operations aim to suppress critics of the regime.
On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding the CHOSEN BRICK malware, used by Iranian state-linked actors to target dissidents, activists, and journalists. This spyware is delivered through spear-phishing campaigns on messaging platforms like WhatsApp and Telegram, enabling attackers to steal sensitive information such as emails, messages, and contacts. The malware can also capture screen content and activate device microphones. The advisory highlights that the Iranian regime utilizes such cyber operations to suppress perceived threats, with some victims' personal details appearing on pro-Iranian leak sites. The campaign has been active since at least 2025, with a focus on individuals in the UK, US, and the Netherlands. Attackers often impersonate trusted contacts to build rapport before delivering the malware disguised as legitimate software. The FBI attributes the malware to Iran's Ministry of Intelligence and Security (MOIS).
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Following this threat?
Track Black Basta, Apt32 and Fin13 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Qilin Ransomware Targets Retelit, Major Telecom Provider in Italy The Qilin ransomware group has reportedly targeted Retelit SpA, a leading telecommunications operator in Italy. This attack is part of a broader campaign that has seen a significant increase in ransomware incidents attributed to Qilin since the start of 2026. The group exploits known vulnerabilities, particularly in…