Posted

UK, US and Netherlands warn of Iran-linked spyware

On Tuesday, 15 September, the United Kingdom, the United States and the Netherlands issued a joint cybersecurity advisory detailing spyware they say is used by Iran-linked actors in attacks. National Cyber Security Centre (NCSC) announced the warning.

According to the joint advisory from the NCSC, the FBI and the Dutch intelligence service AIVD, Iranian state or state-linked cyber actors are using a spyware family known as CHOSEN BRICK. The campaign targets dissidents, activists and journalists. Attacks are carried out through spear-phishing on messaging platforms including WhatsApp and Telegram.

The malware can collect contacts, emails and social media data, capture screen content and access a device’s microphone. Some stolen personal details later appeared on pro-Iranian leak sites. Attackers often posed as trusted contacts and tailored messages to individual targets. In some cases they sent fake documents, including fabricated MRI results, to persuade victims to install the malicious file.

“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” said Paul Chichester, NCSC Director of Operations.

The agencies said Iran “almost certainly” uses cyber operations to help suppress people it sees as threats to the regime. According to the FBI, Iran’s Ministry of Intelligence and Security (MOIS) is involved in the campaign. Iran’s embassy in London did not immediately comment.

Security services advise potential targets to be cautious with unexpected messages and links in messengers and not to open attachments from unknown or suspicious senders.