Spyware Surge: Iranian Cyber Tactics Unveiled

The UK, US, and Netherlands released a joint advisory about Iranian state-linked spyware used to target dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, infiltrates messaging platforms, compromising sensitive information. Cyber actors pose as trusted contacts to install the virus, as Iran reportedly uses these tactics to quell regime critics.

Spyware Surge: Iranian Cyber Tactics Unveiled
This image is AI-generated and does not depict any real-life event or location. It is a fictional representation created for illustrative purposes only.

The governments of Britain, the United States, and the Netherlands have issued a joint cybersecurity advisory. It details the use of spyware by Iranian state-linked actors targeting dissidents, activists, and journalists worldwide. This spyware, called 'CHOSEN BRICK', operates through spear-phishing campaigns on messaging platforms like WhatsApp and Telegram.

Paul Chichester, Britain's National Cyber Security Centre director of operations, stated that Iranian cyber actors exploit this digital surveillance tactic to suppress regime critics by stealing emails, messages, and accessing personal devices. Iran's embassy in London did not respond to requests for comment on these allegations.

The advisory warns that the malware collects data from contact lists, emails, and social media accounts, even capturing screen content and accessing device microphones. The FBI has confirmed that Iran's Ministry of Intelligence and Security employs these cyber operations to gather intelligence, orchestrate data leaks, and inflict reputational damage on its targets.

Give Feedback

Use this form for editorial or site feedback. We usually reply within 2 to 3 working days.

By submitting, you agree that we may use your email address to respond.