The UK's National Cyber Security Centre (NCSC) has joined international intelligence partners to warn of an Iranian state-backed cyber campaign using sophisticated spear-phishing techniques and spyware to target dissidents, activists and journalists around the world.
In a joint advisory published with the US Federal Bureau of Investigation and the Netherlands' General Intelligence and Security Service, the agencies detailed the use of spyware known as CHOSEN BRICK, which has been deployed to collect sensitive information from individuals perceived by Iran to pose a threat to the regime.
According to the advisory, Iranian cyber actors have impersonated trusted contacts on messaging platforms including WhatsApp and Telegram, building relationships with victims before persuading them to download malicious software.
The attackers have also tailored phishing lures to individual targets, including sending fake MRI test results and other personalised content designed to increase the likelihood of infection.
Once installed, CHOSEN BRICK enables attackers to access emails, contacts and social media messages, capture screenshots, activate a device's microphone and collect messaging histories. The malware is persistent, meaning it survives a reboot, and has been observed targeting Windows devices.
The NCSC said the campaign forms part of Iran's broader use of cyber operations to monitor and suppress critics of the regime.
The advisory warns that information stolen during previous campaigns has appeared on pro-Iranian leak sites, potentially increasing the personal safety risks faced by victims.
The UK government said it would not tolerate attempts by foreign states to intimidate, harass or surveil people living in the UK. It added that practical guidance is available online for those who believe they may be at risk of transnational repression, while specialist training on identifying state threats has been rolled out across all UK police forces.
The NCSC is encouraging individuals who may be at heightened risk to follow the mitigation advice outlined in the advisory and to enrol in its free cyber defence services designed to help protect high-risk users from targeted attacks.
Paul Chichester, director of operations at the NCSC, said: “With our international partners, we strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice.
“We will continue to call out malicious cyber activity by the Iranian state and support communities with practical advice to strengthen their online personal security.”
Josiah Smith, director of operations at security firm OPSWAT said the malware fits a pattern associated with Iranian state-linked operators for years.
“What stands out here is the lure quality (fabricated MRI results is a level of tailoring that takes real reconnaissance on the victim) and that this is a Windows-only surveillance tool with live screen and microphone capturer,” he added.
“That combination, long-con impersonation plus full desktop surveillance, is consistent with the toolset Iran's intelligence services use specifically against dissidents, journalists and activists abroad, where the goal is identifying who someone is talking to and what they're saying, not just breaching an account.”









Recent Stories