The United States, United Kingdom and Netherlands have warned that Iranian state-linked cyber actors are using spyware to target dissidents, activists and journalists around the world.
The joint warning, issued on September 15, centers on a malware family called CHOSEN BRICK. The campaign has targeted people in the UK, U.S. and Netherlands and uses social engineering to persuade victims to open files or applications that appear legitimate.
A campaign built on trust
According to the UK’s National Cyber Security Centre, attackers have impersonated trusted contacts on WhatsApp and Telegram and built relationships with targets before delivering malicious files. Lures have included fake MRI results and software made to resemble legitimate applications.
The approach is designed to make the victim believe the file is relevant before the spyware is installed. The advisory says the malware has been observed exclusively on Windows systems and can remain active after a device is restarted.
What the spyware can access
CHOSEN BRICK can collect contacts, emails and social media messages. It can also capture screenshots and access a device’s microphone. Investigators say information taken from some victims has appeared on pro-Iranian leak sites.
The NCSC, FBI and Netherlands’ AIVD jointly published technical details and mitigation guidance. The NCSC assesses that Iran almost certainly uses cyber activity to support the repression of people viewed as threats to the Iranian government.
A wider security concern
The disclosure adds a cyber dimension to security concerns involving Iran and Western countries. It also comes amid a tense European security environment, including the recent NATO drone incident in Lithuania.
Officials are urging people who may be targeted to follow the technical guidance released with the advisory and seek specialist assistance if they suspect a device has been compromised.