UK, US and Netherlands issue advisory on Iran spyware
- On Tuesday, Britain, the United States, and the Netherlands issued a joint cybersecurity advisory detailing spyware known as "CHOSEN BRICK" used by Iranian state-linked actors to target dissidents, activists, and journalists.
- Attackers often pose as trusted contacts on WhatsApp and Telegram, using fake documents including fabricated MRI results to conduct spear-phishing campaigns and persuade victims to download the malware.
- The FBI stated Iran's Ministry of Intelligence and Security uses the malware to collect intelligence and inflict reputational harm, with victim details appearing on pro-Iranian leak sites linked to "Handala Hack."
- NCSC director of operations Paul Chichester stated Iran "almost certainly" uses cyber operations to suppress perceived threats, stealing emails and messages to repress critics of the regime.
- Since the start of the Iran war, the persona "Handala" has targeted multiple United States entities, including a destructive cyberattack against Michigan-based supplier Stryker and the leak of FBI Director Kash Patel's emails.
85 Articles
85 Articles
Iran is using spyware to collect sensitive information about Iranians living in the West who are critical of the Iranian regime. The AIVD, together with the American and British intelligence services, warns of this. They are targeting dissidents, activists, and journalists. According to cybersecurity expert Lisa de Wilde, these involve highly targeted attacks in which victims are approached via social media.
Iran using spyware to gather information on dissidents living in the West: AIVD
Iran is using spyware to gather sensitive information about people critical of the regime living in the West, the Dutch intelligence agency said in a joint warning with the American FBI and British NCSC. Several dissidents’ stolen personal data have appeared on pro-Iran websites, NOS reports.
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
Iranian operators tied to Telegram-based malware targeting activists
A new malware campaign used Telegram as command-and-control infrastructure to surveil dissidents and journalists. The activity is attributed to Iranian hackers and centered on espionage, with targets drawn from politically sensitive civilian...
Coverage Details
Bias Distribution
- 44% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium
































