The UK’s National Cyber Security Centre (NCSC), working with the FBI and the Netherlands’ General Intelligence and Security Service (AIVD), has issued a joint warning about a spyware campaign attributed to Iranian state-linked actors.
According to the advisory, the campaign has targeted people viewed by Iran as critics or opponents of the government, including dissidents, activists and journalists. Targets have reportedly included individuals outside Iran, including in the United Kingdom.
The agencies said the operators use spear-phishing and social-engineering methods to persuade victims to install malware known as CHOSEN BRICK. Attackers have reportedly impersonated trusted contacts through services such as WhatsApp and Telegram, sometimes developing a relationship with targets before sending malicious files or links. Lures have been tailored to victims’ interests and, in at least some cases, have included fabricated medical documents.
Malware capabilities
The advisory says CHOSEN BRICK is designed for Windows systems and can remain active after a device is restarted. Once installed, it can collect data including contacts, email content and messages from social-media platforms. The malware can also capture screen activity and access a device’s microphone, the agencies said.
Officials warned that information taken from compromised devices has, in some instances, appeared on pro-Iranian leak sites. Such disclosures may increase risks to the safety and privacy of affected individuals.
Recommended precautions
The NCSC encouraged people who may face elevated surveillance risks to review the technical advisory and use available security support. Recommended steps include:
- Be cautious of unexpected messages, attachments and links, including those sent by apparent acquaintances.
- Confirm sensitive or unusual requests through a separate, trusted communication channel.
- Keep operating systems, browsers and security software updated.
- Use strong, unique passwords and enable multi-factor authentication where available.
- Seek specialist assistance if suspicious activity is identified on a device or account.
The NCSC said it assesses that Iran uses cyber operations to support repression of people considered threats to the regime. The joint publication provides indicators and mitigation guidance intended to help organizations and individuals detect potential compromise and reduce exposure to the campaign.
