UK, US and Dutch Agencies Warn of Iranian Spyware Targeting Regime Critics
The UK's National Cyber Security Centre, the FBI and the Netherlands' AIVD have published a joint advisory warning that Iranian state-backed actors are running a spyware campaign targeting critics of the regime, including dissidents, activists and journalists. In some cases, stolen data has surfaced on pro-Iranian leak sites, increasing personal safety risks for victims.
The spyware, known as Chosen Brick, harvests contacts, emails and social media messages to track targets' movements and enable further repression. It uses Windows registry keys to persist on infected devices and adds exclusions to Microsoft Defender to avoid detection. It communicates with attackers through Telegram and can capture screens, steal WhatsApp and Telegram browser data, read emails, activate device microphones, delete files, download further malware, and even wipe entire systems.
The malware spreads through social engineering. Attackers build rapport with targets on social media, often posing as a contact or technical support representative, before persuading them to download seemingly legitimate apps or files such as photo editing tools, antivirus software, or fake medical scans. The agencies are urging at-risk individuals to learn these tactics and follow the advisory's mitigation guidance, and for organisations that suspect infection to contact their IT provider immediately.