News
Global Headlines
Iran-linked hackers use 'Chosen Brick' spyware to target journalists, activists

Just Earth News | @justearthnews | 18 Sep 2026, 05:36 am Print

Iran-linked hackers use 'Chosen Brick' spyware to target journalists, activists Iran

UK, US Netherlands issue advisory on Iran-linked spyware. Photo: Pixabay

Britain, the United States and the Netherlands have issued a joint advisory warning about spyware allegedly used by Iranian state-linked actors to target dissidents, activists and journalists around the world.

Britain’s National Cyber Security Centre (NCSC) has shared details of how Iranian state-backed cyber actors have been observed attempting to trick targets into downloading software capable of tracking their movements.

“Dissidents, activists and journalists around the world, including in the UK, that are perceived to pose a threat to Iran are among those that have been targeted with the spyware dubbed ‘CHOSEN BRICK’,” the NCSC said in an official statement.

Chosen Brick enables attackers to collect information from a target’s contacts, emails and social media messages. It also has capabilities to capture screen content and access a device’s microphone.

A new joint advisory issued by the NCSC and its international partners said Iranian state actors have been observed impersonating contacts on messaging platforms such as WhatsApp and Telegram. They allegedly build rapport with targets before deploying  Chosen Brick and stealing sensitive information, some of which has subsequently appeared on leak sites.

According to the advisory, the actors tailor their social-engineering attempts to areas of relevance or interest to their targets. In some cases, they have reportedly used fake MRI test results to lure victims.

The British government said attempts by foreign powers to intimidate, harass, surveil or otherwise target individuals in the UK “will never be tolerated”.

It said security support and practical guidance are available for people at risk of transnational repression, including measures to protect themselves both online and in person.

Specialist training on identifying state-threat activity has been rolled out across all UK police forces. The government said law enforcement and intelligence agencies have the powers needed to detect and disrupt such activity and will take action against perpetrators.

“We will continue to call out malicious cyber activity by the Iranian state and support communities with practical advice to strengthen their online personal security,” Paul Chichester, NCSC Director of Operations, said.

The NCSC said it assesses that Iran “almost certainly” uses cyber activity to support the repression of individuals viewed as threats to the regime.

Personal details of some previous victims have appeared on pro-Iranian leak sites, potentially increasing the risks to their personal safety, the agency said.

To reduce the risk of compromise, the NCSC has advised individuals who may be targeted to follow the mitigation measures outlined in its advisory and seek dedicated support available to high-risk individuals, including free cyber-defence services.

The malware has so far been exclusively used against devices running the Windows operating system. The advisory warns that CHOSEN BRICK is persistent and can survive a reboot of an infected device.