Skip to content
MarketsIndicesCommoditiesFXRates
Technology

UK, US, Netherlands Warn of Iran-Linked Spyware

UK, US and Dutch authorities warn that Iran-linked hackers used "CHOSEN BRICK" spyware to spy on dissidents, activists and journalists.

UK, US, Netherlands Warn of Iran-Linked Spyware

The United Kingdom, the United States and the Netherlands issued a joint cybersecurity alert on Tuesday warning of spyware they say is used by agents linked to the Iranian state to target dissidents, activists and journalists.

The UK's National Cyber Security Centre said Iranian state-linked cyber actors used a spyware family known as "CHOSEN BRICK" to steal emails, messages and other sensitive information through spear-phishing campaigns carried out on messaging platforms including WhatsApp and Telegram.

Paul Chichester, the National Cyber Security Centre's Director of Operations, said the details of the campaign showed how Iran ruthlessly uses digital surveillance to pursue its goal of suppressing critics of the regime, stealing emails and messages and gaining access to devices.

Iran's embassy in London did not immediately respond to a request for comment.

How the spyware works

According to the alert, the malware can collect information from contact lists, emails and social media accounts, capture content displayed on a screen, and access a device's microphone.

The National Cyber Security Centre said some victims' personal data later appeared on pro-Iran leak websites. The FBI, in its own alert, said Iran's Ministry of Intelligence and Security was using the malware to gather information, carry out data leaks and damage the reputations of its intended targets.

The FBI did not immediately respond to a request for further details on how many people were targeted or where they are located.

Fake MRI results used as bait

The National Cyber Security Centre said the attackers often posed as trusted contacts within messaging apps and tailored their approach to each individual target. In some cases, the agency said, they used fake documents, including falsified MRI scan results, to persuade victims to download the malware.

The National Cyber Security Centre, together with the FBI and the Dutch intelligence service AIVD, said Iran almost certainly uses cyber operations to help suppress people it views as threats.

Link to the Handala hacker

The FBI alert was described as an update to a warning issued in March 2026 that detailed the Ministry of Intelligence and Security's alleged efforts to use the malware to collect data on targets, information that was later published online by a hacker known as "Handala Hack".

Since the start of the war with Iran, Handala has targeted a number of companies and individuals in the United States. These include a destructive cyberattack in March against Stryker, a provider of medical supplies and services, and the leak that same month of personal emails belonging to FBI Director Kash Patel.

Handala did not respond to a request for comment sent by email.

Related

Leave a comment

Your email address will not be published. Required fields are marked *