British intelligence warns of Iranian spyware targeting dissidents
NCSC and international allies uncover 'Chosen Brick' malware campaign used to track activists and journalists
Quick Look
- The UK's National Cyber Security Centre has warned that Iranian state actors are using 'Chosen Brick' spyware to target dissidents, journalists, and activists.
- The malware, active since autumn 2023, enables surveillance of devices and data theft via social engineering.
AI-generated summary
Why It Matters
The NCSC is part of GCHQ and monitors state-sponsored cyber threats. Hostile states have increasingly targeted UK critical infrastructure over the past year.
British intelligence has issued a warning after finding Iranian spies have targeted dissidents with spyware that can enable tracking of their movements.
Dissidents, activists and journalists were targeted by state actors that impersonated their contacts on messaging apps to trick them into downloading spyware called Chosen Brick, the National Cyber Security Centre, part of GCHQ, warned.
The malware gave agents access to the person’s contacts, emails and social media messages as well as a device’s microphone and content on the screen.
The UK, alongside allies in the US and the Netherlands, discovered the plot which is targeting both British dissidents and others from a range of different countries. It remains unclear how many people were affected by the malware, although the FBI claimed that cyber actors had used the malware dating back to Autumn 2023.
Iranian agents used social engineering tricks to tailor their impersonations to areas of relevance or interest to their targets; in one instance, fake MRI test results lured a victim in.
The malware, targeting Windows operating systems, will survive a device being rebooted. Some stolen personal details have been posted on pro-Iranian leak sites, the NCSC said.
Paul Chichester, NCSC director of operations, said that the cyber campaign showed Iran’s ruthless use of digital surveillance to target dissidents.
“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” he said.
“With our international partners, we strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice.
“We will continue to call out malicious cyber activity by the Iranian state and support communities with practical advice to strengthen their online personal security.”
The FBI issued its own advisory, and claimed the Iran government’s Ministry of Intelligence and Security (MOIS) was using the malware to “collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets.”
Detailed technical advice about the malware was published on the NCSC website, as well as how to avoid falling prey to them.
Over the summer, NCSC chief Richard Horne warned that hostile states, such as Russia, China and Iran, were increasingly targeting the UK’s critical systems.
He said that three-quarters of cyber attacks impacting organisations within the UK’s critical infrastructure over the past year could be linked back to hostile state actors.
Open Questions
- How many individuals have been successfully compromised by Chosen Brick?
- What specific countermeasures are recommended for high-risk individuals?





