Home / News

UK, US and Dutch Agencies Expose Iranian Spyware Targeting Dissidents and Journalists

Britain, the United States and the Netherlands have disclosed a spyware campaign they attribute to Iranian state actors, detailing how malware delivered through highly targeted social engineering has been used to monitor dissidents, activists and journalists around the world.

The UK’s National Cyber Security Centre (NCSC), the FBI and the Netherlands’ General Intelligence and Security Service (AIVD) issued a joint advisory on September 15 describing a Windows malware family the NCSC calls CHOSEN BRICK. The FBI separately tracks the malware as HEAVYGRAM and attributes its use to Iran’s Ministry of Intelligence and Security (MOIS).

The campaign relies heavily on personalized deception rather than software exploits. Attackers research intended victims, then approach them through services including WhatsApp and Telegram while posing as trusted contacts or technical support. After establishing rapport, they persuade targets to open malicious files disguised as legitimate applications or documents. Observed lures have impersonated Telegram, Norton Antivirus, KeePass, Pictory and RunwayML; some were presented as MRI scan results.

The malware has been observed exclusively on Windows. Once installed, CHOSEN BRICK can establish persistence so that it survives a reboot and can add exclusions to Microsoft Defender. It communicates with its operators through Telegram bots, with a separate bot identifier used for individual victims.

Its surveillance capabilities extend well beyond stealing files. The malware can capture screenshots and microphone audio, retrieve emails and browser-accessible Telegram and WhatsApp data, enumerate system information, download additional malware and, in at least one analyzed sample, wipe data. The agencies said information collected from infected devices can reveal a victim’s contacts, location and patterns of activity.

Some stolen personal information has subsequently appeared on pro-Iranian leak sites, according to the advisory. The NCSC assesses that Iran “almost certainly” uses cyber operations to support repression of people it regards as threats. Reuters reported that Iran’s embassy in London did not immediately respond to a request for comment on the allegations.

The advisory also highlights a route around corporate security controls. Iranian operators have sometimes contacted targets initially through work devices and, when delivery failed or risked detection, encouraged them to open the files on personal computers instead. The agencies recommend that organizations whose employees may be targeted extend security awareness and compromise checks to personal devices where possible.

The NCSC has published indicators of compromise and detection guidance alongside recommendations including phishing-resistant multi-factor authentication, application allowlisting, endpoint and network monitoring, current antivirus protection and automatic software updates.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By CircleID Reporter

CircleID’s internal staff reporting on news tips and developing stories. Do you have information the professional Internet community should be aware of? Contact us.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

New TLDs

Sponsored byRadix

Domain Names

Sponsored byVerisign

DNS Security

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC

DNS

Sponsored byDNIB.com

IPv4 Markets

Sponsored byIPv4.Global

Cybersecurity

Sponsored byVerisign