Header image

Iran-backed spyware campaign targets UK dissidents and activists

The UK and its allies have issued a warning to opponents of the Iranian regime, alerting them to a potential targeting by a Tehran-backed spyware campaign. The advisory, published by the National Cyber Security Centre (NCSC), the FBI, and the Netherlands' General Intelligence and Security Service (AIVD), aims to assist dissidents, activists, and journalists critical of the regime, according to Infosecurity Magazine.

The campaign utilizes spyware known as Chosen Brick, designed to harvest contacts, emails, and social media messages, and track victims' movements. The malware employs social engineering tactics, with threat actors impersonating contacts or technical support to persuade victims into downloading malicious applications or files. 

Once installed, Chosen Brick can enumerate processes, capture screens, steal data from messaging apps like Telegram and WhatsApp, harvest emails, and activate the device microphone. It also has the capability to delete files, download further malware, and wipe the entire system. The spyware evades detection by using Windows registry keys for persistence and adding exclusions to Microsoft Defender. 

Information stolen by the spyware has reportedly appeared on pro-Iranian leak sites, increasing personal safety risks for victims. The NCSC advises individuals at risk to familiarize themselves with the social-engineering techniques and mitigation advice provided in the advisory, which has been active since at least 2025.

Source: Infosecurity Magazine

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Upcoming Events

No events found.