Home Technology UK, US, Netherlands Warn of Iran-Linked Spyware in Joint Advisory
Technology

UK, US, Netherlands Warn of Iran-Linked Spyware in Joint Advisory

Share


UK, US and Netherlands Issue Cybersecurity Warning on Iran-Linked Spyware Threat

Joint Advisory Details Iranian State-Linked Cyber Threats

LONDON, Sept 15 (Reuters) – Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by Iranian state-linked actors to target dissidents, activists and journalists.

CHOSEN BRICK Spyware and Attack Methods

Britain’s National Cyber Security Centre said Iranian state-linked cyber actors had used a spyware family known as “CHOSEN BRICK” to steal emails, messages and other sensitive information through “spear-phishing” campaigns on messaging platforms including WhatsApp and Telegram.

“The details of this cyber campaign reveal  how Iran ruthlessly uses digital surveillance in pursuit of  its  aim  to  repress critics of the regime, stealing emails and messages and accessing devices,” Paul Chichester, NCSC director of operations, said in a statement.

Iran’s embassy in London did not immediately respond to a request for comment.

Capabilities of the Malware

The malware, according to the advisory, can collect information from contact lists, emails and social media accounts, capture screen content and access a device’s microphone. The NCSC said some victims’ personal details had later appeared on pro-Iranian leak sites. The FBI, in its own advisory, said Iran’s Ministry of Intelligence and Security (MOIS) was using the malware to “collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets.” 

The FBI declined to share additional details on how many people have been targeted with the malware, or where they’re located.

Attack Techniques and Social Engineering

The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware.

International Response and Attribution

The NCSC, alongside the FBI and the Netherlands’ AIVD intelligence service, said Iran “almost certainly” uses cyber operations to help suppress people it sees as threats. 

Previous Warnings and Hacking Personas

The FBI’s advisory said it was an update to a March 2026 warning describing alleged MOIS efforts to use the malware to collect data on targets, which was then posted online by a hacking persona known as “Handala Hack.” 

Handala Hack’s Activities

Handala has targeted multiple U.S. companies and people since the start of the Iran war, including a destructive cyberattack against Michigan-based medical supplies and services supplier Stryker in March, and the leak of FBI Director Kash Patel’s personal emails later that month.

Handala did not respond to an emailed request for comment on Tuesday.

(Reporting by Sam Tabahriti in London and AJ Vicens in Detroit. Editing by William James, Alexandra Hudson and Mark Potter)



Source link

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Technology

Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors | Police

Vast troves of highly sensitive police data are lying on Microsoft cloud...

Technology

Microsoft cloud platform exposes UK police data to US government access risks

Sensitive data from more than 40 UK police forces is stored on...

Technology

Turning the UK’s Data Centre Ambitions Into Reality

The infrastructure behind the UK’s digital economy faces growing challenges. From rising...

Technology

‘A critical moment’: concern UK is not up to speed in acting on AI risks | AI (artificial intelligence)

Towards the end of Keir Starmer’s time in office, his senior ministers,...