AUTO-UPDATED

NCSC and Allies Warn of Iranian Spyware Campaign

The UK’s National Cyber Security Centre, the FBI, and Dutch intelligence have issued a joint warning regarding a sophisticated Iranian spyware campaign targeting dissidents, journalists, and activists.

Key Points

  • The campaign utilizes "Chosen Brick" spyware to harvest emails, messages, and contact lists from compromised devices.
  • Threat actors employ social engineering on social media to trick victims into downloading malicious files disguised as legitimate software.
  • The malware evades detection by adding exclusions to Microsoft Defender and uses Telegram for command and control operations.
  • Capabilities include screen capture, audio recording via device microphones, and the ability to wipe entire systems.
  • Intelligence agencies report the campaign has been active since at least 2025 and poses a direct threat to the personal safety of targets.

Why it Matters

This advisory highlights the increasing use of digital surveillance by state-backed actors to repress political opposition globally. By targeting personal devices through social engineering, these campaigns pose significant security risks to both individuals and the organizations that employ them.
Infosecurity Magazine Published by Phil Muncaster
Read original