The UK’s National Cyber Security Centre, the FBI, and Dutch intelligence have issued a joint warning regarding a sophisticated Iranian spyware campaign targeting dissidents, journalists, and activists.
Key Points
- The campaign utilizes "Chosen Brick" spyware to harvest emails, messages, and contact lists from compromised devices.
- Threat actors employ social engineering on social media to trick victims into downloading malicious files disguised as legitimate software.
- The malware evades detection by adding exclusions to Microsoft Defender and uses Telegram for command and control operations.
- Capabilities include screen capture, audio recording via device microphones, and the ability to wipe entire systems.
- Intelligence agencies report the campaign has been active since at least 2025 and poses a direct threat to the personal safety of targets.