UK, US and Netherlands Issue Advisory on Iran-Linked Spyware

Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by Iranian state-linked actors to target dissidents, activists and journalists. Britain's National Cyber Security Centre said Iranian state-linked cyber actors had used a spyware family known as "CHOSEN ‌BRICK" to steal ‌emails, messages and other ‌sensitive information ⁠through "spear-phishing" campaigns on ⁠messaging platforms including WhatsApp and Telegram. "The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing ⁠devices," Paul Chichester, NCSC Director of Operations, ‌said in ‌a statement. Iran's embassy in London did not immediately ‌respond to a request for comment. The malware, ‌according to the advisory, can collect information from contact lists, emails and social media accounts, capture screen content and access a device's microphone. ‌The NCSC said some victims' personal details had later appeared on pro-Iranian ⁠leak ⁠sites. The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware. The NCSC, alongside the FBI and the Netherlands' AIVD intelligence service, said Iran "almost certainly" uses cyber operations to help suppress people it sees as threats.