Welcome to Roya News, stay informed with the most important news at your fingertips.

1
Image 1 from gallery

UK, US, Dutch agencies warn of Iranian spyware campaign

Listen to this story:
0:00

Note: AI technology was used to generate this article’s audio.

Published :  
4 hours ago|
Last Updated :  
1 hour ago|

Britain's National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI) and the Dutch General Intelligence and Security Service (AIVD) have issued a joint advisory detailing a spyware campaign by Iranian state-linked cyber actors targeting dissidents, activists and journalists around the world.


Read more: Iranian hackers attempted cyberattacks against critical US infrastructure: report


The agencies warned that individuals at risk should familiarize themselves with the social-engineering techniques used in the campaign and follow mitigation advice to reduce the risk of compromise.

Spyware targets Windows devices

The joint advisory details a malware family known as CHOSEN BRICK.

The FBI's technical analysis tracks the malware as HEAVYGRAM.

The NCSC says the malware has been used against targets around the world, including in the UK, United States and Netherlands, since at least 2025.

"Iranian cyber actors engaged with targets via social messaging applications to build rapport prior to attempting to deliver the malware," the advisory states.

Attackers have been observed contacting targets through applications including WhatsApp and Telegram, often impersonating people known to them or technical support. They tailor their approaches using information gathered about their targets and have used malicious files disguised as legitimate software and, in some cases, fabricated MRI test results.

Once installed on a Windows device, CHOSEN BRICK can collect contacts, emails and social media messages, capture screen content and access the device microphone. The malware is also persistent and can survive a system reboot.

Stolen data appears on leak sites

NCSC Director of Operations Paul Chichester said the campaign demonstrated "how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices."

The NCSC said personal details belonging to some previous victims have appeared on pro-Iranian leak sites, potentially increasing risks to their personal safety.

The FBI's March 2026 alert separately identified the online persona Handala Hack in connection with Iranian MOIS cyber activity, including campaigns involving data theft and hack-and-leak operations.

The FBI assesses that Iran's Ministry of Intelligence and Security uses the malware to collect intelligence, conduct data leaks and inflict reputational harm against targets.