UK, US, Dutch agencies warn of Iranian spyware campaign
Note: AI technology was used to generate this article’s audio.
Britain's National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI) and the Dutch General Intelligence and Security Service (AIVD) have issued a joint advisory detailing a spyware campaign by Iranian state-linked cyber actors targeting dissidents, activists and journalists around the world.
Read more: Iranian hackers attempted cyberattacks against critical US infrastructure: report
The agencies warned that individuals at risk should familiarize themselves with the social-engineering techniques used in the campaign and follow mitigation advice to reduce the risk of compromise.
Spyware targets Windows devices
The joint advisory details a malware family known as CHOSEN BRICK.
The FBI's technical analysis tracks the malware as HEAVYGRAM.
The NCSC says the malware has been used against targets around the world, including in the UK, United States and Netherlands, since at least 2025.
"Iranian cyber actors engaged with targets via social messaging applications to build rapport prior to attempting to deliver the malware," the advisory states.
Attackers have been observed contacting targets through applications including WhatsApp and Telegram, often impersonating people known to them or technical support. They tailor their approaches using information gathered about their targets and have used malicious files disguised as legitimate software and, in some cases, fabricated MRI test results.
Once installed on a Windows device, CHOSEN BRICK can collect contacts, emails and social media messages, capture screen content and access the device microphone. The malware is also persistent and can survive a system reboot.
Stolen data appears on leak sites
NCSC Director of Operations Paul Chichester said the campaign demonstrated "how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices."
The NCSC said personal details belonging to some previous victims have appeared on pro-Iranian leak sites, potentially increasing risks to their personal safety.
The FBI's March 2026 alert separately identified the online persona Handala Hack in connection with Iranian MOIS cyber activity, including campaigns involving data theft and hack-and-leak operations.
The FBI assesses that Iran's Ministry of Intelligence and Security uses the malware to collect intelligence, conduct data leaks and inflict reputational harm against targets.



