Home / Technology / UK, US, NL Expose Iran's Cyber Espionage
UK, US, NL Expose Iran's Cyber Espionage
15 Sep
Summary
- Iran-linked actors use 'CHOSEN BRICK' spyware.
- Spyware targets dissidents, activists, and journalists.
- Malware steals sensitive data through phishing attacks.

Britain, the United States, and the Netherlands issued a joint cybersecurity advisory on September 15, 2026, exposing Iranian state-linked cyber actors. These actors have been utilizing a spyware family named 'CHOSEN BRICK' to target dissidents, activists, and journalists.
The malware is deployed through sophisticated spear-phishing campaigns on popular messaging platforms like WhatsApp and Telegram. Its capabilities include stealing emails, messages, contact lists, and social media account information, alongside capturing screen content and accessing device microphones. Victims' personal details have reportedly appeared on pro-Iranian leak sites, indicating the repressive aims of these digital surveillance operations.
The FBI indicated that Iran's Ministry of Intelligence and Security (MOIS) is behind these efforts, using the malware for intelligence gathering, data leaks, and damaging the reputations of intended targets. These cyber operations are believed to be a significant tool for Iran to suppress individuals perceived as threats to the regime.