World News

UK, US, Netherlands issue advisory on Iran-linked spyware

The NCSC, alongside the FBI and the Netherlands’ AIVD intelligence service, said Iran “almost certainly” uses cyber operations to help suppress people it sees as threats.

By Reuters and The Algemeiner

Britain, the United States, and the Netherlands issued a joint cybersecurity advisory detailing spyware they say is used by Iranian state-linked actors to target dissidents, activists, and journalists.

Britain’s National Cyber Security Center said Iranian state-linked cyber actors had used a spyware family known as “CHOSEN BRICK” to steal emails, messages, and other sensitive information through “spear-phishing” campaigns on messaging platforms, including WhatsApp and Telegram.

“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” Paul Chichester, NCSC director of operations, said in a statement.

Iran‘s embassy in London did not immediately respond to a request for comment.

The malware, according to the advisory, can collect information from contact lists, emails, and social media accounts, capture screen content, and access a device’s microphone.

The NCSC said some victims’ personal details had later appeared on pro-Iranian leak sites.

The FBI, in its own advisory, said Iran‘s Ministry of Intelligence and Security (MOIS) was using the malware to “collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets.”

The FBI declined to share additional details on how many people have been targeted with the malware or where they’re located.

The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets.

In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware.

The NCSC, alongside the FBI and the Netherlands’ AIVD intelligence service, said Iran “almost certainly” uses cyber operations to help suppress people it sees as threats.

The FBI’s advisory said it was an update to a March 2026 warning describing alleged MOIS efforts to use the malware to collect data on targets, which was then posted online by a hacking persona known as “Handala Hack.”

Handala has targeted multiple US companies and people since the start of the Iran war, including a destructive cyberattack against Michigan-based medical supplies and services supplier Stryker in March and the leak of FBI Director Kash Patel’s personal emails later that month.

Handala did not respond to an emailed request for comment on Tuesday.

Share
Published by
Yossi Licht
Tags: cyberattack Iran spy

Recent Posts

  • World News

US court records capture Gazan terrorist laughing during Oct. 7 massacre

Prosecutors say the calls support their allegation that al-Muhtadi directly participated in the Hamas-led assault.

10 minutes ago
  • Videos

WATCH: Houthi forces shoot down Saudi F-15 fighter jet

In a dramatic escalation of hostilities between the Houthis of Yemen and Saudi Arabia, an…

27 minutes ago
  • World News

South Florida Democrat Moskowitz airs campaign ad targeting antisemitism with concentration camp footage

Moskowitz’s team emphasized the 'deeply personal' nature of the congressman’s battle against antisemitism in a…

40 minutes ago
  • Israel News

Iranian spy sentenced to 13.5 years in Israeli prison

In exchange for the missions he completed, Granovsky received thousands of dollars from the agent…

55 minutes ago
  • Videos

WATCH: Palestinian ambassador to UK claims Bible is a ‘Palestinian book’

Palestinian Ambassador to the UK Husam Zomlot called the Bible a 'Palestinian book' that was…

1 hour ago
  • World News

Americans face generational divide over Israel, poll finds

Among Democratic voters, just 18 percent sympathize more with Israel, while 59 percent sympathize more…

1 hour ago