US Edition
Your source for latest news
World NewsCybersecurity

UK, US and Netherlands expose Iranian spyware campaign targeting dissidents

A joint advisory names malware Western agencies say Iran's intelligence service has used since at least 2023 to spy on exiled activists and journalists, sometimes through fake WhatsApp contacts and forged medical documents.

PW
By PressTemps World DeskPublished Today, 21:52 ET · 5 min read
UK, US and Netherlands expose Iranian spyware campaign targeting dissidents
File photo, illustrative: the J. Edgar Hoover Building in Washington, D.C., headquarters of the FBI, one of three agencies that co-signed Tuesday's advisory on Iranian state-linked spyware. Photo: Ajay Suresh / Wikimedia Commons, CC BY 2.0.
What to know
Britain, the US and the Netherlands jointly named a spyware family, "CHOSEN BRICK" (FBI: HEAVYGRAM), that they attribute to Iran's Ministry of Intelligence and Security.
The malware steals emails, messages, screen captures and microphone audio, using Telegram as its command-and-control channel, and has targeted dissidents, activists and journalists since at least 2023.
Attackers used social engineering on WhatsApp and Telegram, including fabricated medical documents, to trick victims into installing disguised files; some victims' data later appeared on pro-Iranian leak sites.
Tuesday's advisory updates an FBI flash alert from March 2026 and is the first version co-signed by the UK's NCSC and the Netherlands' AIVD.

Cybersecurity and intelligence agencies in Britain, the United States and the Netherlands on Tuesday published a joint advisory detailing a spyware campaign they attribute to Iran's Ministry of Intelligence and Security, saying the malware has been used to surveil dissidents, activists and journalists in at least three countries.

The advisory from Britain's National Cyber Security Centre, published alongside the FBI and the Netherlands' AIVD intelligence service, names the malware family "CHOSEN BRICK" — the same tool the FBI tracks under the name HEAVYGRAM. It says the software has been deployed against targets in the UK, US and the Netherlands "from at least 2025," while the wider campaign, according to the FBI's supporting technical writeup, dates back to the autumn of 2023.

What the malware does

According to the advisory, CHOSEN BRICK can harvest a target's contact lists, emails and social media messages, record screen content and activate a device's microphone. It is controlled through the Telegram messaging app, which the malware uses as a command-and-control channel, and it copies data directly from the Telegram and WhatsApp web clients running in a victim's browser. Agencies say the malware installs itself in a non-standard system directory designed to look like a legitimate Windows folder, sets a registry run key so it survives a reboot, and registers a unique mutex to avoid running twice on the same machine. To move stolen data out, operators route traffic through HTTPS or SOCKS5 proxies to disguise their use of Telegram's bot API and, in some cases, exfiltrate files to commercial cloud object-storage services rather than a dedicated server, making the traffic harder for defenders to flag as malicious. The advisory also says the malware adds exclusions to Microsoft Defender so infected files are never scanned, and it can delete itself and wipe evidence from a compromised machine once it has finished collecting data.

The agencies say the attackers typically make initial contact by posing as trusted acquaintances or platform support staff on WhatsApp or Telegram, then persuade the target to open a disguised file. In some cases documented by the FBI, operatives sent victims fabricated medical documents, including fake MRI results, to lend the malicious file credibility. Once installed, the malware masquerades as familiar software such as KeePass, Norton Antivirus, Adobe Flash or the video tools Pictory and RunwayML.

"Iran ruthlessly uses digital surveillance to repress critics, stealing emails and accessing devices," said Paul Chichester, the NCSC's director of operations.

Who is affected

The three agencies assessed that Iran "almost certainly" uses cyber operations to support repression of people it regards as threats to the government, singling out dissidents, activists and journalists living both inside and outside the country. The advisory says the personal details of some previous victims subsequently surfaced on pro-Iranian leak sites, which it warned could heighten the physical risk to those affected. The National Cyber Security Centre, part of the British signals intelligence agency GCHQ, did not disclose how many individuals have been targeted or identify victims by name, citing operational and safety concerns. Dutch authorities said separately that victims located in the Netherlands have been notified directly.

Background: an escalating pattern

Tuesday's release builds on an earlier warning. The FBI first flagged the Telegram-controlled malware in a flash alert issued in March, which described Iranian government-linked actors using Telegram infrastructure to push malicious files to identified targets. That alert came the same month that a hacking persona known as "Handala Hack" — which the FBI has separately linked to Iranian intelligence — published emails after breaching the personal account of an FBI official and struck the medical device maker Stryker with destructive wiper malware, according to reporting at the time. Tuesday's advisory updates that earlier alert with new technical detail and a longer list of indicators of compromise, and was published in near-identical form by all three agencies, including the Dutch intelligence service's own copy of the advisory, which adds guidance specific to victims notified inside the Netherlands — marking the first time the UK and Dutch governments have co-signed the findings.

Western officials have documented Iranian efforts to reach dissidents abroad through means well beyond hacking. U.S. prosecutors have said that, since at least June 2020, an Iranian intelligence network led by Alireza Shahvaroghi Farahani surveilled and plotted to kidnap an Iranian-American journalist and activist in Brooklyn, researching speedboats and maritime routes to forcibly return her to Iran; four Iranian nationals were indicted, and a fifth defendant was accused of helping finance the operation. Separate criminal cases have since resulted in prison sentences in the U.S. for men accused of stalking the same journalist and plotting to have her killed. Press-freedom groups including the Committee to Protect Journalists have separately tracked a pattern of detentions of journalists inside Iran and, this year, a lengthy nationwide internet blackout that CPJ and Reporters Without Borders said was being used to obscure a crackdown on independent media. Tuesday's advisory did not draw a direct link between CHOSEN BRICK and any single detention or prosecution, but its authors said the campaign's overall purpose was consistent with that broader pattern of pressuring critics who have left the country.

What happens next

The advisory urges individuals who believe they may be targeted — particularly journalists, activists and dissidents connected to Iran — to avoid installing software received as an attachment or link, rely on official app stores, keep devices updated automatically and leave Microsoft's SmartScreen download warnings enabled. Organizations are advised to deploy phishing-resistant multi-factor authentication, application allowlisting and endpoint monitoring, and to search their logs against the indicators of compromise published with the advisory. The agencies are asking anyone who believes they have been targeted to report it: to the NCSC in the UK, the FBI's Internet Crime Complaint Center in the US, or the AIVD in the Netherlands. Iran's embassy in London did not immediately respond to a request for comment reported alongside the advisory's release, and Tehran has not issued a public response to the specific allegations.

More on this story

All World News