ERBIL, Kurdistan Region of Iraq - Intelligence services from the US, UK, and the Netherlands on Tuesday revealed alleged Iranian spear phishing methods to install spyware on the devices of political dissidents and activists across the globe, with a British official saying it reveals "how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime."
In a joint advisory released by Britain's National Cyber Security Centre (NCSC), the American Federal Bureau of Investigation (FBI), and the Dutch General Intelligence and Security Service (AIVD), the agencies offered insight into the CHOSEN BRICK malware, which they claimed has been used to target Iranian political opponents around the globe since at least 2025.
"CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails, and social media messages, which could enable tracking of their movements," the advisory read. "Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists, and journalists," noting that some individuals had their data posted on pro-Iran websites.
The report explicitly mentioned the WhatsApp and Telegram messaging platforms as means through which Iranian cyber groups gain access to a target, using social engineering techniques such as operating under the guise of technical support or an acquaintance to convince them to download seemingly legitimate applications that contain the spyware.
"The actors are known to tailor their social engineering to include areas of relevance or interest to their targets and have even included fake MRI test results to lure victims in," the NCSC said in a separate statement on the matter.
Once it has been installed on the victim's device, CHOSEN BRICK can then perform a wide array of functions to garner information, including screen capturing, retrieving emails, and capturing audio content using the device's microphone.
The intelligence services also listed mitigation techniques potential targets can use to avoid compromise, as well as means of determining if their electronic devices contain the spyware.
The Iranian government’s efforts to track down dissidents abroad have intensified in recent months, with Iranian state media on Monday promoting Alaj, a monitoring and intelligence platform aiming to identify individuals it describes as "traitors" and those opposing state interests.
The platform’s declared objectives include imposing measures against those identified, including the "freezing of assets and the revocation of consular and citizenship services."
"The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages, and accessing devices," said Paul Chichester, the NCSC's Director of Operations.
"With our international partners, we strongly encourage individuals at risk to familiarize themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice."