Britain, US, Netherlands issue advisory on Iranian spyware targeting dissidents
Summary
Britain, the United States, and the Netherlands issued a joint advisory on Tuesday alerting the public to spyware used by Iranian state actors to target dissidents, activists, and journalists worldwide. The malware, known as “CHOSEN BRICK,” allows Iranian cyber actors to collect sensitive information, including emails and social media messages, and access device microphones. According to Britain’s National Cyber Security Centre, this cyber campaign exemplifies Iran's use of digital surveillance to suppress critics, with the malware specifically designed for Windows devices and capable of persisting after device reboots.
Analysis
Britain: Britain maintains strong national cybersecurity infrastructure through dedicated agencies focused on threat detection and public advisories. As the lead issuer of the advisory, it detailed the Iranian actors' use of malware to steal communications and access devices of critics of the regime. Netherlands: The Netherlands actively engages in international efforts to counter state-backed cyber threats and protect human rights advocates. It joined the United States and Britain in releasing the advisory highlighting the spyware campaign by Iranian actors. United States: The United States is a leading nation in global cybersecurity cooperation and intelligence sharing with allies. It participated in issuing the joint advisory alongside Britain and the Netherlands to expose Iranian state-sponsored spyware operations targeting dissidents and journalists worldwide. Paul Chichester: Paul Chichester is the Director of Operations at Britain’s National Cyber Security Centre, overseeing responses to cyber incidents and threat disclosures. He stated that the Iranian campaign demonstrates ruthless digital surveillance aimed at repressing critics through stolen data and device access. National Cyber Security Centre: Britain’s National Cyber Security Centre serves as the primary government body responsible for protecting the UK from cyber attacks and providing guidance on threats. It published key details on the Iranian malware operation known as CHOSEN BRICK in the joint advisory. Persistence Mechanism: The CHOSEN BRICK malware was designed to remain active on infected systems even after device reboots. Cyber Espionage Tactics: Iranian actors impersonated contacts on apps like WhatsApp and Telegram to build trust before deploying spyware exclusively on Windows devices. International Coordination: Britain, the United States, and the Netherlands collaborated on a joint advisory to expose and counter state-sponsored malware targeting activists and journalists globally.
Categories
politicstech