Iranian state actors have been targeting UK dissidents, activists, and journalists using sophisticated spyware, according to the National Cyber Security Centre (NCSC), which operates under GCHQ, the UK's signals intelligence agency. British intelligence has issued a warning after uncovering evidence that Iranian spies have used malware to track the movements and communications of individuals critical of the Iranian government. The spyware, named Chosen Brick, was deployed through deceptive tactics such as impersonating contacts on messaging apps, tricking victims into downloading the software. Once installed, the malware grants attackers access to a person's contacts, emails, social media messages, and even a device's microphone and screen content.
The cyber campaign, uncovered by the UK alongside the US and the Netherlands, has targeted not only British dissidents but also individuals from various other countries. While the exact number of people affected remains unclear, the FBI has reported that the malware was in use as early as Autumn 2023. Iranian agents used social engineering techniques to tailor their attacks to their targets' interests, including sending fake MRI test results to lure one victim. The malware is designed to persist even after a device is rebooted, making it particularly dangerous. Some of the stolen personal information has been shared on websites supportive of Iran, according to the NCSC.
Paul Chichester, director of operations at the NCSC, emphasized that this cyber campaign highlights Iran's use of digital surveillance to suppress dissent. "The details of this cyber campaign reveal how Iran uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices," he said. The NCSC, in collaboration with international partners, urges individuals at risk to understand the social-engineering tactics used in these attacks and follow mitigation advice to protect themselves. The FBI has also issued its own advisory, stating that Iran's Ministry of Intelligence and Security (MOIS) is using the malware to gather intelligence, leak data, and damage the reputations of its targets.
Technical details about the malware and how to avoid falling victim to it have been published on the NCSC website. Earlier this year, NCSC chief Richard Horne warned that hostile states, including Russia, China, and Iran, are increasingly targeting the UK's critical systems. He noted that three-quarters of cyber attacks affecting the UK's critical infrastructure in the past year were linked to state-sponsored actors. These warnings underscore the growing threat posed by state-backed cyber operations and the importance of maintaining strong digital defenses.
Iranian Cyber Campaign Targets UK Dissidents and Activists with Spyware
AI-rewritten from original reportingHow it works
iranspywarecyberattackncscgchqfbi



