GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
UK, US and Netherlands issue advisory on Iran-linked spyware - Finance news and analysis from Global Banking & Finance Review
Finance

UK, US and Netherlands issue advisory on Iran-linked spyware

Published by Global Banking & Finance Review

Posted on September 15, 2026

3 min read

· Last updated: September 15, 2026

Add as preferred source on Google

UK, US, and Netherlands Issue Warning on Iran-Linked Spyware Targeting Activists

Joint Cybersecurity Advisory and Details of Iranian Spyware Campaign

Overview of the Advisory

LONDON, Sept 15 (Reuters) - Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by Iranian state-linked actors to target dissidents, activists and journalists.

Technical Details of the "CHOSEN BRICK" Spyware

Methods of Attack

Britain's National Cyber Security Centre said Iranian state-linked cyber actors had used a spyware family known as "CHOSEN BRICK" to steal emails, messages and other sensitive information through "spear-phishing" campaigns on messaging platforms including WhatsApp and Telegram.

Official Statements

"The details of this cyber campaign reveal  how Iran ruthlessly uses digital surveillance in pursuit of  its  aim  to  repress critics of the regime, stealing emails and messages and accessing devices," Paul Chichester, NCSC Director of Operations, said in a statement.

Iran's embassy in London did not immediately respond to a request for comment.

Capabilities and Impact of the Malware

Information Gathering and Victim Impact

The malware, according to the advisory, can collect information from contact lists, emails and social media accounts, capture screen content and access a device's microphone. The NCSC said some victims' personal details had later appeared on pro-Iranian leak sites. The FBI, in its own advisory, said Iran's Ministry of Intelligence and Security (MOIS) was using the malware to "collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets." 

Scope of Targeting

The FBI did not immediately respond to a request for additional details on how many people have been targeted with the malware, or where they're located.

Attack Techniques and Deception Tactics

Social Engineering Approaches

The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware.

International Cooperation and Attribution

Suppression of Dissent

The NCSC, alongside the FBI and the Netherlands' AIVD intelligence service, said Iran "almost certainly" uses cyber operations to help suppress people it sees as threats. 

Previous Warnings and Hacking Personas

The FBI's advisory said it was an update to a March 2026 warning describing alleged MOIS efforts to use the malware to collect data on targets, which was then posted online by a hacking persona known as "Handala Hack." 

Notable Attacks and Responses

High-Profile Targets

Handala has targeted multiple U.S. companies and people since the start of the Iran war, including a destructive cyberattack against Michigan-based medical supplies and services supplier Stryker in March, and the leak of FBI Director Kash Patel's personal emails later that month.

Response from Handala

Handala did not respond to an emailed request for comment on Tuesday.

Reporting Credits

(Reporting by Sam Tabahriti in London and AJ Vicens in Detroit; editing by William James, Alexandra Hudson)

Key Takeaways

  • CHOSEN BRICK spyware harvests contacts, messages, screen images, microphone data and has led to leaks on pro‑Iran platforms, per NCSC, FBI and AIVD (apnews.com).
  • Attackers employed tailored spear‑phishing—including fake MRI documents—to trick victims into installing the spyware (apnews.com).
  • The campaign is linked to Iran’s Ministry of Intelligence and Security (MOIS) and follows a broader pattern of destructive cyber‑operations by Iran‑affiliated groups like Handala targeting U.S. entities such as Stryker in March 2026 (apnews.com).

References

Frequently Asked Questions

What is the name of the spyware linked to Iranian state actors?
The spyware is called 'CHOSEN BRICK' and is used by Iranian state-linked actors to target dissidents, activists, and journalists.
How does the Iranian spyware operate?
The spyware is deployed via spear-phishing campaigns on messaging platforms like WhatsApp and Telegram and can steal emails, messages, and other sensitive data.
Which countries issued the advisory about Iranian spyware?
The United Kingdom, United States, and Netherlands issued a joint cybersecurity advisory on the spyware.
What kind of information can the malware collect?
The malware can access contact lists, emails, social media accounts, capture screen content, and use a device’s microphone.
Who are the main targets of this Iranian cyber campaign?
The main targets are dissidents, activists, journalists, and critics of the Iranian regime.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category