September 18, 2026 06:03 pm (IST)
Follow us:
facebook-white sharing button
twitter-white sharing button
instagram-white sharing button
youtube-white sharing button
Gurugram murder shocker: Groom-to-be leaves sisters at Delhi restaurant to meet ex-colleague, found dead days later | Delhi horror: Teen allegedly gangraped, stabbed to death and dumped in field; dogs eat parts of body | TMC name, symbol frozen: EC tells rival factions to pick new identities ahead of Bengal bypolls | Married just 17 days ago: Hyderabad engineer mysteriously found dead at US home | ‘We will promote cash’: New UPI charge triggers trader backlash, Opposition protests | Gurugram biker crash: Main accused Kalyan Bainsla sent to police custody for 2 days | ‘Just tax collection’: Ashneer Grover slams new UPI charges above Rs 2,000 | India condemns Houthi attack on Saudi Arabia, warns of threat to Red Sea shipping | Gurugram biker hit by car: Two including main accused arrested after viral road rage video, attempt to murder case filed | Gurugram horror caught on camera: ‘I felt unsafe’—car chases, rams woman biker and flees
Iran Spyware
UK, US Netherlands issue advisory on Iran-linked spyware. Photo: Pixabay

What is Chosen Brick? UK, US, Netherlands warn of spyware campaign targeting Iran critics worldwide

| @indiablooms | Sep 18, 2026, at 05:00 pm

Britain, the United States and the Netherlands have issued a joint advisory warning about spyware allegedly used by Iranian state-linked actors to target dissidents, activists and journalists around the world.

Britain’s National Cyber Security Centre (NCSC) has shared details of how Iranian state-backed cyber actors have been observed attempting to trick targets into downloading software capable of tracking their movements.

“Dissidents, activists and journalists around the world, including in the UK, that are perceived to pose a threat to Iran are among those that have been targeted with the spyware dubbed ‘CHOSEN BRICK’,” the NCSC said in an official statement.

Chosen Brick enables attackers to collect information from a target’s contacts, emails and social media messages. It also has capabilities to capture screen content and access a device’s microphone.

A new joint advisory issued by the NCSC and its international partners said Iranian state actors have been observed impersonating contacts on messaging platforms such as WhatsApp and Telegram. They allegedly build rapport with targets before deploying  Chosen Brick and stealing sensitive information, some of which has subsequently appeared on leak sites.

According to the advisory, the actors tailor their social-engineering attempts to areas of relevance or interest to their targets. In some cases, they have reportedly used fake MRI test results to lure victims.

The British government said attempts by foreign powers to intimidate, harass, surveil or otherwise target individuals in the UK “will never be tolerated”.

It said security support and practical guidance are available for people at risk of transnational repression, including measures to protect themselves both online and in person.

Specialist training on identifying state-threat activity has been rolled out across all UK police forces. The government said law enforcement and intelligence agencies have the powers needed to detect and disrupt such activity and will take action against perpetrators.

“We will continue to call out malicious cyber activity by the Iranian state and support communities with practical advice to strengthen their online personal security,” Paul Chichester, NCSC Director of Operations, said.

The NCSC said it assesses that Iran “almost certainly” uses cyber activity to support the repression of individuals viewed as threats to the regime.

Personal details of some previous victims have appeared on pro-Iranian leak sites, potentially increasing the risks to their personal safety, the agency said.

To reduce the risk of compromise, the NCSC has advised individuals who may be targeted to follow the mitigation measures outlined in its advisory and seek dedicated support available to high-risk individuals, including free cyber-defence services.

The malware has so far been exclusively used against devices running the Windows operating system. The advisory warns that CHOSEN BRICK is persistent and can survive a reboot of an infected device.

Support Our Journalism

We cannot do without you.. your contribution supports unbiased journalism

IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.

Support objective journalism for a small contribution.