Already a subscriber? Make sure to log into your account before viewing this content. You can access your account by hitting the “login” button on the top right corner. Still unable to see the content after signing in? Make sure your card on file is up-to-date.
Intelligence agencies in three countries issued a joint advisory Tuesday warning that Iran is using spyware to target dissidents, activists and journalists living outside the country.
Getting into it: The FBI, the UK’s National Cyber Security Center and the Netherlands’ AIVD are all behind the warning, which centers on a malware family called “CHOSEN BRICK.” The NCSC says Iranian actors impersonate people their targets already know on WhatsApp and Telegram, build rapport and then get them to download and open files that look legitimate. In some cases, they faked medical scan results to make the file look worth opening.
Once installed, the malware can pull contact lists, emails and social media messages; capture what is on screen; and switch on a device’s microphone. It targets Windows machines and is persistent, meaning it survives a reboot. Stolen personal information from some of the people hit has since surfaced on leak sites run by Iran’s supporters, leaving those victims open to more harassment, according to the NCSC.
The FBI attributed the campaign to Iran’s Ministry of Intelligence and Security (MOIS), saying MOIS is using the malware to “collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets.” All three agencies assessed that Iran “almost certainly” uses cyber operations to support the repression of anyone the regime considers a threat. The bureau would not say how big the target pool is or what countries those people live in. Iran’s embassy in London did not respond to a request for comment.
The advisory updates an FBI warning from March that described the same MOIS operation feeding stolen data to a hacking persona called “Handala Hack.” Handala has gone after multiple American companies and individuals since the war began, including a destructive attack that same month that took down networks worldwide at Stryker, a top medical device manufacturer.
The group said the attack marked “the beginning of a new chapter in cyber warfare.” Handala also said in March that it had broken into FBI Director Kash Patel’s private email and posted images and files from it online.






