The UK National Cyber Security Centre (NCSC), part of GCHQ, along with international partners from the US and the Netherlands, has issued a warning regarding a spyware campaign attributed to Iranian state actors. This campaign, utilizing malware known as ‘CHOSEN BRICK’, targets dissidents, activists, and journalists worldwide, including those in the UK, who are perceived as threats to the Iranian regime.
According to the advisory, CHOSEN BRICK is designed to collect sensitive information from its targets, including screen captures, messaging history, and access to contacts and social media messages. The malware has been observed being deployed through spear-phishing tactics, where attackers impersonate trusted contacts on messaging platforms like WhatsApp and Telegram to build rapport before tricking victims into downloading the malicious software.
The NCSC emphasizes the importance of awareness and preparedness for individuals at risk of digital surveillance. They have provided guidance on identifying and countering these threats, which includes recognizing social engineering techniques used by attackers. The advisory also highlights that the malware is particularly persistent, capable of surviving device reboots, and is primarily aimed at Windows operating systems.
In response to this threat, the UK government has reiterated its commitment to protecting individuals from foreign intimidation and harassment. They have rolled out specialist training across UK police forces to help identify state-sponsored cyber threats and have encouraged those at risk to utilize available resources for personal security.
For further details, the full advisory can be accessed through the NCSC’s official website: NCSC.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



