Back to news

Western agencies expose Iranian spyware campaign against dissidents and journalists

A coordinated warning identifies CHOSEN BRICK malware as a tool for stealing messages, recording screens and tracking perceived opponents of Iran abroad.

A coordinated warning

Security agencies in the United Kingdom, United States and Netherlands issued a coordinated warning on 15 September about an Iranian spyware campaign targeting dissidents, activists and journalists. Al Jazeera reported that the agencies assess Iran is using cyber operations to pursue critics living outside the country. The campaign centres on a malware family called CHOSEN BRICK, delivered through carefully prepared approaches on messaging services rather than indiscriminate mass emails.

How the operation works

The attackers are reported to impersonate people or services familiar to a target, build trust and then persuade the person to open a malicious file. The malware is designed for Windows computers and can persist after a restart. Once installed, it can collect email and browser-based messaging data, capture a computer screen, activate a microphone and download additional tools. Investigators also warned that information stolen from some victims has later appeared on pro-Iranian leak sites.

Why dissidents face particular risk

The warning treats the campaign as more than conventional intelligence collection. Access to contacts, communications and location-related information can expose political networks and place individuals at physical risk. A 2025 statement published by the British government on behalf of the G7 Rapid Response Mechanism described an established pattern of Iranian efforts to intimidate, harass, kidnap or kill perceived opponents abroad, as well as operations aimed at obtaining and disclosing journalists' personal information.

The policy response

British sanctions guidance updated in September 2026 prohibits supplying interception and monitoring services to or for the benefit of Iran's government. That policy background shows why the new technical disclosure matters: Western governments are linking digital surveillance tools to a broader campaign of transnational repression. The latest advisory also gives potential targets practical indicators for checking devices and urges high-risk individuals to use specialist cyber-defence services.

What to watch

The immediate test is whether publication of the malware's behaviour and infrastructure disrupts the campaign or merely prompts its operators to change tools. Investigators will also be watching for compromised accounts, new leak sites and attempts to move conversations from protected workplace systems to personal devices. No military strike or ceasefire was announced; this is a counterintelligence and personal-security development.