US, UK, and Netherlands Expose Iranian Spyware Campaign
The United States, United Kingdom, and Netherlands issued a joint advisory attributing the Chosen Brick spyware campaign to Iran's Ministry of Intelligence and Security.
The governments of the United Kingdom, the United States, and the Netherlands issued a joint cybersecurity advisory on September 15, 2026, exposing a state-sponsored spyware campaign targeting dissidents, activists, and journalists globally. The National Cyber Security Centre (NCSC) identified the malware family as Chosen Brick, while the FBI tracks the same software as Heavygram.
Iranian state-linked actors deploy the spyware on Windows-based systems using spear-phishing and social engineering via WhatsApp, Telegram, and Instagram. Attackers often impersonate trusted acquaintances or technical support, tricking victims into downloading malicious files disguised as legitimate software or fabricated documents, such as fake MRI results. Once installed, the spyware grants attackers full control, allowing them to capture real-time screen activity and audio, steal emails and private messaging histories, and modify device security settings.
The FBI attributed the activity to Iran's Ministry of Intelligence and Security (MOIS). The agency uses the malware to collect intelligence and inflict reputational harm, often publishing stolen data on pro-Iranian leak sites via the persona Handala Hack. Paul Chichester, Director of Operations at the NCSC, stated the campaign demonstrates how Iran uses digital surveillance to repress critics of the regime. This cyber activity is described as part of a broader pattern of Iranian efforts to silence opponents abroad, which has previously included kidnapping and assassination plots.