FBI, NCSC, AIVD Warn of Iran's 'CHOSEN BRICK' Spyware — SkimNews

Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Three Western intelligence agencies—the FBI, Britain's NCSC, and the Netherlands' AIVD—issued coordinated advisories warning that Iran is "almost certainly" using cyber operations to target Iranian dissidents living in the West.
- CHOSEN BRICK spyware, used by Iranian state-linked actors, steals sensitive data through spear-phishing campaigns on messaging platforms including WhatsApp and Telegram, the agencies said.
- Iran's Ministry of Intelligence and Security (MOIS) is using the malware to "collect intelligence, conduct data leaks, and inflict reputational harm" against intended targets, according to the FBI.
- NCSC director Paul Chichester said the campaign reveals how Iran "ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices."
- Handala Hack, an Iran-linked group, used related MOIS malware in March to cripple global networks of medical device company Stryker, calling the attack "the beginning of a new chapter in cyber warfare."
- Handala Hack also claimed to have accessed and shared personal emails of FBI Director Kash Patel, and US officials said a July cyberattack on Minnesota water systems resembled the group's tactics.
Why it matters: The three-nation coordinated advisory names Iran's MOIS and the 'CHOSEN BRICK' malware by signature, tying it to spear-phishing on WhatsApp and Telegram—platforms used by millions of diaspora dissidents. The campaign's reach extends beyond critics: Handala Hack already crippled Stryker's global networks and allegedly accessed FBI Director Kash Patel's emails, while a July Minnesota water system attack resembled the same group's tactics.
Ask SkimNews


