Western agencies warn of Iranian spyware campaign targeting dissidents abroad

Western agencies warn of Iranian spyware campaign targeting dissidents abroad

The United States, the United Kingdom and the Netherlands have issued coordinated warnings about what they say is an Iranian spyware campaign aimed at dissidents living in the West. The advisories say Iranian state-linked cyber actors are using a spyware family known as CHOSEN BRICK to target critics of the Iranian government abroad. Officials said the activity is part of a broader effort to monitor, intimidate and gather information on opponents outside Iran.

Shopify_Landscape

Sponsored

The FBI, Britain's National Cyber Security Centre and the Netherlands' AIVD all repeated the warning in separate but aligned notices. Britain's cyber agency said the campaign shows how Iran uses digital surveillance to pursue its aim of repressing critics, including by stealing emails and messages and accessing devices. The FBI said Iran's Ministry of Intelligence and Security was using the malware to collect intelligence, conduct data leaks and inflict reputational harm on intended targets.

The agencies said the campaign relies on spear-phishing through messaging platforms including WhatsApp and Telegram. That method typically involves sending deceptive messages designed to trick targets into clicking malicious links or revealing access details. The warnings did not say how many people may have been affected, but they made clear that the focus is on Iranian dissidents and critics living outside the country.

The latest advisories add to a pattern of Western concern about Iranian cyber activity beyond its borders. The row says the current warning is a continuation of regular alerts about efforts to surveil and harass critics abroad, but it also highlights a specific spyware family and delivery method. That makes the case more concrete for security services and for people in exile who may already face pressure from online monitoring and harassment.

Shopify_Landscape

Sponsored

The warnings also come against a backdrop of repeated allegations that Iranian-linked actors use cyber tools not only to gather intelligence but also to damage reputations and spread stolen material. In a previous warning in March, the FBI said alleged Ministry of Intelligence and Security activity had used malware to collect data on targets that was later posted online by a persona known as Handala Hack. The same row says a separate attack in March crippled the global networks of Stryker, and that in July US officials said a cyberattack on water systems in Minnesota resembled the Handala Hack.

What remains unclear is the full scale of the CHOSEN BRICK campaign, how many targets were reached, and whether the activity has been contained. The advisories do not provide a public attribution process beyond the agencies' assessments that Iranian state-linked actors are responsible. The next developments to watch are whether more countries issue similar warnings, whether additional technical indicators are published, and whether the campaign leads to further arrests, sanctions or defensive measures.

360LiveNews 360LiveNews | 15 Sep 2026 22:02 LONDON
← Back to Homepage