UK NCSC FBI and Dutch AIVD Expose MOIS-Linked CHOSEN BRICK Spyware Targeting Regime Opponents
The UK National Cyber Security Centre, the FBI and the Netherlands' AIVD issued a joint advisory on Tuesday detailing a spyware family dubbed "CHOSEN BRICK" that Iranian state actors have used against dissidents, activists and journalists, including targets in the UK
The joint advisory converts prior scattered leak-site reporting into an official, publicly attributed intelligence product, which strengthens the evidentiary basis for future sanctions or visa actions against MOIS-linked operators and gives at-risk individuals concrete indicators to harden their devices. Naming CHOSEN BRICK and tying it to the March Handala Hack leaks signals that UK, US and Dutch services are tracking the same infrastructure across multiple campaigns rather than treating each leak as isolated. Iran's demonstrated pattern of using personalized lures, including fabricated medical documents, indicates operators retain access to detailed target profiling that predates the malware deployment itself. Disclosure typically forces threat actors to retool rather than halt operations, so continued targeting of diaspora dissidents should be expected even as this specific toolset is burned. Read alongside the Alaj crowdsourced-informant platform launched this week, the two together show MOIS running parallel diaspora-targeting operations: bespoke cyber tools for high-value individual dissidents and mass civic mobilization for the broader opposition abroad.
4 sources
- UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists -
UK National Cyber Security Centre (NCSC) - US, UK, Netherlands warn of Iranian CHOSEN BRICK spyware targeting press -
The Jerusalem Post - UK, US and Netherlands issue advisory on Iran-linked spyware -
Arab News - Iranian cyber spies used fake MRI scan results to hack enemy of regime -
The Record