Adversary Intelligence — 2026-09-16

UK NCSC FBI and Dutch AIVD Expose MOIS-Linked CHOSEN BRICK Spyware Targeting Regime Opponents

BLUFBurning CHOSEN BRICK forces MOIS to retool but not halt diaspora targeting, and its parallel launch of the Alaj informant platform confirms Tehran is scaling transnational repression rather than constraining it.

The UK National Cyber Security Centre, the FBI and the Netherlands' AIVD issued a joint advisory on Tuesday detailing a spyware family dubbed "CHOSEN BRICK" that Iranian state actors have used against dissidents, activists and journalists, including targets in the UK 1. NCSC Director of Operations Paul Chichester said attackers impersonated trusted contacts on WhatsApp and Telegram, building rapport before deploying the Windows-targeted malware, which collects contacts, emails and social media messages and can capture screen content and access device microphones 12. Arab News reported that the FBI's advisory attributed the campaign to Iran's Ministry of Intelligence and Security, which it said uses the tool to "collect intelligence, conduct data leaks, and inflict reputational harm" against targets, and identified the report as an update to a March advisory tied to leaks posted by a persona known as "Handala Hack" 3. Multiple outlets reported attackers used fabricated lures, including fake MRI test results, to persuade victims to install the malware, and the NCSC said some victims' personal data later surfaced on pro-Iranian leak sites 1234.

Analysis
The joint advisory converts prior scattered leak-site reporting into an official, publicly attributed intelligence product, which strengthens the evidentiary basis for future sanctions or visa actions against MOIS-linked operators and gives at-risk individuals concrete indicators to harden their devices. Naming CHOSEN BRICK and tying it to the March Handala Hack leaks signals that UK, US and Dutch services are tracking the same infrastructure across multiple campaigns rather than treating each leak as isolated. Iran's demonstrated pattern of using personalized lures, including fabricated medical documents, indicates operators retain access to detailed target profiling that predates the malware deployment itself. Disclosure typically forces threat actors to retool rather than halt operations, so continued targeting of diaspora dissidents should be expected even as this specific toolset is burned. Read alongside the Alaj crowdsourced-informant platform launched this week, the two together show MOIS running parallel diaspora-targeting operations: bespoke cyber tools for high-value individual dissidents and mass civic mobilization for the broader opposition abroad.
4 sources
  1. UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists - UK National Cyber Security Centre (NCSC)
  2. US, UK, Netherlands warn of Iranian CHOSEN BRICK spyware targeting press - The Jerusalem Post
  3. UK, US and Netherlands issue advisory on Iran-linked spyware - Arab News
  4. Iranian cyber spies used fake MRI scan results to hack enemy of regime - The Record

View in full brief →

UNCLASSIFIED // OPEN SOURCE