# UK and Allies Uncover Iranian Spyware Targeting Global Dissidents and Journalists

*Published September 16, 2026*
*Source: [https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists](https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists)*

## Executive Summary

The UK, US, and Dutch authorities have exposed the CHOSEN BRICK spyware used by Iranian state actors to monitor dissidents and journalists. This discovery highlights the regime's use of digital surveillance to repress perceived threats, with detailed guidance provided to help potential targets protect themselves.

## Article

In a significant cybersecurity revelation, the UK National Cyber Security Centre, in collaboration with the US and Dutch authorities, has unveiled details about the CHOSEN BRICK spyware used by Iranian state actors. This malicious software has been deployed to monitor dissidents, activists, and journalists worldwide, including those in the UK. The spyware is capable of gathering extensive data from victims, such as contacts, emails, and social media communications, and it can even capture screen content and access the device's microphone.

Iranian cyber attackers have been employing sophisticated social engineering tactics, impersonating trusted contacts on platforms like WhatsApp and Telegram to build rapport before deploying the spyware. These tactics have included deceptive methods such as fake MRI test results to lure targets into their trap. The UK government has emphasized its commitment to countering any foreign attempts at intimidation or surveillance, particularly those directed at individuals within its borders.

In response to this threat, the NCSC and its partners have released a comprehensive advisory containing technical analysis and guidance to help at-risk individuals identify and mitigate the threat of CHOSEN BRICK. This guidance is particularly crucial as the malware is known to persist even after a device reboot and is specifically targeted at the Windows operating system.

The advisory is part of a broader effort to support communities at risk of transnational repression. With specialized training rolled out across UK police forces and intelligence agencies, the country is equipping its personnel with the necessary tools to detect and disrupt such activities. The NCSC encourages those who may be at risk to familiarize themselves with the techniques outlined in the advisory and to utilize the available cyber defense resources to bolster their online security.
