{"id":75997,"date":"2026-09-15T17:08:20","date_gmt":"2026-09-15T17:08:20","guid":{"rendered":"https:\/\/newsvog.com\/ur\/75997"},"modified":"2026-09-15T17:08:21","modified_gmt":"2026-09-15T17:08:21","slug":"uk-us-and-netherlands-issue-advisory-on-iran-linked-spyware","status":"publish","type":"post","link":"https:\/\/newsvog.com\/ur\/75997","title":{"rendered":"UK, US and Netherlands issue advisory on Iran-linked spyware"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div style=\"font-size:16px;line-height:1.6\">\n<p><strong>LONDON: Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by \u200bIranian state-linked actors to target dissidents, activists and journalists.<\/strong><\/p>\n<p><span>Britain\u2019s National Cyber Security Centre \u200csaid Iranian state-linked cyber actors had used a spyware family known as \u201cCHOSEN BRICK\u201d to steal emails, messages and other sensitive information through \u201cspear-phishing\u201d campaigns on messaging platforms including WhatsApp and Telegram.<\/span><\/p>\n<p><span>\u201cThe details of this cyber campaign reveal \u202fhow \u200bIran ruthlessly uses digital surveillance in pursuit of\u202f its\u202f aim\u202f to \u202frepress critics of the \u200bregime, stealing emails and messages and accessing devices,\u201d Paul Chichester, NCSC director of \u2060operations, said in a statement.<\/span><\/p>\n<p><span>Iran\u2019s embassy in London did not immediately respond to a request \u200bfor comment.<\/span><\/p>\n<p><span>The malware, according to the advisory, can collect information from contact lists, emails and social \u200bmedia accounts, capture screen content and access a device\u2019s microphone. The NCSC said some victims\u2019 personal details had later appeared on pro-Iranian leak sites. The FBI, in its own advisory, opens new tab, said Iran\u2019s Ministry of Intelligence and Security (MOIS) \u200bwas using the malware to \u201ccollect intelligence, conduct data leaks, and inflict reputational harm against their \u200bintended targets.\u201d<\/span><\/p>\n<p><span>The FBI declined to share additional details on how many people have been targeted with the malware, \u200cor where \u2060they\u2019re located.<\/span><\/p>\n<p><span>The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware.<\/span><\/p>\n<p><span>The NCSC, alongside the FBI and \u200bthe Netherlands\u2019 AIVD intelligence \u200bservice, said Iran \u201calmost certainly\u201d \u2060uses cyber operations to help suppress people it sees as threats.<\/span><\/p>\n<p><span>The FBI\u2019s advisory said it was an update to a March 2026 warning \u200bdescribing alleged MOIS efforts to use the malware to collect data on \u200btargets, which \u2060was then posted online by a hacking persona known as \u201cHandala Hack.\u201d<\/span><\/p>\n<p><span>Handala has targeted multiple U.S. companies and people since the start of the Iran war, including a destructive cyberattack against Michigan-based medical supplies and \u2060services supplier \u200bStryker in March, and the leak of FBI Director Kash \u200bPatel\u2019s personal emails later that month.<\/span><\/p>\n<p><span>Handala did not respond to an emailed request for comment on Tuesday.<\/span><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/arynews.tv\/uk-us-and-netherlands-issue-advisory-on-iran-linked-spyware\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>LONDON: Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by \u200bIranian state-linked actors to target dissidents, activists and journalists. Britain\u2019s National Cyber Security Centre \u200csaid Iranian state-linked cyber actors had used a spyware family known as \u201cCHOSEN BRICK\u201d to steal emails, messages and other sensitive information through \u201cspear-phishing\u201d&#8230;<\/p>\n","protected":false},"author":1,"featured_media":75998,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-75997","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pakistan"],"taxonomy_info":{"category":[{"value":16,"label":"Pakistan"}]},"featured_image_src_large":["https:\/\/newsvog.com\/ur\/wp-content\/uploads\/Cyber-Security-1024x576.jpg",1024,576,true],"author_info":{"display_name":"frkhokhar@gmail.com","author_link":"https:\/\/newsvog.com\/ur\/author\/frkhokhargmail-com"},"comment_info":0,"category_info":[{"term_id":16,"name":"Pakistan","slug":"pakistan","term_group":0,"term_taxonomy_id":16,"taxonomy":"category","description":"All about Pakistan","parent":0,"count":5401,"filter":"raw","cat_ID":16,"category_count":5401,"category_description":"All about Pakistan","cat_name":"Pakistan","category_nicename":"pakistan","category_parent":0}],"tag_info":false,"_links":{"self":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts\/75997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/comments?post=75997"}],"version-history":[{"count":1,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts\/75997\/revisions"}],"predecessor-version":[{"id":75999,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts\/75997\/revisions\/75999"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/media\/75998"}],"wp:attachment":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/media?parent=75997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/categories?post=75997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/tags?post=75997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}