British Intelligence Exposes Iranian Spyware Targeting Dissidents
How Trusted Messages Can Become A Surveillance Trap
A Trusted-Looking Message Can Become A Route Into A Dissident’s Computer, Britain’s Cybersecurity Agency Warns.
Britain’s National Cyber Security Centre, part of GCHQ, has exposed an Iranian state-linked surveillance campaign alongside US and Dutch partners. Its 15 September warning describes CHOSEN BRICK spyware targeting dissidents, activists and journalists, including people in the UK. NCSC announcement.
One distinction matters immediately: the observed malware targets Windows computers. Contact through a messaging app does not make this an established iPhone or Android infection campaign. That detail changes which device a potential victim should ask a security specialist to examine.
The Familiar Name Is Part Of The Trap
The joint advisory describes attackers developing a relationship before persuading someone to open a disguised file. Lures have resembled legitimate applications or medical material; the guidance also describes attempts to move delivery from work equipment to personal devices. All observed infections in that advisory involved Windows. Joint technical advisory.
The practical lesson is broader than spotting spelling mistakes. A message can fit someone’s interests and still require independent verification. A useful question is whether the requested action makes sense: why should receiving a document require installing software, or why should a work-related file be opened outside the organisation’s normal protections?
The Risk Extends Beyond A Stolen Password
The NCSC says the spyware can take screenshots and access microphones, alongside collecting communications and contact information. It also reports that personal information from some victims appeared on pro-Iranian leak sites. These are the agency’s attributed findings, rather than a claim that every targeted person experienced every capability. NCSC findings.
For a journalist or campaigner, the consequences can spread through a network. A contact list may expose people who never received the original message. The value of a compromised computer therefore cannot be measured simply by whether money disappears from its owner’s bank account.
What A Useful Response Looks Like
High-risk individuals should use a separate, established route to verify unusual requests and involve their organisation’s security team if a suspicious file was opened. The NCSC’s dedicated guidance explicitly covers approaches to personal accounts as well as workplace messages. NCSC guidance for high-risk individuals.
In its related technical report, the FBI recommends current software, trusted download sources, anti-malware protection and strong account security. Its report uses the name HEAVYGRAM; analysts should preserve each source’s terminology when discussing particular samples. FBI technical report.
This warning makes a targeted campaign more visible. It does not establish that every unexpected message is state espionage, or that changing a phone setting removes malware from a separate laptop. The first useful step is identifying the suspicious action and the device on which it happened.

