British spies uncover Iranian cyber attacks targeting dissidents around the world

British intelligence have uncovered an Iranian spyware campaign stealing sensitive data from targets around the world.

Dissidents, activists and journalists were among those targeted, GCHQ's National Cyber Security Centre (NCSC) said.

Iranian "cyber actors" reportedly used spyware to collect information such as screen captures and messaging history.

Spies in the UK discovered the plot alongside allies in the US and Netherlands.

NCSC said they had watched Iranian state hackers trying to trick targets into downloading software that can track their movements.

The cyber criminals also impersonated contacts on services like WhatsApp, built rapport and then used spyware called 'CHOSEN BRICK' to steal sensitive information.

The spyware allows attackers to steal information on a target's contacts, such as emails and social media messages, NCSC said.

It can also allow them to capture screen content and access a device's microphone.

Attackers often tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, ⁠to persuade victims to download the malware, the NCSC said.

The agency said it was issuing new advice to those at risk.

Iran's embassy in London did not immediately respond to a request for comment.

The FBI, in its own advisory, said Iran's Ministry of Intelligence and Security (MOIS) ‌was using the malware to "collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets."

The US agency did not immediately respond to a request for additional details on how ‌many people have been targeted with the malware, or where they are located.

Tehran "almost certainly" uses ​cyber operations to help suppress people it sees as threats, the NCSC, the FBI ​and the Netherlands' AIVD intelligence service, said.

The FBI's advisory said ​it was an update to a March 2026 warning describing alleged MOIS efforts ⁠to use the malware to collect data on targets, which was then posted online by a hacking persona known as "Handala Hack".

Handala has targeted multiple US companies and people since the start ⁠of the Iran war, including a destructive
cyberattack against ​Michigan-based medical supplies and services supplier Stryker in March, and the leak of ​FBI Director Kash Patel's personal emails later that month.

Sky News

(c) Sky News 2026: British spies uncover Iranian cyber attacks targeting dissidents around the world

More from National Headlines

On Air Now The Happy Garden Podcast 6:00pm - 7:00pm
Now Playing
Leave A Light On Belinda Carlisle Download
Recently Played

Weather

Travel News

How To Listen

Download Our Apps

  • Available on the App Store
  • Available on Google Play

Podcasts