The Jerusalem PostSuspect arrested in fatal shooting of 30-year-old man in Jaffa as police probe motive of incidentESPN DeportesBoston Celtics: resumen de temporada baja y previa 2026-27וואלהצה"ל: חוסל ראש חולייה מארגון הטרור גא"פ שפשט לכיסופים ב-7 באוקטוברRTP DesportoBenfica aponta ao tricampeonato de futsalInquirerDy thanks Marcos for directing VAT removal on system loss chargeDaily MaverickCULTURAL PHENOMENON: Star Trek at 60 and the optimistic future it still dares us to imagineESPNLeagues, unions urge action against escalating threats from bettorsDeadlineAmazon Prime Video Debuts $30-A-Month Bundle With AMC+, BritBox, MGM+, PBS Masterpiece & StarzABC NewsMeasles-related deaths in Pennsylvania rise to 4, health officials sayVarietyQuentin Tarantino to Publish ‘Cliff Booth’ Novel Before Brad Pitt and David Fincher’s Movie Streams on NetflixCBS Sports2026 Week 2 NFL odds, start times, betting lines, spreads: Get Week 2 NFL picks, predictions for every gameXatakaVivió hasta los 103 años, actuó en más de 90 películas y fue nominado a tres Óscar. Hoy su hijo es toda una leyenda de Hollywood
The Daily Newsstand · Free, Always
Tuesday, September 15, 2026

UK, US and Netherlands issue advisory on Iran-linked spyware

Translate

LONDON, Sept 15 : Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by Iranian state-linked actors to target dissidents, activists and journalists.

Britain's National Cyber Security Centre said Iranian state-linked cyber actors had used a spyware family known as "CHOSEN BRICK" to steal emails, messages and other sensitive information through "spear-phishing" campaigns on messaging platforms including WhatsApp and Telegram.

"The details of this cyber campaign reveal  how Iran ruthlessly uses digital surveillance in pursuit of  its  aim  to  repress critics of the regime, stealing emails and messages and accessing devices," Paul Chichester, NCSC Director of Operations, said in a statement.

Iran's embassy in London did not immediately respond to a request for comment.

The malware, according to the advisory, can collect information from contact lists, emails and social media accounts, capture screen content and access a device's microphone. The NCSC said some victims' personal details had later appeared on pro-Iranian leak sites. The FBI, in its own advisory, said Iran's Ministry of Intelligence and Security (MOIS) was using the malware to "collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets." 

The FBI did not immediately respond to a request for additional details on how many people have been targeted with the malware, or where they're located.

The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware.

The NCSC, alongside the FBI and the Netherlands' AIVD intelligence service, said Iran "almost certainly" uses cyber operations to help suppress people it sees as threats. 

The FBI's advisory said it was an update to a March 2026 warning describing alleged MOIS efforts to use the malware to collect data on targets, which was then posted online by a hacking persona known as "Handala Hack." 

Handala has targeted multiple U.S. companies and people since the start of the Iran war, including a destructive cyberattack against Michigan-based medical supplies and services supplier Stryker in March, and the leak of FBI Director Kash Patel's personal emails later that month.

Handala did not respond to an emailed request for comment on Tuesday.

View the original on Channel News Asia

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.