Western Agencies Expose Iranian State Spyware Targeting Dissidents and Journalists
Three Western intelligence agencies have exposed a sophisticated spyware operation linked to Iran's Ministry of Intelligence and Security (MOIS), detailing how state actors deploy surveillance malware to target dissidents, activists, and journalists. The joint advisory, published September 15, 2026, marks an escalation in documented Iranian cyber operations against perceived adversaries.
Britain's National Cyber Security Centre (NCSC), the U.S. Federal Bureau of Investigation (FBI), and the Netherlands' AIVD intelligence service issued the warning about a malware family tracked as CHOSEN BRICK. The advisory updates a March 2026 FBI warning about MOIS data collection efforts, which were subsequently published online by the Handala Hack persona.
The spyware can extract data from contact lists, emails, and social media accounts, capture screenshots, and activate device microphones for audio surveillance. According to the NCSC, some victims' personal information later appeared on pro-Iranian leak sites, representing what authorities describe as a coordinated surveillance and intimidation campaign.
Technical Operations and Infrastructure
CHOSEN BRICK uses Telegram for command and control communications to blend in with legitimate processes, making detection more difficult. The malware exfiltrates stolen data through a combination of Telegram bots and cloud storage services including VultrObjects and StorjShare, according to the NCSC advisory.
Attackers employ sophisticated social engineering tactics, impersonating trusted contacts on WhatsApp and Telegram with customized approaches for each target. Some documented lures include fabricated documents such as fake medical imaging results designed to trick victims into downloading the malicious payload.
Attribution and Broader Campaign Context
The FBI attributed the tool directly to Iran's Ministry of Intelligence and Security, stating it is used to collect intelligence, conduct data leaks, and inflict reputational harm against intended targets. The threat actor behind CHOSEN BRICK, known as Void Manticore, has operated under multiple online personas since at least mid-2022, including Homeland Justice, Karma, and Handala Hack, targeting entities across Albania, Israel, and the United States.
Between February 2024 and February 2025, the group conducted over 85 documented attacks, with healthcare as the most frequently targeted sector, followed by IT, education, and government institutions. MOIS cyber operations have been a long-standing concern for Western governments, with the U.S. Treasury Department sanctioning the agency in September 2022 for malicious cyber activities dating back to at least 2007.
Recent High-Profile Operations
The advisory comes amid heightened tensions following several prominent attacks. In March 2026, Handala Hack claimed responsibility for a destructive attack against Michigan-based medical technology company Stryker Corporation. The attackers compromised administrator accounts and weaponized Microsoft Intune, Stryker's cloud-based mobile device management platform, to issue remote wipe commands affecting approximately 56,000 employees across more than 61 countries.
On March 27, 2026, the same group breached FBI Director Kash Patel's personal email account, publishing over 300 emails and photos spanning from approximately 2011 to 2022. The FBI confirmed the breach involved only historical personal information with no classified data compromised. In response, the U.S. Department of Justice seized four MOIS-controlled websites in March 2026, including handala-hack[.]to and handala-redwanted[.]to, which were used to claim credit for attacks and publish personally identifiable information.
The group previously disrupted Albanian government computer systems in July 2022 using the Homeland Justice persona, forcing Albania to suspend online public services for citizens.
Protection Guidance
Paul Chichester, NCSC Director of Operations, emphasized the ruthlessness of Iran's digital surveillance tactics. The agencies recommend individuals verify contacts before opening files, avoid unsolicited documents on messaging applications, enable app-store-only installations, and not disable security warnings when downloading files.
The FBI did not disclose the total number of victims or their locations. The advisory notes that Iran relies on cyber operations as part of efforts to suppress those it views as threats to state interests.


