The United States, United Kingdom and the Netherlands have warned that Iranian state-linked cyber actors are using spyware to target Iranian dissidents living abroad, with messaging platforms including WhatsApp and Telegram being used in attempts to steal sensitive information.
What Spyware Are Authorities Warning About?
The coordinated warning focuses on a spyware family known as “CHOSEN BRICK”.
Intelligence agencies from the three countries said the malware is allegedly being used by Iranian state-linked cyber actors in spear-phishing campaigns. The targets are primarily critics of the Iranian government and dissidents living outside Iran.
The US Federal Bureau of Investigation, Britain’s National Cyber Security Centre and the Netherlands’ AIVD intelligence service issued coordinated warnings about the cyber activity.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
How Are People Being Targeted?
The spyware is allegedly delivered through targeted spear-phishing campaigns on messaging services such as WhatsApp and Telegram.
These attacks are designed to persuade specific targets to interact with malicious content, allowing attackers to obtain sensitive information.
The warning describes the activity as part of a wider effort to monitor and gather intelligence on Iranian critics living overseas.
What Can the Spyware Be Used For?
The FBI said Iran’s Ministry of Intelligence and Security was using the malware to collect intelligence, conduct data leaks and cause reputational harm to intended targets.
British cyber authorities said the campaign showed how digital surveillance could be used against critics living abroad.
The warning adds to earlier concerns about cyber operations aimed at Iranian dissidents outside the country.
Have Similar Attacks Been Reported Before?
In March, the FBI described alleged efforts involving the same malware against targets that were posted online by a person known as “Handala Hack”.
That attack also affected medical technology company Stryker, with an Iran-linked hacking group claiming responsibility and describing it as the beginning of a new chapter in cyber warfare.
The so-called Handala hackers also claimed to have accessed the personal emails of FBI Director Kash Patel and shared photographs and documents online.
In July, US officials said a cyberattack targeting water systems in Minnesota resembled the “Handala Hack”.
Also Read: https://the420.in/handala-stryker-cyberattack-kash-patel-fbi-email-breach-iran/
Why Are Messaging Apps Important in These Attacks?
WhatsApp and Telegram are specifically identified as platforms used in the spear-phishing campaigns.
Instead of relying on broad attacks, spear-phishing focuses on particular individuals. The attackers attempt to reach their intended targets through messages designed to persuade them to interact with malicious content.
This makes unexpected messages, links or files particularly important to examine carefully when the recipient may be a high-risk target.
Who Is Most at Risk?
The warning specifically concerns Iranian dissidents and critics of the Iranian government living abroad.
Authorities said the cyber activity is aimed at collecting intelligence and sensitive information from intended targets.
The alleged operations can also involve leaking obtained information or using it to cause reputational damage.
The three countries have described the activity as part of continuing cyber efforts directed at dissidents overseas.
What Should High-Risk Users Watch For?
The method described in the warning relies heavily on targeted communication through familiar messaging platforms.
People who may be at heightened risk should therefore treat unexpected messages, links and requests for information cautiously, particularly when they arrive through WhatsApp or Telegram.
The warning also shows that a familiar messaging platform does not by itself make a message trustworthy. The identity of the sender and the legitimacy of any link or request should be checked before interacting with it.
The420 Cyber Takeaway: “Spyware Can Arrive Through an Ordinary Message”
The case highlights how sophisticated cyber surveillance does not always begin with an obvious technical attack. A carefully targeted WhatsApp or Telegram message can become the entry point.
For people facing heightened surveillance risks, recognising targeted phishing attempts and treating unexpected digital communication cautiously can be an important first line of defence.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics