Tripartite Intelligence Report Highlights Iranian Cyber Campaigns

UK, US, and Dutch agencies reveal a coordinated Iranian operation targeting overseas dissidents with advanced spyware.
Intelligence services in the United Kingdom, the United States, and the Netherlands have jointly identified a sustained Iranian cyber-espionage campaign aimed at monitoring individuals abroad. According to the report published by GN geopolitics/cyber (en-US), the operation targeted dissidents, human rights activists, and journalists across multiple jurisdictions. The coordinated disclosure marks a significant escalation in the visibility of state-sponsored digital surveillance extending beyond Iran’s borders.
The campaign, which involved the deployment of sophisticated spyware, allowed actors to track physical locations, capture screen content, and access private communications. Officials from the UK National Cyber Security Centre, the FBI, and their Dutch counterparts stated that the tools were designed for comprehensive surveillance of mobile devices and online activity. The joint assessment concludes that Tehran utilizes these capabilities to suppress perceived threats, regardless of where they reside.
Deception Tactics Target Personal Trust
Attackers primarily employed social engineering techniques to compromise their targets. According to the intelligence report, operatives impersonated trusted contacts on messaging platforms such as WhatsApp to establish rapport. Once trust was established, victims were persuaded to download and install a malware package designated as “CHOSEN BRICK.” In one documented instance, the threat actors fabricated fake medical results to convince a target to open an infected file, demonstrating the tailored nature of the deception.
Once installed, the spyware granted extensive access to the device. The software could read contact lists, emails, and social media messages, while also capturing screenshots and remotely activating microphones. The NCSC noted that the tool further enabled the monitoring of victims' physical movements, effectively turning personal devices into surveillance instruments for the state. This level of intrusion exposes not only the targeted individuals but also their broader networks of associates.
Attribution Points to State Actors
The Federal Bureau of Investigation attributed the operation directly to Iran’s Ministry of Intelligence. The FBI stated that the ministry utilized the tools to harvest intelligence and damage the reputations of targeted individuals. This attribution aligns with a broader pattern of cyber operations linked to Iranian state entities. The total number of victims and their specific geographic locations have not been formally disclosed, limiting the public understanding of the campaign's full scale.
The joint assessment from the three intelligence agencies concluded that Tehran “almost certainly” uses cyber operations to suppress individuals it perceives as threats. This finding underscores that the Islamic Republic’s surveillance apparatus is not confined to its domestic borders. The evolution of these operations from open-source gathering to direct device infiltration represents a significant shift in the landscape of digital repression.
Data Leakage and Public Exposure
The risks associated with these operations extend beyond real-time surveillance. The FBI previously warned that exfiltrated data from earlier victims was published online by a group operating under the handle “Handala Hack.” This secondary distribution of stolen information amplifies the damage to victims, potentially exposing their private communications and personal details to the public domain. The combination of state surveillance and public data leakage creates a compounded threat to the safety and privacy of targeted individuals.
The Iranian Embassy in London did not respond to requests for comment before the publication of the findings. As the details of the “CHOSEN BRICK” campaign emerge, the focus of international security discourse is shifting toward the protection of diaspora communities and activists who face state-sponsored digital threats from abroad. The incident highlights the growing complexity of cybersecurity challenges in a geopolitical context where digital borders are increasingly porous.






