Iranian Cyber Actors Deploy CHOSEN BRICK Spyware Against Western Activists and Press
Summary
British intelligence has identified Iranian state-linked cyber actors utilizing the CHOSEN BRICK spyware family to compromise the communications of activists and journalists. This operation highlights Iran's ongoing asymmetric warfare capabilities and intent to gather intelligence on Western civil society, contributing to the broader information warfare dimension of the conflict.
Full Content
Sources (1)
Actor Responses
State-linked cyber actors deployed CHOSEN BRICK spyware to steal sensitive information from targets.
Not directly involved in the event, but the target demographic (Western press/activists) falls under US sphere of influence.
Related Events (3)
"The new event details the specific deployment of CHOSEN BRICK spyware by Iranian actors, which is the precise subject of the joint advisory issued by Western allies in event 12. Both events describe the same ongoing cyber campaign and intelligence gathering efforts against Western targets."
"Event 8 describes the IRGC's campaign to suppress international dissidents. The new event, involving the targeting of activists and journalists via spyware, is a specific tactical manifestation of this broader suppression and intelligence-gathering strategy."
"The new event is a joint advisory warning about the 'CHOSEN BRICK' spyware campaign, while recent event 4 describes the actual deployment of this specific spyware by Iranian actors. The advisory is a direct response to and documentation of the operational activity described in event 4, representing the same cyber conflict vector."