Skip to the story
All stories

UK, US, Netherlands warn of Iranian spyware targeting dissidents

Joint cybersecurity advisory details 'CHOSEN BRICK' malware used in spear-phishing campaigns.

AI-assisted coverage comparison, editor-supervised · How this was made

Published
UK, US, Netherlands warn of Iranian spyware targeting dissidents

What this story says

  • British, US, and Dutch intelligence agencies issued a joint cybersecurity advisory about Iranian state-linked spyware.
  • The spyware, named 'CHOSEN BRICK', is used to steal sensitive information from dissidents, activists, and journalists.
  • Iranian actors deployed the malware through spear-phishing campaigns on messaging platforms like WhatsApp and Telegram.
  • Victims' personal details were later found on pro-Iranian leak sites, according to the FBI.

Who covered it

Left 0%(0)Centre 50%(6)Right 50%(7)

Percentages are shares of the 13 outlets carrying a published leaning rating. 13 of the 26 outlets we know ran this story carry no rating and are not counted in them. Coverage measured .

Trust

60/100

Craft

65/100

Hype

20/100

26 sources · methodology

Thin on the left so far

None of the 13 outlets with a published leaning rating that ran this story are rated left.

This story is still being watched, so it is a count and not yet a finding. Coverage keeps arriving for hours after an event, and a side that has published nothing this morning may publish by tonight. If it is still true when we stop checking, we will say so plainly.

British, US, and Dutch intelligence services have issued a joint cybersecurity advisory detailing spyware used by Iranian state-linked actors. The malware, known as 'CHOSEN BRICK', is designed to steal sensitive information from dissidents, activists, and journalists. According to the advisory, Iranian actors used spear-phishing campaigns on messaging platforms such as WhatsApp and Telegram to deploy the spyware.

The spyware is capable of capturing screen content, accessing device microphones, and collecting data from contact lists, emails, and social media accounts. The FBI stated that some victims' personal details were later found on pro-Iranian leak sites. The National Cyber Security Centre (NCSC) in Britain, part of GCHQ, collaborated with the FBI and the Netherlands' AIVD intelligence service on the warning.

Disagreement on malware capabilities

Protothema reported that the spyware could capture screen content, message history, and contact details including emails and social media messages. Channel News Asia, citing the NCSC, stated the malware can collect information from contact lists, emails, and social media accounts, capture screen content, and access a device's microphone. The FBI's advisory, as reported by Channel News Asia, indicated the malware is used to 'collect intelligence, conduct data leaks, and inflict reputational harm'.

What the coverage left out

None of the centre or right-rated reports mentioned the FBI's claim that some victims' personal details were later found on pro-Iranian leak sites. The FBI's specific statement on Iran's Ministry of Intelligence and Security (MOIS) using the malware for intelligence collection, data leaks, and reputational harm was also not mentioned in the right-rated reports.

Still developing. We have re-checked which outlets are covering this 6 times, most recently on 15 Sept 2026, 18:15, and will add the sides that appear.

How other outlets pictured it

Which photograph to run is each newsroom’s own choice. The leaning beside a name is that outlet’s published rating, not a claim that the pictures divide along it. Every picture is shown from the outlet’s own server and links to the article it ran in.

Figurines with computers and smartphones are seen in front of the words "Cyber Security" in this illustration taken, February 19, 2024. REUTERS/Dado Ruvic/Illustration
Channel News AsiaCentre

How each side covered it

Our own reading of the reporting listed below, written from the outlets’ articles rather than quoted from them. The reasoning is set out on our methodology page.

Left

0 rated outlets

No outlet rated left has run this story so far. We are still checking, and will say plainly if that does not change.

Centre

6 rated outlets

  • Seven centre-rated reports led on the joint warning issued by Britain, the US, and the Netherlands regarding Iranian state-linked spyware. These reports identified the spyware as 'CHOSEN BRICK' and stated its use against dissidents, activists, and journalists. Several mentioned the spear-phishing tactics employed via platforms like WhatsApp and Telegram. Channel News Asia and Devdiscourse noted that the FBI stated some victims' personal details appeared on pro-Iranian leak sites. Portfolio highlighted the spread of the spyware on popular messaging apps.

Right

7 rated outlets

  • Four right-rated reports focused on the joint cybersecurity advisory from Britain, the US, and the Netherlands concerning Iranian state-linked spyware. Protothema reported that the spyware 'CHOSEN BRICK' was used to steal data from dissidents, activists, and journalists worldwide, detailing its capabilities to capture screen content and access microphones. Reformatorisch Dagblad noted the Dutch General Intelligence and Security Service (AIVD) warning about Iran hacking devices of critics in the Netherlands, and its collaboration with British and American colleagues. The Jerusalem Post also mentioned the NCSC's statement on Iranian state-linked actors using 'CHOSEN BRICK' to steal sensitive information.

Questions about this coverage

How did the left and right cover UK, US, Netherlands warn of Iranian spyware targeting dissidents?
Of the 13 outlets on this story carrying a published leaning rating, 0% are rated left, 50% are rated centre, 50% are rated right. Those percentages are shares of the rated outlets, not of every outlet that ran it, which was 26. The sections above set out what each side emphasised, in its own terms.
Is UK, US, Netherlands warn of Iranian spyware targeting dissidents left or right?
Neither side dominates it. Of the 13 rated outlets on this story, 0% are rated left, 50% are rated centre, 50% are rated right, and no side holds the 70% this site would want before calling a field one-sided. A story is not left or right in any case; the outlets that carried it are what carry ratings.
Is the coverage of UK, US, Netherlands warn of Iranian spyware targeting dissidents biased?
UK, US, Netherlands warn of Iranian spyware targeting dissidents is one event reported by 26 outlets, and this page does not rate the story as biased or unbiased. What it publishes is the spread: which outlets ran it, where named rating organisations place each of them on the spectrum, and what each side chose to lead with. A leaning rating describes an outlet's record over time, not this article, and the two should not be run together.
Which side is not reporting UK, US, Netherlands warn of Iranian spyware targeting dissidents?
When we first saw this story, outlets rated left had barely covered it. Coverage accretes for hours after an event, so that is where to look rather than a verdict — the split above is the current count, and it is the one to read.
Which outlets covered UK, US, Netherlands warn of Iranian spyware targeting dissidents?
26 that we know of, every one of them listed further up this page with a link to its own report and to what we hold on the publisher. Nothing here is a summary of somebody else's summary: the outlets are named so the original reporting can be read.
What is the 'CHOSEN BRICK' spyware?
'CHOSEN BRICK' is a spyware family used by Iranian state-linked actors. It is designed to steal sensitive information from targets, including screen content, microphone access, contact lists, emails, and social media data.
Who is being targeted by this spyware?
The spyware is reportedly used to target dissidents, activists, and journalists. The advisory suggests that Iranian actors are using digital surveillance to repress critics of the regime.
How is the spyware deployed?
Iranian actors are deploying the 'CHOSEN BRICK' spyware through spear-phishing campaigns. These campaigns often occur on messaging platforms like WhatsApp and Telegram, where attackers may pose as trusted contacts.
Which countries issued the warning?
A joint cybersecurity advisory was issued by intelligence services from Britain, the United States, and the Netherlands. They collaborated to warn about the activities of the Iranian state-linked actors using this spyware.

Read it at the source

26 outlets, grouped by the leaning a published rating gives them. Every headline links to the original; an underlined outlet name opens our profile of that publisher.

Left

0

No outlet in this group ran the story.

Centre

6

Right

7

Not rated

13
Show 5 more

How did this read?

About the coverage, not about the story. We do not ask whether you agree with what happened — we have no honest use for that answer.

Iranian Spyware Warning | MediaBias News