---
title: "UK, US, Netherlands warn of Iranian spyware targeting dissidents"
publication: "MediaBias News"
url: "https://mediabias.news/conflict/uk-us-netherlands-warn-of-iranian-spyware-targeting-dissidents"
api: "https://mediabias.news/api/v1/stories/uk-us-netherlands-warn-of-iranian-spyware-targeting-dissidents"
markdown: "https://mediabias.news/conflict/uk-us-netherlands-warn-of-iranian-spyware-targeting-dissidents.md"
audio: "https://mediabias.news/api/audio/uk-us-netherlands-warn-of-iranian-spyware-targeting-dissidents"
category: "Conflict & Security"
published: "2026-09-15T16:46:08.989Z"
source_reported: "2026-09-15T16:17:28.000Z"
updated: "2026-09-15T19:00:12.274Z"
trust_score: 60
critic_score: 65
hype_score: 20
assessment_type: "coverage-and-source-reporting-analysis"
fact_check_status: "not-performed"
coverage_measured: "2026-09-15T18:55:01.690Z"
---

# UK, US, Netherlands warn of Iranian spyware targeting dissidents

*Joint cybersecurity advisory details 'CHOSEN BRICK' malware used in spear-phishing campaigns.*

**Scores for the source reporting** (0-100, assessing the original journalism this article was written from, not this write-up): 

- Trust 60 of 100, higher is better. Central claim attributed to NCSC, FBI, and AIVD; two independent outlets corroborated.
- Craft 65 of 100, higher is better. Reporting includes quotes from officials and details on malware capabilities and targeting methods.
- Hype 20 of 100, lower is better. The language used is factual and avoids sensationalism, with a clear and informative headline.

Scored by MediaBias News; method at https://mediabias.news/methodology.

**The short version**

- British, US, and Dutch intelligence agencies issued a joint cybersecurity advisory about Iranian state-linked spyware.
- The spyware, named 'CHOSEN BRICK', is used to steal sensitive information from dissidents, activists, and journalists.
- Iranian actors deployed the malware through spear-phishing campaigns on messaging platforms like WhatsApp and Telegram.
- Victims' personal details were later found on pro-Iranian leak sites, according to the FBI.

British, US, and Dutch intelligence services have issued a joint cybersecurity advisory detailing spyware used by Iranian state-linked actors. The malware, known as 'CHOSEN BRICK', is designed to steal sensitive information from dissidents, activists, and journalists. According to the advisory, Iranian actors used spear-phishing campaigns on messaging platforms such as WhatsApp and Telegram to deploy the spyware.

The spyware is capable of capturing screen content, accessing device microphones, and collecting data from contact lists, emails, and social media accounts. The FBI stated that some victims' personal details were later found on pro-Iranian leak sites. The National Cyber Security Centre (NCSC) in Britain, part of GCHQ, collaborated with the FBI and the Netherlands' AIVD intelligence service on the warning.

## Disagreement on malware capabilities

Protothema reported that the spyware could capture screen content, message history, and contact details including emails and social media messages. Channel News Asia, citing the NCSC, stated the malware can collect information from contact lists, emails, and social media accounts, capture screen content, and access a device's microphone. The FBI's advisory, as reported by Channel News Asia, indicated the malware is used to 'collect intelligence, conduct data leaks, and inflict reputational harm'.

## What the coverage left out

None of the centre or right-rated reports mentioned the FBI's claim that some victims' personal details were later found on pro-Iranian leak sites. The FBI's specific statement on Iran's Ministry of Intelligence and Security (MOIS) using the malware for intelligence collection, data leaks, and reputational harm was also not mentioned in the right-rated reports.

## Who covered it

Shares of the 19 covering outlets with a published leaning rating:

- Left: 16% (3)
- Centre: 31% (6)
- Right: 53% (10)

16 of 35 covering outlets carried no usable leaning rating and were excluded from those percentages. Coverage measured 2026-09-15T18:55:01.690Z.

**Coverage watch:** developing. Checked 9 times; 1 check found a material change. Most recently checked 2026-09-15T19:00:12.274Z.

## How the sides framed it

### Left

- The Independent's report stated that Iranian agents used social engineering tactics, such as fake MRI results, to trick individuals into downloading spyware. This malware, known as Chosen Brick, allowed access to contacts, emails, social media, and device microphones.
- The National Cyber Security Centre (NCSC) warned that the spyware targeted dissidents, activists, and journalists. The FBI claimed Iran's Ministry of Intelligence and Security used the malware for intelligence gathering and to inflict reputational harm.
- The Independent's report noted that the malware targeted Windows operating systems and could survive device reboots. Some stolen personal details were posted on pro-Iranian leak sites, according to the NCSC.

### Centre

- Seven centre-rated reports led on the joint warning issued by Britain, the US, and the Netherlands regarding Iranian state-linked spyware. These reports identified the spyware as 'CHOSEN BRICK' and stated its use against dissidents, activists, and journalists. Several mentioned the spear-phishing tactics employed via platforms like WhatsApp and Telegram. Channel News Asia and Devdiscourse noted that the FBI stated some victims' personal details appeared on pro-Iranian leak sites. Portfolio highlighted the spread of the spyware on popular messaging apps.

### Right

- Four right-rated reports focused on the joint cybersecurity advisory from Britain, the US, and the Netherlands concerning Iranian state-linked spyware. Protothema reported that the spyware 'CHOSEN BRICK' was used to steal data from dissidents, activists, and journalists worldwide, detailing its capabilities to capture screen content and access microphones. Reformatorisch Dagblad noted the Dutch General Intelligence and Security Service (AIVD) warning about Iran hacking devices of critics in the Netherlands, and its collaboration with British and American colleagues. The Jerusalem Post also mentioned the NCSC's statement on Iranian state-linked actors using 'CHOSEN BRICK' to steal sensitive information.

**Provisional coverage gap:** left. The watch is not closed, so this is not yet a settled blindspot finding.

## Factuality profile of the covering outlets

These are published factuality ratings of the outlets, not a verdict on whether this story or its claims are true.

- veryLow: 1
- mixed: 6
- high: 11
- unknown: 16
- veryHigh: 1

## Verification scope

This page compares coverage and scores the source reporting. It is not a ClaimReview verdict on whether the underlying event or claim is true.

## Original reporting this was written from

- [IT Security News - cybersecurity, infosecurity news](https://itsecuritynews.info/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware) — Iranian spies hit Windows machines with Chosen Brick data-stealing malware
- [SANA](https://sana.sy/international/2581625) — Britain, America and the Netherlands Are Issuing a Warning About Iranian Spying Programs.
- [The Independent](https://independent.co.uk/news/world/middle-east/iran-state-actors-spyware-ncsc-warning-b3050729.html) — Iranian state actors targeting dissidents and activists with spyware
- [The Independent (US)](https://the-independent.com/news/world/middle-east/iran-state-actors-spyware-ncsc-warning-b3050729.html) — Iranian state actors targeting dissidents and activists with spyware
- [Globo](https://valor.globo.com/mundo/noticia/2026/09/15/reino-unido-eua-e-holanda-emitem-alerta-sobre-software-espio-ligado-ao-ir.ghtml) — UK, USA and Netherlands Issue Spyware Alert Linked to Iran
- [The Algemeiner](https://algemeiner.com/2026/09/15/uk-us-netherlands-issue-advisory-iran-linked-spyware) — UK, US, Netherlands Issue Advisory on Iran-Linked Spyware
- [연합뉴스-Yonhap News Agency](https://yna.co.kr/view/AKR20260916003200085) — US, UK, and Netherlands Warn of Iran-Linked Spyware… "Targeted Tracking"
- [enikos.gr](https://enikos.gr/international/vretania-ipa-kai-ollandia-proeidopoioun-gia-iraniko-spyware-stochoi-dimosiografoi-aktivistes-kai-antifronountes/2644542) — Britain, US and Netherlands Warn of Iranian Spyware - Targeting Journalists, Activists and Dissidents
- [NOS](https://nos.nl/artikel/2631145-aivd-iran-breekt-online-in-bij-dissidenten-om-gevoelige-informatie-te-stelen) — AIVD: Iran Breaks Into Dissidents' Online Accounts to Steal Sensitive Information
- [KAYHAN LIFE](https://kayhanlife.com/news/iran/uk-us-and-netherlands-issue-advisory-on-iran-linked-spyware) — UK, US and Netherlands Issue Advisory on Iran-Linked Spyware
- [ERT NEWS](https://ertnews.gr/eidiseis/diethni/vretania-ipa-kai-ollandia-proeidopoioun-gia-iraniko-logismiko-ypoklopis) — Britain, US and Netherlands Warn of Iranian Spyware
- [ARY News](https://arynews.tv/uk-us-and-netherlands-issue-advisory-on-iran-linked-spyware) — UK, US and Netherlands issue advisory on Iran-linked spyware
- [Aleph News](https://alephnews.ro/guvern/iranul-acuzat-de-o-ampla-operatiune-de-spionaj-cibernetic-disidenti-si-jurnalisti-din-intreaga-lume-vanati-cu-spyware-inclusiv-prin-whatsapp-ce-spun-serviciile-de-informatii-occidentale) — Iran, Accused of an Extensive Cyber Spying Operation: Dissidents and Journalists, Hunted with Spyware, Including Through WhatsApp. What Western Information Services Say
- [BizToc](https://biztoc.com/x/78e2826d7c838b59) — UK, US, Netherlands warn of Iranian spyware
- [Protothema](https://protothema.gr/world/article/1879267/iranoi-haker-eklevan-dedomena-me-spyware-apo-adifronoudes-aktivistes-kai-dimosiografous-se-olo-ton-kosmo) — Iranian Hackers Stole Data with Spyware From Dissidents, Activists and Journalists Around the World
- [Asharq AL-awsat](https://english.aawsat.com/world/5318670-uk-us-and-netherlands-issue-advisory-iran-linked-spyware) — UK, US and Netherlands Issue Advisory on Iran-Linked Spyware
- [NewsBomb](https://newsbomb.gr/kosmos/story/1763572/vretanoi-kataskopoi-apokalypsan-iranikes-kyvernoepitheseis-me-stoxo-antifronoyntes-ana-ton-kosmo) — British Spies Uncover Iranian Cyberattacks Targeting Dissidents Around the World
- [Portfolio](https://portfolio.hu/uzlet/20260915/veszelyes-kemszoftver-terjed-a-nepszeru-uzenetkuldokon-kiadtak-a-figyelmeztetest-862936) — Dangerous Spyware Spreads on Popular Messaging Apps, Warning Issued
- [insider.gr](https://insider.gr/eidiseis/424881/inomeno-basileio-ipa-kai-ollandia-proeidopoioyn-gia-kakoboylo-logismiko-apo-iran) — UK, US and Netherlands Warn of Malware From Iran
- [Capital.gr](https://capital.gr/diethni/4017026/inomeno-basileio-ipa-kai-ollandia-ekdidoun-proeidopoiisi-sxetika-me-logismiko-upoklopis-apo-to-iran) — UK, US and Netherlands Issue Warning About Spyware From Iran
- [Great Yorkshire Radio](https://greatyorkshireradio.co.uk/uk/british-spies-uncover-iranian-cyber-attacks-targeting-dissidents-around-the-world) — British Spies Uncover Iranian Cyber Attacks Targeting Dissidents Around The World
- [NDTV](https://ndtv.com/world-news/iran-uses-spyware-like-chosen-brick-to-target-dissidents-us-uk-advisory-12050793) — Iran Uses Spyware Like 'Chosen Brick' To Target Dissidents: US-UK Advisory
- [Business Daily](https://businessdaily.gr/diethni/232197_proeidopoiisi-bretanias-ipa-kai-ollandias-gia-iraniko-logismiko-ypoklopis) — US, UK and Netherlands Warn of Iranian Spyware
- [Unknown](https://eurointegration.com.ua/news/2026/09/15/7245545) — UK, US and Netherlands Warned of Iranian Cyber Spying Campaign
- [Reformatorisch Dagblad](https://rd.nl/a/aivd-iran-hackt-apparaten-van-critici-in-nederland) — AIVD: Iran Hacks Devices of Critics in the Netherlands
- [Unknown](https://alquds.co.uk/%D8%A8%D8%B1%D9%8A%D8%B7%D8%A7%D9%86%D9%8A%D8%A7-%D9%88%D8%A3%D9%85%D8%B1%D9%8A%D9%83%D8%A7-%D9%88%D9%87%D9%88%D9%84%D9%86%D8%AF%D8%A7-%D8%AA%D8%B5%D8%AF%D8%B1-%D8%AA%D8%AD%D8%B0%D9%8A%D8%B1%D8%A7) — Britain, America and the Netherlands Issue a Warning About Iranian Spying Programs.
- [Naftemporiki](https://naftemporiki.gr/kosmos/2161876/kampanaki-apo-vretania-ipa-kai-ollandia-gia-logismiko-kataskopeias-poy-syndeetai-me-to-iran) — "Bell" From Britain, US and Netherlands for Spy Software Linked to Iran
- [Devdiscourse](https://devdiscourse.com/article/law-order/3977507-global-alert-iranian-spyware-targeting-activists-revealed) — Global Alert: Iranian Spyware Targeting Activists Revealed
- [cedarnews.net](https://cedarnews.net/nederlands/985876/cyberactoren-iran-zetten-malware-dissidenten-activisten-journalisten) — Cyber Actors From Iran Deploy Malware Against Dissidents, Activists, and Journalists.
- [Jerusalem Post](https://jpost.com/middle-east/iran-news/article-908693) — Western intelligence warns of Iranian cyber campaign using spyware against activists, press
- [Market Screener](https://marketscreener.com/news/uk-us-and-netherlands-issue-advisory-on-iran-spyware-ce785bdddc8ef120) — UK, US and Netherlands issue advisory on Iran spyware
- [Reuters](https://reuters.com/world/uk-us-netherlands-issue-advisory-iran-spyware-2026-09-15) — UK, US and Netherlands issue advisory on Iran spyware
- [Channel News Asia](https://channelnewsasia.com/business/uk-us-and-netherlands-issue-advisory-iran-spyware-6386571) — UK, US and Netherlands issue advisory on Iran spyware
- [WTVB](https://wtvbam.com/2026/09/15/uk-us-and-netherlands-issue-advisory-on-iran-spyware) — UK, US and Netherlands issue advisory on Iran spyware
- [CNN Brasil](https://cnnbrasil.com.br/economia/money/tecnologia/reino-unido-eua-e-holanda-emitem-alerta-sobre-spyware-ligado-ao-ira) — UK, USA and Netherlands Issue Spyware Alert Linked to Iran

## Questions

**What is the 'CHOSEN BRICK' spyware?**

'CHOSEN BRICK' is a spyware family used by Iranian state-linked actors. It is designed to steal sensitive information from targets, including screen content, microphone access, contact lists, emails, and social media data.

**Who is being targeted by this spyware?**

The spyware is reportedly used to target dissidents, activists, and journalists. The advisory suggests that Iranian actors are using digital surveillance to repress critics of the regime.

**How is the spyware deployed?**

Iranian actors are deploying the 'CHOSEN BRICK' spyware through spear-phishing campaigns. These campaigns often occur on messaging platforms like WhatsApp and Telegram, where attackers may pose as trusted contacts.

**Which countries issued the warning?**

A joint cybersecurity advisory was issued by intelligence services from Britain, the United States, and the Netherlands. They collaborated to warn about the activities of the Iranian state-linked actors using this spyware.

---

MediaBias News — https://mediabias.news. Reproduced from https://mediabias.news/conflict/uk-us-netherlands-warn-of-iranian-spyware-targeting-dissidents. Please cite as: MediaBias News, "UK, US, Netherlands warn of Iranian spyware targeting dissidents", https://mediabias.news/conflict/uk-us-netherlands-warn-of-iranian-spyware-targeting-dissidents