/* ═══ DEPTH LAYER (server-rendered news pages) ═══ Matches the homepage: layered elevation + transform-only hovers, so the article and category pages share one visual language. No WebGL — the lead image on an article page is the LCP element. */ :root{ --e1:0 1px 2px rgba(13,13,13,.05),0 1px 3px rgba(13,13,13,.04); --e2:0 2px 4px rgba(13,13,13,.05),0 6px 14px rgba(13,13,13,.07); --e3:0 8px 16px rgba(13,13,13,.08),0 18px 38px rgba(13,13,13,.11); --ease:cubic-bezier(.22,1,.36,1); --spring:cubic-bezier(.34,1.4,.64,1); } .np-card,.rel-card,.cat-card,.art-related-card,.qc-card{border-radius:14px;box-shadow:var(--e1);overflow:hidden; transition:transform .3s var(--ease),box-shadow .3s var(--ease),border-color .3s} .np-card:hover,.rel-card:hover,.cat-card:hover,.art-related-card:hover,.qc-card:hover{transform:translateY(-5px);box-shadow:var(--e3);border-color:transparent} .np-card img,.rel-card img,.cat-card img,.art-related-card img,.qc-card img{transition:transform .55s var(--ease)} .np-card:hover img,.rel-card:hover img,.cat-card:hover img,.art-related-card:hover img,.qc-card:hover img{transform:scale(1.06)} article img[fetchpriority="high"]{border-radius:16px;box-shadow:var(--e3)} .np-pill{border-radius:999px;box-shadow:var(--e1);transition:transform .16s var(--spring),box-shadow .16s} .np-pill:hover{transform:translateY(-2px);box-shadow:var(--e2)} @media(hover:none){.np-card,.rel-card,.cat-card,.art-related-card,.qc-card{transform:none!important}} @media(prefers-reduced-motion:reduce){*{animation-duration:.01ms!important;transition-duration:.01ms!important} .np-card,.rel-card,.cat-card,.np-pill{transform:none!important}}
BREAKING
World

UK, US and Netherlands Expose Iranian 'CHOSEN BRICK' Spyware

📅 Published: 15 Sept 2026, 09:14 pm IST 🔄 Updated: 15 Sept 2026, 09:14 pm IST 10 min read 1 views
The National Cyber Security Centre headquarters in London, where officials announced the discovery of Iranian-linked CHOSEN BRICK spyware.
The National Cyber Security Centre in London, UK.
Key Points
  • UK, US, and Netherlands expose CHOSEN BRICK spyware
  • Iranian state actors targeted journalists and dissidents
  • NCSC confirms global scale of digital surveillance campaign
  • Spyware designed to compromise mobile and desktop devices
  • Intelligence agencies warn of ongoing threat to human rights

British intelligence services, working alongside counterparts in the United States and the Netherlands, have formally identified a sophisticated cyber campaign linked to the Iranian state. Officials at the National Cyber Security Centre (NCSC) confirmed on Tuesday, 15 September 2026, that the operation utilised a previously undisclosed piece of malicious software, dubbed 'CHOSEN BRICK', to monitor and extract data from high-profile individuals.

The targets of this digital dragnet include international journalists, human rights activists, and political dissidents who have frequently challenged the Iranian administration from abroad. This disclosure marks a significant escalation in the ongoing digital contest between Western intelligence agencies and Tehran's state-backed cyber units.

Government officials said the discovery was the result of months of forensic analysis across three continents. The coalition of nations aims to disrupt the infrastructure that allows such spyware to function, effectively neutralising the immediate threat to those currently under surveillance.

The move represents a coordinated effort to expose the methods used by state actors to suppress dissent beyond their own borders. By making the technical details of CHOSEN BRICK public, the NCSC and its partners are attempting to force a change in the operational patterns of the attackers.

This is not merely a technical warning but a clear geopolitical signal that the targeting of individuals on European soil will not go unnoticed by Western security apparatuses.

The NCSC has urged organisations and individuals who believe they may have been targeted to review their security protocols immediately.

Inside the Mechanics of the CHOSEN BRICK Spyware

The CHOSEN BRICK spyware operates with a level of technical sophistication that experts said distinguishes it from common commercial surveillance tools. Unlike basic malware that relies on brute-force entry, this software employs a multi-stage infection process designed to evade standard detection systems.

Sources confirmed that once a device is compromised, the spyware establishes a persistent connection to remote command-and-control servers, allowing operators to exfiltrate sensitive documents, private messages, and real-time location data.

Technical assessments indicate that the malware is capable of bypassing end-to-end encryption by capturing data before it is encrypted by the application or after it has been decrypted upon receipt.

This capability makes it particularly lethal for journalists and activists who rely on encrypted messaging services to communicate with sources within Iran.

The NCSC report highlights that the spyware is often delivered via spear-phishing campaigns, where targets are sent bespoke lures tailored to their professional interests or personal social circles.

Once the user clicks a malicious link or opens a compromised document, the malware installs itself in the background, consuming minimal system resources to remain hidden from the device's operating system.

Experts noted that the modular nature of CHOSEN BRICK allows the attackers to update its capabilities remotely, adding new features such as microphone activation or screen recording without requiring a secondary installation.

This flexibility suggests a high degree of investment in the development and maintenance of the tool by a state-funded entity.

The intelligence community is now working to map the full extent of the infection, which has been detected on devices across multiple jurisdictions, including the UK, the Netherlands, and several countries in the Middle East.

The Global Reach of Tehran's Digital Surveillance

The reach of the CHOSEN BRICK campaign extends far beyond the borders of Iran, affecting individuals living in exile across Europe and North America. By targeting dissidents in London, Amsterdam, and Washington, the Iranian state is attempting to exert control over the information flow that reaches the Iranian public from the outside world.

Officials said the primary goal of this operation is to identify the sources of leaks and to monitor the organisational activities of opposition groups.

The psychological impact on these communities is profound, as the threat of digital surveillance forces many to limit their professional activities and self-censor their public statements.

For journalists, the risk is twofold: the loss of personal privacy and the potential exposure of their sources, which could lead to severe consequences for those still residing within Iran.

The NCSC has observed that the targeting is highly selective, focusing on individuals who have demonstrated a sustained capacity to influence public opinion or provide critical reporting on Iranian domestic affairs.

This pattern of behaviour mirrors previous state-sponsored cyber operations, yet the introduction of CHOSEN BRICK marks a departure in terms of its stealth and effectiveness.

The international nature of the campaign has necessitated a cross-border response, with the UK, US, and Netherlands sharing intelligence to create a unified defence.

This collaboration is essential, as the attackers often route their traffic through servers in multiple countries to obscure the origin of the command-and-control infrastructure.

By exposing these nodes, the allied nations are effectively cutting off the 'eyes and ears' of the Iranian operators, forcing them to rebuild their network from scratch.

Why European Democracies Are Now on High Alert

The discovery of CHOSEN BRICK has triggered a broader debate within European security circles regarding the protection of democratic values in the digital age. As state actors become more adept at using cyber tools to harass and intimidate citizens, the burden on national intelligence agencies to provide protection has grown exponentially.

European officials said that the use of such spyware against residents in the UK and the Netherlands is a violation of international norms and a direct challenge to the rule of law.

The threat is not just limited to the individual; it extends to the integrity of the democratic process, as the silencing of journalists and activists undermines the public's access to independent information.

Many analysts have pointed out that the current regulatory framework in Europe, while robust in terms of data privacy, is struggling to keep pace with the rapid evolution of state-sponsored cyber warfare.

The NCSC's decision to go public with the details of CHOSEN BRICK is a strategic move to raise awareness among the private sector and civil society.

By providing technical indicators of compromise, the agency is enabling organisations to bolster their own defences, effectively crowdsourcing the security of the digital space.

This approach is seen as more effective than traditional diplomatic protests, which often fail to deter state actors who operate in the shadows.

The focus is now shifting towards building a more resilient digital infrastructure that can withstand such targeted intrusions, ensuring that European democracies remain safe havens for free speech and political expression.

The alliance between the UK, US, and the Netherlands is expected to expand, with other nations likely to be invited to join the intelligence-sharing initiative in the coming weeks.

Intelligence Cooperation Across the Atlantic and North Sea

The success of the operation to expose CHOSEN BRICK is a testament to the depth of intelligence sharing between the UK, the US, and the Netherlands. Sources confirmed that the NCSC worked closely with the American National Security Agency (NSA) and Dutch security services to piece together the puzzle of the Iranian operation.

This level of cooperation is critical in the modern cyber landscape, where threats often span multiple jurisdictions and require a rapid, synchronised response.

The intelligence agencies involved have developed a shared repository of technical data, allowing them to track the movement of the spyware in real-time.

This collaborative model allows for a more comprehensive view of the threat, as each nation contributes unique insights based on their own monitoring capabilities.

For example, while the UK may detect an initial intrusion attempt, the US might provide the technical analysis of the command-and-control server, and the Netherlands could offer insights into the specific vulnerabilities being exploited.

This synergy is essential for identifying the patterns that indicate a state-sponsored campaign rather than a random criminal enterprise.

The agencies are also working to develop new tools and techniques to counter such spyware, sharing these innovations with their partners to ensure a unified front.

The ongoing partnership is expected to evolve into a more permanent structure for cyber defence, as the threat from state actors continues to grow in complexity.

Officials said that the goal is not just to react to individual attacks but to build a proactive system that can anticipate and neutralise threats before they cause significant damage.

The Future of State-Sponsored Digital Threats

As we look ahead, the landscape of cyber warfare is likely to become even more contested. The use of CHOSEN BRICK is a clear indicator that state actors are willing to invest heavily in the development of bespoke tools to achieve their strategic objectives.

Experts said that we should expect to see more of these 'boutique' spyware campaigns, which are designed to be used against specific targets rather than for mass surveillance.

This shift makes detection much harder, as the signature of the malware is often unique to the target.

The international community will need to develop new legal and diplomatic mechanisms to hold these states accountable for their actions.

This could include targeted sanctions against the entities responsible for developing and deploying the spyware, as well as greater transparency in the attribution process.

The role of the private sector will also be crucial, as technology companies and cybersecurity firms play a key role in identifying and patching the vulnerabilities that these state actors exploit.

The NCSC's focus on transparency is a step in the right direction, but much more needs to be done to ensure that the internet remains a space for open communication.

The coming years will likely see a race between the developers of these advanced spyware tools and the defenders who are working to protect the digital ecosystem.

The outcome of this race will have significant implications for the future of global security and the protection of individual rights in the digital age.

The commitment shown by the UK and its allies to expose these threats is a vital component of this ongoing effort.

What Dissidents and Journalists Must Do Now

For those who believe they may be at risk, the NCSC has provided a series of recommendations to enhance their digital security. First and foremost, individuals should ensure that all devices are updated to the latest software versions, as these often contain critical security patches that can block known vulnerabilities.

Second, the use of hardware security keys for two-factor authentication is strongly encouraged, as these provide a much higher level of protection than SMS-based codes.

Third, journalists and activists should be extremely cautious when opening unsolicited emails or messages, even if they appear to come from trusted contacts.

If a message seems suspicious, it is better to verify it through an alternative channel before clicking any links or downloading attachments.

The NCSC also recommends that individuals review their privacy settings on social media and messaging platforms, limiting the amount of personal information that is publicly available.

For those in high-risk roles, the use of encrypted communication tools that are known for their security and transparency is essential.

Finally, if any suspicious activity is detected, it should be reported to the relevant national cybersecurity authority immediately.

Taking these steps can significantly reduce the risk of falling victim to campaigns like the one involving CHOSEN BRICK.

The goal is to make the cost of such attacks prohibitively high for the perpetrators, thereby deterring future attempts.

By staying informed and vigilant, the community of journalists and activists can continue to do their vital work while minimising the threat posed by state-sponsored cyber espionage.

Frequently Asked Questions

What is CHOSEN BRICK?
CHOSEN BRICK is a sophisticated piece of spyware identified by the NCSC and international partners as being used by Iranian state actors to target dissidents, journalists, and activists globally.
How does this spyware infect devices?
The spyware is typically delivered via spear-phishing campaigns, where targets are sent tailored links or documents that, when opened, install the malicious software in the background.
Which countries are involved in the investigation?
The investigation and subsequent warning were a coordinated effort between the United Kingdom, the United States, and the Netherlands.
Sponsored
Recommended offers for you →
IranCybersecurityNCSCEspionageSpywareJournalismHuman Rights
Share: