Jessica Entwistle
September 16 2026
The National Cyber Security Centre has published a joint advisory with international partners exposing CHOSEN BRICK, a sophisticated spyware tool used by Iranian state actors to conduct surveillance against dissidents, activists and journalists. The advisory provides detailed technical analysis of the malware's capabilities, indicators of compromise, and practical guidance to help organisations and individuals at risk detect and defend against the threat. The disclosure is part of a coordinated effort to raise awareness of state-sponsored targeting and provide actionable intelligence to those who may be affected.
For UK organisations working with human rights groups, media organisations, academic institutions, legal practices or civil society networks, this advisory is directly relevant. Many UK-based individuals and organisations maintain contact with diaspora communities, activists and journalists who may be at heightened risk of state-sponsored surveillance. The operational context is that spyware targeting is not limited to the individuals themselves; it can extend to their professional networks, colleagues, legal representatives and the organisations that support them. Understanding the threat profile and ensuring that appropriate technical and operational safeguards are in place is an important part of duty of care for organisations working in these sectors. The NCSC advisory provides specific indicators of compromise and detection guidance that security teams can use to assess whether devices or networks have been affected.
Organisations should review endpoint security and mobile device management policies for staff who may be at risk, particularly those working with vulnerable communities or handling sensitive communications. Ensure that the NCSC advisory is shared with relevant teams, including IT, security, legal and human resources. Consider whether staff understand the risk, know how to report suspicious activity, and have access to secure communication channels. Review whether endpoint detection and response tools are deployed and configured to detect the indicators of compromise outlined in the advisory. For organisations supporting at-risk individuals, consider whether additional security measures such as device hardening, secure messaging platforms or threat intelligence sharing are appropriate. Ensuring that security awareness training includes guidance on state-sponsored threats and social engineering is also a practical step that helps staff recognise and respond to targeting attempts.
Source: NCSC UK