Cookie Consent by Free Privacy Policy Generator

NCSC issues advisory on Iranian spyware targeting dissidents and activists

The National Cyber Security Centre has published a detailed advisory on CHOSEN BRICK, a spyware tool used by Iranian state actors to target dissidents, activists and journalists. The NCSC reports that the malware has been deployed against individuals and organisations perceived as critical of the Iranian government, including human rights defenders and media professionals. The advisory includes technical analysis of the malware's capabilities, indicators of compromise, and practical guidance to help individuals and organisations at risk detect and defend against the threat. The NCSC has coordinated the advisory with international partners to provide a comprehensive picture of the threat activity and the techniques used by the Iranian actors involved.

Why this matters for UK organisations

This advisory is particularly relevant for UK organisations working with or supporting human rights groups, journalists, activists, or diaspora communities who may be at risk from state-sponsored surveillance. The NCSC's guidance makes clear that the threat is targeted rather than indiscriminate, but organisations in relevant sectors should review whether they have individuals or partners who may be at heightened risk. The advisory also serves as a reminder that state-sponsored surveillance capabilities are increasingly sophisticated and that organisations with a duty of care to vulnerable individuals need to understand the threat landscape and take proportionate protective measures. The technical detail provided by the NCSC is intended to help security teams identify potential compromise and implement appropriate defences. For organisations in the charity, media, legal, or advocacy sectors, this is an opportunity to review whether existing security measures are sufficient to protect individuals who may be specifically targeted by state actors.

What to review

Organisations should review the NCSC's advisory and assess whether individuals in their organisation or partner network may be at risk from state-sponsored surveillance. Security teams should familiarise themselves with the technical indicators of compromise provided in the advisory and ensure that monitoring and detection capabilities are in place to identify potential targeting. Organisations with a duty of care to vulnerable individuals should ensure that appropriate support, guidance, and protective measures are available, and that staff understand how to recognise and report potential surveillance activity. This is also a prompt to review whether responsibility for managing these risks is clearly assigned and whether existing security policies adequately address the specific risks faced by individuals who may be targeted by state actors.

Source: NCSC UK

News and blog posts
Cisco has released an emergency security update for a critical zero-day...
Spanish data protection authorities have reported what appears to be the first...
Infosecurity Magazine reports that attackers are actively exploiting a critical...
Today's brief covers a mix of immediate technical risks and emerging...