Western intelligence warns of Iranian cyber threats targeting dissidents西方情报机构警告称,伊朗正以网络威胁攻击异见人士。
Western intelligence agencies highlight ‘CHOSEN BRICK’ spyware targeting critics of Iran government abroad.
![The warning over Tehran's hacking attempts is just the latest to Iranian dissidents from Western intelligence [File: Reuters]](https://www.aljazeera.com/wp-content/uploads/2026/06/2026-05-28T100002Z_1135925787_RC28ILAQV7NQ_RTRMADP_3_USA-MILITARY-SURVEILLANCE-1782187370.jpg?resize=770%2C513&quality=80)
Western intelligence agencies highlight ‘CHOSEN BRICK’ spyware targeting critics of Iran government abroad.
The warning over Tehran's hacking attempts is just the latest to Iranian dissidents from Western intelligence [File: Reuters]
The United States, the United Kingdom and the Netherlands have warned that Iranian spyware is being used to hunt dissidents living in the West.
Iran is “almost certainly” using cyber operations to target Iranian critics of the regime, intelligence agencies from the trio of countries cautioned on Tuesday.
In coordinated advisories, the FBI in the US, Britain’s National Cyber Security Centre (NCSC) and the Netherlands’ AIVD intelligence service all repeated the same warning.
“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” said Paul Chichester, the director of Britain’s NCSC.
Chichester highlighted a spyware family known as “CHOSEN BRICK” that is allegedly used by Iranian state-linked cyber actors to steal sensitive information through “spear-phishing” campaigns on messaging platforms including WhatsApp and Telegram.
The FBI said that Iran’s Ministry of Intelligence and Security (MOIS) was using the malware to “collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets”.
The advice is a continuation of regular warnings issued by Western intelligence over Iran’s efforts to target dissidents abroad.
In a warning issued in March, the FBI had described alleged MOIS efforts to use the malware to collect data on targets that was then posted online by a persona known as “Handala Hack.”
That attack in March crippled the global networks of Stryker, one of the world’s largest medical device companies, with an Iran-linked hacking group claiming responsibility and warning it marked “the beginning of a new chapter in cyber warfare”.
The so-called Handala hackers also claimed to have gained access to the personal emails of Kash Patel , the director of the US Federal Bureau of Investigation (FBI), sharing photographs and documents from the official online.
In July, US officials said a cyberattack on water systems in the state of Minnesota resembled the “Handala Hack”.
西方情报机构重点关注针对伊朗政府海外批评者的“精选砖块”间谍软件。
西方情报机构就德黑兰的黑客攻击发出的警告,只是西方向伊朗异见人士发出的最新警告。[图片来源:路透社]
美国、英国和荷兰警告称,伊朗间谍软件正被用来追捕居住在西方的异见人士。
周二,来自这三个国家的情报机构发出警告,称伊朗“几乎肯定”正在利用网络行动来攻击伊朗政权的批评者。
美国联邦调查局、英国国家网络安全中心 (NCSC) 和荷兰 AIVD 情报机构在协调一致的警告中都重复了同样的警告。
英国国家网络安全中心主任保罗·奇切斯特表示:“此次网络攻击的细节揭示了伊朗如何无情地利用数字监控来达到镇压政权批评者的目的,窃取电子邮件和信息,并访问设备。”
奇切斯特重点介绍了一种名为“CHOSEN BRICK”的间谍软件家族,据称伊朗国家网络行为者利用该软件通过在WhatsApp和Telegram等即时通讯平台上发起的“鱼叉式网络钓鱼”活动来窃取敏感信息。
美国联邦调查局表示,伊朗情报与安全部(MOIS)正在利用恶意软件“收集情报、进行数据泄露,并对目标对象造成声誉损害”。
这一建议延续了西方情报机构此前就伊朗企图在海外打击异见人士而发出的定期警告。
在 3 月份发布的一份警告中,FBI 描述了 MOIS 涉嫌利用恶意软件收集目标数据,然后由名为“Handala Hack”的人在网上发布这些数据的行为。
今年 3 月的那次攻击瘫痪了全球最大的医疗器械公司之一 Stryker 的全球网络,一个与伊朗有关联的黑客组织声称对此负责,并警告说这标志着“网络战新篇章的开始”。
所谓的 Handala 黑客还声称获得了美国联邦调查局 (FBI) 局长卡什·帕特尔 (Kash Patel) 的个人电子邮件访问权限,并在网上分享了官方照片和文件。
7 月,美国官员表示,明尼苏达州供水系统遭受的网络攻击与“汉达拉黑客事件”类似。