Britain, the United States and the Netherlands issue a joint cybersecurity advisory warning about spyware they say is used by Iran state-linked actors to target dissidents, activists and journalists. The advisory outlines how the actors deploy a spyware family referred to as “CHOSEN BRICK” to steal data from targeted devices and accounts.

The UK’s National Cyber Security Centre says the activity involves “spear-phishing” campaigns delivered through messaging platforms including WhatsApp and Telegram. It says the campaigns aim to obtain emails, messages and other sensitive information. The outlets also frame the warning as part of broader efforts to improve awareness and help organisations detect and defend against these threats.

While reporting is consistent on the named countries, the spyware family, and the general targeting and delivery methods, coverage differs in emphasis. Some outlets focus more on the technical description of the phishing and data theft, while others highlight the broader implication that the activity is directed at civil-society figures and independent media.