Western intelligence agencies, including the UK’s National Cyber Security Centre (NCSC), warn of an Iranian state-linked cyber campaign that uses spyware to target activists and dissidents. The advisory says the activity involves a spyware family identified as “CHOSEN BRICK.”

The reports state that the malware is used to steal emails, messages, and other sensitive information from victims. Both outlets describe the campaign as involving actors associated with Iran and say the advisory is based on technical indicators and intelligence shared or coordinated between the UK and other partners.

While the outlets share the same core details—Iran-linked actors, the CHOSEN BRICK spyware family, and data theft of communications—the framing differs slightly. One outlet emphasizes the role of “Western intelligence” and highlights concerns for both activists and the press, while the other stresses that the warning comes from a US-UK advisory and focuses on targeting dissidents. Neither source provides additional operational details such as dates, affected organizations, or specific distribution methods.