Britain, the United States and the Netherlands issued a joint warning on Tuesday about a cyberespionage campaign that the three countries said Iran-linked entities are using to target dissidents, activists and journalists with malware capable of stealing messages and sensitive data and compromising devices.
Chosen Break spyware relies on spear-phishing
The UK’s National Cyber Security Centre said state-linked Iranian entities had used a suite of spyware known as Chosen Break. It said the campaigns rely on “spear-phishing” through messaging platforms, including WhatsApp and Telegram, to gain access to emails, conversations and other information.
Paul Chichester, the UK centre’s director of operations, said the campaign’s details showed, in his words, Iran’s use of digital surveillance to suppress critics of the regime, steal messages and compromise devices. The US Federal Bureau of Investigation said the Iranian Ministry of Intelligence and Security uses the program to gather intelligence, leak data and damage the reputations of targeted individuals.