BREAKING
World 3 min 33,395

Iran's Espionage on British Protesters and Activists Using Malware

2 h ago

Iranian state actors have targeted British protesters, activists, and journalists using malware called Chosen Brick. This malware allows the perpetrators to access the personal information of victims and track their movements.

Iran's Espionage on British Protesters and Activists Using Malware
Image Iran's Espionage on British Protesters and Activists Using Malware (منبع تصویر: independent.co.uk)

Details of Cyber Attacks

The UK's National Cyber Security Centre (NCSC) reported that these actors deceive victims by impersonating their close contacts on messaging apps, tricking them into downloading the malware. This malware gives the perpetrators access to victims' contacts, emails, and social media messages, and can also access the device's microphone and screen content.

Joint investigations by Britain and its allies in the United States and the Netherlands show that these attacks are directed at British protesters and others in various countries. While the exact number of victims is unclear, the FBI has stated that this malware has been in use since fall 2023.

Use of Social Engineering Tricks

Iranian actors tailor their impersonation tactics to areas related to the victims' interests using social engineering tricks. In one instance, a fake MRI test result deceived a victim. This malware is designed to continue operating even after the device is restarted.

Some of the stolen personal information has been published on Iranian-backed data leak sites. Paul Chichester, NCSC's operations director, stated that this cyber campaign demonstrates Iran's ruthless use of digital surveillance to target protesters.

Chichester added: "The details of this cyber campaign show that Iran ruthlessly uses digital surveillance to suppress regime critics, stealing emails and messages and accessing devices. Together with our international partners, we advise at-risk individuals to familiarize themselves with social engineering techniques and follow risk mitigation recommendations."

The FBI also issued its warning, claiming that Iran's Ministry of Intelligence and Security (MOIS) uses this malware to gather information, conduct data breaches, and cause harm to its targets' reputations.

Detailed technical advice regarding this malware has been published on the NCSC website, along with explanations on how to avoid falling into their traps.

Last summer, Richard Horne, head of the NCSC, warned that hostile countries like Russia, China, and Iran are increasingly attacking Britain's critical systems. He added that three-quarters of the cyber attacks affecting Britain's critical infrastructure organizations last year were linked to hostile state actors.

Source: independent.co.uk

SHARE WhatsApp Telegram X Facebook