ZeroHour

Search: “spyware”

10 stories in the last 3d

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

Joint advisory details Iranian spear-phishing campaign deploying CHOSEN BRICK spyware to surveil dissidents, activists, and journalists across UK, US, Netherlands.

The NCSC (part of GCHQ), FBI, and AIVD jointly warned that Iranian state actors impersonate trusted contacts on WhatsApp and Telegram to deploy the CHOSEN BRICK spyware against dissidents, activists, and journalists worldwide. The Windows-only malware is persistent across reboots and collects contacts, emails, social media messages, screen captures, and microphone audio. Stolen personal details of some victims have been published on pro-Iranian leak sites. The FBI published complementary technical analysis, and the NCSC offers free cyber defence services for high-risk individuals.

NCSC UK · 1d agoThreat actor in the wild1

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

UK, US, and Dutch agencies expose CHOSEN BRICK spyware used by Iranian MOIS hackers to surveil dissidents, journalists, and activists via fake MRI lures.

The UK NCSC, FBI, and Dutch AIVD jointly warned that Iranian state-sponsored hackers deploy CHOSEN BRICK Windows spyware against dissidents, activists, and journalists since at least 2025. Operators build rapport over WhatsApp and Telegram, often posing as known contacts or tech support, then deliver malicious files disguised as an MRI scan or installers for Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass. The malware steals contacts, emails, and social media messages, captures screen content and microphone audio, adds Microsoft Defender exclusions, and uses per-victim Telegram bots for command and control. The FBI attributes the tradecraft to Iran's Ministry of Intelligence and Security, including the 'Handala Hack' persona, and stolen data has surfaced on pro-Iranian leak sites.

The Record · 1d agoThreat actor in the wild1

Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists

UK NCSC, FBI and Dutch AIVD warn Iranian state hackers deploy CHOSEN BRICK spyware via WhatsApp and Telegram lures against dissidents and journalists since 2025.

The UK's NCSC, the FBI and the Netherlands' AIVD jointly warned that Iranian state cyber actors have deployed CHOSEN BRICK against dissidents, activists and journalists in the UK, US and Netherlands since at least 2025. Victims are contacted on WhatsApp or Telegram by impostors posing as known contacts or platform support, then tricked into running files disguised as software such as fake Norton Antivirus, KeePass, Telegram or MRI scan results. The Windows malware adds Microsoft Defender exclusions, persists via HKCU Run keys, uses per-device Telegram bots for C2, and can capture screens, activate microphones, steal email and messaging data, and download further payloads. Some stolen data has later appeared on pro-Iranian leak sites, and the agencies note Iranian intelligence has plotted kidnappings or lethal operations against targets abroad.

Help Net Securityupdated · 4h agofirst · 1d agoThreat actor in the wild 7 sources

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

FBI, UK NCSC, and Dutch AIVD warn Iranian intelligence uses Chosen Brick spyware against dissidents, stealing contacts, emails, and messaging data.

A joint advisory from the FBI, UK NCSC, and Dutch AIVD says Iranian state cyber actors have used the Chosen Brick Windows malware since at least 2025 to surveil dissidents, activists, and journalists. Attacks begin with heavily researched WhatsApp and Telegram messages impersonating trusted contacts, tricking victims into opening fake installers resembling Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. The malware persists via the HKCU Run registry key, adds Microsoft Defender exclusions, uses victim-specific Telegram bots for C2, captures screen and audio, steals emails and Telegram/WhatsApp data, and can wipe systems.

The Register · Security · 1d agoThreat actor in the wild1

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

FBI, NCSC, and AIVD detail Iran MOIS spyware CHOSEN BRICK/HEAVYGRAM, Telegram-controlled Windows malware spying on dissidents since 2023.

A September 15 joint advisory from the FBI, UK NCSC, and Dutch AIVD attributes the Windows spyware HEAVYGRAM (NCSC name CHOSEN BRICK) to Iran's Ministry of Intelligence and Security, with the campaign dating to autumn 2023 and targeting dissidents, journalists, and activists in the UK, US, Netherlands, and worldwide. Delivered via messages impersonating known contacts or tech support, the malware assigns each victim a dedicated Telegram bot for command-and-control and exfiltration, and can take screenshots, record microphone audio, steal Telegram/WhatsApp data, saved passwords, and emails, download more malware, and wipe the computer. Persistence uses a registry Run key (SMQDService or winappx) plus Microsoft Defender exclusions, with stolen data exiting via Telegram and cloud storage services like Vultr and Storj. The US Justice Department seized four pro-Iranian leak sites in March that had published stolen victim data.

The Hacker News · 1d agoMalware in the wild1

Iranian cyber targeting of dissidents, activists and journalists

UK NCSC, FBI, and Dutch AIVD expose CHOSEN BRICK spyware used by Iranian state actors against dissidents, activists, and journalists worldwide.

A joint advisory from the UK NCSC, FBI, and Dutch AIVD details CHOSEN BRICK, a Windows spyware family used by Iranian state cyber actors since at least 2025 against dissidents, activists, and journalists in the UK, US, and Netherlands. Actors build rapport on WhatsApp and Telegram impersonating known contacts or platform support, then deliver disguised payloads resembling apps such as Telegram, Norton, RunwayML, or fake MRI results. The malware persists via HKCU Run registry keys, adds Microsoft Defender exclusions, and uses a unique Telegram bot C2 per victim. Capabilities include screen capture, microphone recording, process enumeration, email and messaging data theft, file deletion, and system wiping; victim data has appeared on pro-Iranian leak sites.

NCSC UK · 1d agoThreat actor in the wild2

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

CISA added actively exploited flaws in Cisco ISE, Acronis Backup, and Google Pixel (CVE-2026-76460, CVE-2026-87886, CVE-2026-58704) to its KEV catalog.

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-76460 (CVSS 10.0), an unauthenticated API authentication bypass in Cisco Identity Services Engine that Cisco confirms is being actively exploited; CVE-2026-87886, a local privilege escalation in the Acronis Backup plugins for cPanel/WHM and Plesk exploited in limited targeted attacks; and CVE-2026-58704 (CVSS 8.8), a Google Pixel cellular modem permission bypass exploited in limited, targeted attacks and patched in the September 2026 Pixel update. Under BOD 22-01, federal agencies must remediate KEV entries by the stated due dates. Google has not attributed the Pixel exploitation to any actor.

Security Affairsupdated · 25m agofirst · 2h agoExploit / PoC in the wild 21 sourcesCVE-2026-76460CVE-2026-87886CVE-2026-58704

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

US Coast Guard and FBI boarded two foreign tankers bound for the US after indications their vessel networks were compromised, investigating possible Iranian involvement.

The Coast Guard and FBI conducted joint offshore security boardings of two commercial ships in the Gulf of Mexico on August 21 and 24 to examine their operational and IT systems following indications both networks were compromised. The vessels reportedly carried oil and natural gas, and one was hacked in the Strait of Gibraltar and lost communications for over 30 hours. No operational disruptions, vessel instability, or environmental impacts have been reported, and authorities are investigating whether Iran or another group exploiting US-Iran tensions was behind the attacks.

CyberScoopupdated · 16h agofirst · 20h agoData breach in the wild 2 sources

Android 0-day Vulnerability on Google Pixel Devices Actively Exploited in Attacks

Google patched CVE-2026-58704, an actively exploited Android zero-day allowing proximal privilege escalation via the Pixel cellular modem, urging the 2026-09-05 patch.

Google confirmed CVE-2026-58704, a high-severity elevation-of-privilege flaw in the Pixel cellular modem, is being exploited in limited, targeted attacks and shipped emergency fixes in the September 2026 Pixel Update Bulletin. The low-complexity bug requires no user interaction and enables proximal/adjacent privilege escalation with no additional execution privileges, phrasing Google has historically used for spyware-vendor and state-aligned zero-days. The Pixel bulletin patches 110 flaws including 12 critical RCEs, while the broader September Android update addressed roughly 180 vulnerabilities, including Wi-Fi memory-corruption bug CVE-2026-28662.

Cyber Security Newsupdated · 17h agofirst · 1d agoExploit / PoC in the wild 8 sourcesCVE-2026-58704CVE-2026-28662

Cisco warns customers of actively exploited zero-day in email gateways

Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 allows unauthenticated root command execution; CISA added it to KEV.

Cisco disclosed CVE-2026-76461, a zero-day in AsyncOS for Cisco Secure Email Gateway that was exploited before disclosure and lets unauthenticated remote attackers execute commands with root privileges on cloud and on-premises instances. CISA promptly added the flaw to its Known Exploited Vulnerabilities catalog, and Cisco has directly contacted cloud customers with indicators of compromise while deploying mitigations. Rapid7 and VulnCheck warn compromised gateways could enable silent email monitoring and internal pivoting from on-premises deployments.

CyberScoopupdated · 21h agofirst · 1d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461