ZeroHour

Search: “spyware”

14 stories in the last 3d

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

Joint advisory details Iranian spear-phishing campaign deploying CHOSEN BRICK spyware to surveil dissidents, activists, and journalists across UK, US, Netherlands.

The NCSC (part of GCHQ), FBI, and AIVD jointly warned that Iranian state actors impersonate trusted contacts on WhatsApp and Telegram to deploy the CHOSEN BRICK spyware against dissidents, activists, and journalists worldwide. The Windows-only malware is persistent across reboots and collects contacts, emails, social media messages, screen captures, and microphone audio. Stolen personal details of some victims have been published on pro-Iranian leak sites. The FBI published complementary technical analysis, and the NCSC offers free cyber defence services for high-risk individuals.

NCSC UK · 1d agoThreat actor in the wild

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

UK, US, and Dutch agencies expose CHOSEN BRICK spyware used by Iranian MOIS hackers to surveil dissidents, journalists, and activists via fake MRI lures.

The UK NCSC, FBI, and Dutch AIVD jointly warned that Iranian state-sponsored hackers deploy CHOSEN BRICK Windows spyware against dissidents, activists, and journalists since at least 2025. Operators build rapport over WhatsApp and Telegram, often posing as known contacts or tech support, then deliver malicious files disguised as an MRI scan or installers for Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass. The malware steals contacts, emails, and social media messages, captures screen content and microphone audio, adds Microsoft Defender exclusions, and uses per-victim Telegram bots for command and control. The FBI attributes the tradecraft to Iran's Ministry of Intelligence and Security, including the 'Handala Hack' persona, and stolen data has surfaced on pro-Iranian leak sites.

The Record · 1d agoThreat actor in the wild1

Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists

UK NCSC, FBI and Dutch AIVD warn Iranian state hackers deploy CHOSEN BRICK spyware via WhatsApp and Telegram lures against dissidents and journalists since 2025.

The UK's NCSC, the FBI and the Netherlands' AIVD jointly warned that Iranian state cyber actors have deployed CHOSEN BRICK against dissidents, activists and journalists in the UK, US and Netherlands since at least 2025. Victims are contacted on WhatsApp or Telegram by impostors posing as known contacts or platform support, then tricked into running files disguised as software such as fake Norton Antivirus, KeePass, Telegram or MRI scan results. The Windows malware adds Microsoft Defender exclusions, persists via HKCU Run keys, uses per-device Telegram bots for C2, and can capture screens, activate microphones, steal email and messaging data, and download further payloads. Some stolen data has later appeared on pro-Iranian leak sites, and the agencies note Iranian intelligence has plotted kidnappings or lethal operations against targets abroad.

Help Net Securityupdated · 3h agofirst · 15h agoThreat actor in the wild 6 sources

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

FBI, UK NCSC, and Dutch AIVD warn Iranian intelligence uses Chosen Brick spyware against dissidents, stealing contacts, emails, and messaging data.

A joint advisory from the FBI, UK NCSC, and Dutch AIVD says Iranian state cyber actors have used the Chosen Brick Windows malware since at least 2025 to surveil dissidents, activists, and journalists. Attacks begin with heavily researched WhatsApp and Telegram messages impersonating trusted contacts, tricking victims into opening fake installers resembling Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. The malware persists via the HKCU Run registry key, adds Microsoft Defender exclusions, uses victim-specific Telegram bots for C2, captures screen and audio, steals emails and Telegram/WhatsApp data, and can wipe systems.

The Register · Security · 1d agoThreat actor in the wild1

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

FBI, NCSC, and AIVD detail Iran MOIS spyware CHOSEN BRICK/HEAVYGRAM, Telegram-controlled Windows malware spying on dissidents since 2023.

A September 15 joint advisory from the FBI, UK NCSC, and Dutch AIVD attributes the Windows spyware HEAVYGRAM (NCSC name CHOSEN BRICK) to Iran's Ministry of Intelligence and Security, with the campaign dating to autumn 2023 and targeting dissidents, journalists, and activists in the UK, US, Netherlands, and worldwide. Delivered via messages impersonating known contacts or tech support, the malware assigns each victim a dedicated Telegram bot for command-and-control and exfiltration, and can take screenshots, record microphone audio, steal Telegram/WhatsApp data, saved passwords, and emails, download more malware, and wipe the computer. Persistence uses a registry Run key (SMQDService or winappx) plus Microsoft Defender exclusions, with stolen data exiting via Telegram and cloud storage services like Vultr and Storj. The US Justice Department seized four pro-Iranian leak sites in March that had published stolen victim data.

The Hacker News · 1d agoMalware in the wild1

Iranian cyber targeting of dissidents, activists and journalists

UK NCSC, FBI, and Dutch AIVD expose CHOSEN BRICK spyware used by Iranian state actors against dissidents, activists, and journalists worldwide.

A joint advisory from the UK NCSC, FBI, and Dutch AIVD details CHOSEN BRICK, a Windows spyware family used by Iranian state cyber actors since at least 2025 against dissidents, activists, and journalists in the UK, US, and Netherlands. Actors build rapport on WhatsApp and Telegram impersonating known contacts or platform support, then deliver disguised payloads resembling apps such as Telegram, Norton, RunwayML, or fake MRI results. The malware persists via HKCU Run registry keys, adds Microsoft Defender exclusions, and uses a unique Telegram bot C2 per victim. Capabilities include screen capture, microphone recording, process enumeration, email and messaging data theft, file deletion, and system wiping; victim data has appeared on pro-Iranian leak sites.

NCSC UK · 1d agoThreat actor in the wild2

Supreme Court denies Trump request to allow USPS mail ballot changes

Supreme Court denied the Trump administration's emergency request to implement USPS mail ballot changes before the 2026 midterms, calling it arbitrary and capricious.

The U.S. Supreme Court rejected 7-2 the Trump administration's petition to change how the U.S. Postal Service handles mail-in ballots for the 2026 midterm elections. Justice Ketanji Brown Jackson wrote the administration was unlikely to succeed, while Justice Brett Kavanaugh cited unreasonably short timelines for state election officials. The blocked executive order would have required USPS citizenship verification, barcode tracking of ballot envelopes, and DHS-compiled "State Citizenship Lists"; a whistleblower alleged a rushed effort to install three restrictive IT verification systems. Justices Alito and Thomas dissented, arguing states and organizations lacked standing.

CyberScoop · 1d agoPolicy & legal

Five alleged leaders of Black Axe’s operations in South Africa extradited to US

US extradited five alleged Black Axe Cape Town leaders from South Africa to face romance-scam wire fraud and money laundering charges.

The Justice Department announced five alleged leaders of Black Axe's South African wing, all Nigerian nationals, were extradited to the US over romance and advance-fee scams run from at least 2011 until their 2021 arrests in South Africa. Prosecutors say the group used fake identities and threatened to expose victims' sensitive photos, with charges including wire fraud, money laundering, and aggravated identity theft carrying up to 62 years. The extradition follows recent multi-country stings arresting dozens of Black Axe members, including 34 arrests in Spain.

CyberScoopupdated · 1d agofirst · 2d agoPolicy & legal 3 sources

CISA promotes a fresh way to deter cyberattackers: Lie to them

CISA issued first-time guidance advising critical infrastructure operators to deploy honeypots, honeytokens, and decoys to detect and distract intruders.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response,' a 22-page guide marking the agency's first guidance on decoys such as honeypots and honeytokens. Acting executive director Chris Butera described decoys as a low-cost, high-fidelity way to detect adversaries already inside networks, complementing zero-trust and assume-compromise approaches. The guidance covers decoy principles, definitions, deployment scenarios, and is aimed especially at resource-constrained critical infrastructure sectors.

CyberScoop · 3h agoAdvisory

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

US Coast Guard and FBI boarded two foreign tankers bound for the US after indications their vessel networks were compromised, investigating possible Iranian involvement.

The Coast Guard and FBI conducted joint offshore security boardings of two commercial ships in the Gulf of Mexico on August 21 and 24 to examine their operational and IT systems following indications both networks were compromised. The vessels reportedly carried oil and natural gas, and one was hacked in the Strait of Gibraltar and lost communications for over 30 hours. No operational disruptions, vessel instability, or environmental impacts have been reported, and authorities are investigating whether Iran or another group exploiting US-Iran tensions was behind the attacks.

CyberScoopupdated · 5h agofirst · 9h agoData breach in the wild 2 sources

Android 0-day Vulnerability on Google Pixel Devices Actively Exploited in Attacks

Google patched CVE-2026-58704, an actively exploited Android zero-day allowing proximal privilege escalation via the Pixel cellular modem, urging the 2026-09-05 patch.

Google confirmed CVE-2026-58704, a high-severity elevation-of-privilege flaw in the Pixel cellular modem, is being exploited in limited, targeted attacks and shipped emergency fixes in the September 2026 Pixel Update Bulletin. The low-complexity bug requires no user interaction and enables proximal/adjacent privilege escalation with no additional execution privileges, phrasing Google has historically used for spyware-vendor and state-aligned zero-days. The Pixel bulletin patches 110 flaws including 12 critical RCEs, while the broader September Android update addressed roughly 180 vulnerabilities, including Wi-Fi memory-corruption bug CVE-2026-28662.

Cyber Security Newsupdated · 6h agofirst · 14h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704CVE-2026-28662

What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies

CISA officials outline future plans for the CDM program, emphasizing speed, automation, unified data, and data-driven federal risk management.

Speaking at an Elastic Federal Cyber Defense Breakfast, CISA officials described next steps for the Continuous Diagnostics and Mitigation (CDM) program that supplies cybersecurity tools to federal agencies. Acting deputy program manager Richard Grabowski named velocity, unification, and data-driven risk management as core goals, including a three-year roadmap to expand SIEM-as-a-Service. Federal CISO Mike Duffy urged aggregating demand across agencies, buying outcomes rather than products, and designing acquisition for continuous improvement. CISA's Matt House tied the program's evolution to post-SolarWinds needs for a government-wide common operating picture.

CyberScoop · 1d agoPolicy & legal

Cisco warns customers of actively exploited zero-day in email gateways

Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 allows unauthenticated root command execution; CISA added it to KEV.

Cisco disclosed CVE-2026-76461, a zero-day in AsyncOS for Cisco Secure Email Gateway that was exploited before disclosure and lets unauthenticated remote attackers execute commands with root privileges on cloud and on-premises instances. CISA promptly added the flaw to its Known Exploited Vulnerabilities catalog, and Cisco has directly contacted cloud customers with indicators of compromise while deploying mitigations. Rapid7 and VulnCheck warn compromised gateways could enable silent email monitoring and internal pivoting from on-premises deployments.

CyberScoopupdated · 10h agofirst · 1d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461

OpenAI stuck fighting Musk antitrust suit after Apple finds a way out

Musk voluntarily dismissed all antitrust claims against Apple but continues pursuing OpenAI over alleged ChatGPT-iPhone chatbot market monopolization.

Elon Musk filed court papers confirming all claims against Apple over its ChatGPT iPhone integration are resolved, agreeing never to raise them again. He refuses to drop parallel claims that OpenAI used the non-exclusive Apple deal to monopolize the chatbot market. OpenAI has dismissed the suit as harassment as Musk's AI firm, now called SpaceXAI, races to catch up.

Ars Technica · AI · 2d agoAI industry