
Loading

Loading
We use strictly necessary cookies to run this site, and — only with your consent — analytics cookies to understand how it's used. See our Privacy Policy for details.

Iranian state hackers are targeting dissidents, activists and journalists with spyware capable of tracking their movements, GCHQ’s National Cyber Security Centre has warned.
Summary
The Iranian spear-phishing campaign has targeted people around the world, including the UK, according to alerts from the UK’s National Cyber Security Centre (NCSC), the Netherlands and the USA. Iranian cyber attackers have used social engineering techniques to persuade people to download files containing hidden malware which infects Windows based devices. The malware, identified as Chosen Brick in the UK or Heavygram in the US has been used to target individuals in the UK, US and the Netherlands from at least 2025.
This summary is a partial excerpt — the source's own feed cuts off here. Read the full story at Techtarget for the rest.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.