NCSC publishes advisory on Iranian cyber targeting of dissidents, activists and journalists
The UK NCSC has released an advisory on CHOSEN BRICK malware used against dissidents, activists and journalists, with technical analysis and protective advice.
The UK's National Cyber Security Centre (NCSC) has published an advisory on Iranian cyber targeting of dissidents, activists and journalists. The advisory covers a malware family the NCSC refers to as CHOSEN BRICK and includes technical analysis of that malware, along with advice to help both individuals and organisations protect themselves. The full advisory is available on the NCSC website: Iranian cyber targeting of dissidents, activists and journalists.
The headline names three groups as targets: dissidents, activists and journalists. The publisher is the UK government's technical authority on cyber security, which places this in the regulation and compliance bucket for UK readers even though it is an advisory rather than a rule. Nobody is being fined. Nobody has a deadline. The NCSC is telling people who are likely to be targeted, and the organisations around them, what the malware looks like and what to do about it.
What the public summary does not say is worth stating plainly, because it is where speculation tends to creep in. The summary does not describe the initial access method, the platforms the malware runs on, the indicators of compromise, or which specific group the NCSC associates with the activity beyond the word "Iranian". Those details, if published, sit in the technical analysis inside the advisory itself. Anyone building detections or briefing staff should work from that document rather than from a headline or from this article.
For identity teams, the interesting part is the choice of target. This is not an advisory about ransomware against a hospital or a supply chain attack against a software vendor. It is about people. Journalists, activists and dissidents typically run their working lives on a mix of personal and organisational accounts: a newsroom Google Workspace or Microsoft 365 tenant, a personal Gmail from 2009, a messaging app on a phone, a social media account with the same password as both. The organisational half of that picture is where an IAM team has any authority. The personal half is where the attacker usually walks in.
That is the acidic bit. The encouraging bit is that the defensive playbook for targeted individuals is well understood and not expensive. It comes down to three areas:
- Authentication that phishing cannot beat. FIDO2 or WebAuthn hardware keys or platform passkeys on the email account, the identity provider, and the social accounts that matter. SMS codes and push notifications do not clear that bar.
- Account recovery that is not weaker than the login. A recovery email or phone number that the target has not touched in years is a second front door with the lock removed.
- Device and app hygiene. Malware needs somewhere to run. Fewer sideloaded apps, fewer browser extensions, current OS patches, and a clear process for what to do when a device looks wrong.
None of that is new. It is also frequently ignored by exactly the people who need it most, because they are busy doing dangerous work and treating their account settings as a chore for a quieter week. The NCSC advisory is a reasonable excuse to make that week this week. Newsrooms, NGOs and universities that host at-risk individuals can treat it as a prompt to go looking for gaps rather than waiting for a compromised inbox to announce them.
The positive reading is that a national technical authority has decided this population deserves a dedicated advisory with malware analysis attached, rather than a generic "be careful out there". That raises the floor for anyone who reads it. It also gives security teams a citable document to put in front of leadership when asking for hardware keys or a tighter recovery policy for high-risk staff, which is a more productive conversation than one that starts after the breach.
What should an identity or security team check now? Pull the list of staff and contributors whose work fits the profile named in the advisory and confirm that each has phishing-resistant MFA enforced, not merely available, on the organisational identity provider and on their work email. Review recovery options and legacy authentication settings on those same accounts, since an old IMAP path or an unmonitored recovery phone undoes the key on the front. Read the technical analysis in the advisory and hand any indicators it contains to whoever owns endpoint detection and mail filtering, then brief the affected people in plain language rather than a policy PDF.
Be the first to comment
Members only: sign up if you have something worth saying.
Want to weigh in? Sign in or create a free account.
No comments yet.