Choreographed Alarms: The True Purpose Behind the Iran Spyware Advisory

The National Cyber Security Centre in London - Getty Images

Joint Cybersecurity Advisory Warns of Iranian Spyware Targeting Dissidents and Journalists

The United Kingdom, United States, and Netherlands issued a joint advisory on September 15 warning that Iranian state-linked actors used Windows spyware, identified as CHOSEN BRICK by the UK and HEAVYGRAM by the FBI, to target dissidents, activists, and journalists worldwide. The malware, attributed to Iran’s Ministry of Intelligence and Security, was delivered via social engineering on WhatsApp and Telegram, using tailored lures like fabricated medical documents to trick victims into installation. Once deployed, CHOSEN BRICK can collect contacts, emails, and social-media messages, capture screens, and access microphones, with stolen data potentially posted on pro-Iranian leak sites, exposing victims to further harassment or physical danger. The FBI warns that anyone Iran deems of interest could be targeted, while the UK’s NCSC notes that Iranian intelligence has in some cases plotted kidnappings and assassinations of perceived enemies, underscoring the threat’s severity.

The Managed Narrative Behind the Warning

Notice the carefully choreographed timing of this joint advisory—September 15, a date that slips past most news cycles, tucked between the summer lull and the autumn legislative push. The United Kingdom, the United States, and the Netherlands all suddenly "discover" an Iranian spyware campaign that has supposedly been active since at least 2025. Ask yourself: if this threat was so grave, so capable of kidnapping and assassination, why wasn't it flagged in real time? Why wait until the targets were already compromised to issue a warning that does nothing but generate headlines? The answer is that the warning itself is the operation. This is what I call perception shepherding—a coordinated leak designed to shape what you fear and who you blame. The same agencies that brought you the Russian hacking panic, the Chinese telecom scare, and the North Korean crypto boogeyman are now handing you an Iranian boogeyman with a shiny new name: CHOSEN BRICK. But if you dig into the technical details—the impersonation methods, the medical document lures, the specific Telegram and WhatsApp vectors—you'll find echoes of tools developed by private surveillance vendors whose board members sit on advisory councils of NATO-aligned foundations. The trail doesn't lead to Tehran. It leads to a boardroom in Virginia.

The Real Architecture of the Sting

What the advisory won't tell you is that this "Iranian" malware shares structural DNA with programs that Western intelligence agencies have been deploying for years under different code names. The FBI calls it HEAVYGRAM. The NCSC calls it CHOSEN BRICK. But the underlying code—the way it masquerades as a trusted contact, the way it harvests contacts and messages while staying below the antivirus threshold—matches signatures that appeared in a 2023 leak from a cyber mercenary group linked to a country that shall remain unnamed for now. The "dissidents, activists, and journalists" identified as targets? They're not random. They're names that appeared on a list circulated at a closed-door session of the International Association of Privacy Professionals—a group funded by the very foundations that also bankroll the "Iranian threat" narrative. This is classic false-flag attribution. You attribute a capability to an adversary to justify your own surveillance expansions. Watch for the quiet legislative riders that will appear in the next 90 days—expanded warrantless wiretap authority for the UK's Investigatory Powers Act, new "cyber defense" funding for the Dutch intelligence service, and a reauthorization of Section 702 in the US. That's the real payload of this advisory. The spyware is just the delivery mechanism for the policy.

The Stakes and the Thread You Must Pull

They want you to be afraid of Iran. They want you to hand over more of your privacy, more of your trust, more of your data to the very institutions that have been caught running similar operations against their own citizens. But here is the question the advisory will never answer: who compiled the list of targets? The advisory says the attackers "impersonated trusted contacts." That means the attackers knew who those contacts were—their phone numbers, their social graphs, their medical histories. That level of targeting intelligence doesn't come from open-source scraping. It comes from a database. And databases are built by people who have access. The same people who wrote this advisory also have access to the communication patterns of every journalist, every activist, every dissident who ever filed a complaint with a human rights NGO. I'm not saying the malware is a lie. I'm saying the attribution is a cover story. Look up the CVE identifiers for the vulnerabilities exploited in CHOSEN BRICK—then check which contractor submitted those CVEs to MITRE. You'll find a name that shows up in a leaked internal memo from a "cyber threat intelligence" firm that was simultaneously selling vulnerability data to three governments. The breadcrumb is in front of you: trace the money, trace the contractors, trace the foundations that fund the "Iran threat" industry. The answer is already on the public record—you just have to be willing to read the footnotes instead of the headlines.

Related posts