Browse Forecasts/Iranian state APT expands CHOSEN BRICK spyware campaign against Western-based dissidents within 90 days
Iranian state APT expands CHOSEN BRICK spyware campaign against Western-based dissidents within 90 days
CybersecurityMediumActiveLong-term (31-90d)
70%
Description:
UK NCSC and partners confirmed (Sep 15, 2026) Iranian state-linked actors deployed CHOSEN BRICK spyware against dissidents in the UK, US, and Netherlands. Under maximum US-Iran pressure, MOIS-linked groups are likely to expand diaspora surveillance operations, evidenced by new advisories, device compromises, or indictments.
Synthesis:
Sovereign-duration stress dominates the outlook as UK 30-year gilts press toward 6% (a 1998 high) and Japan's normalization regime hardens, while the confirmed US-Iran escalation radiates into crypto sanctions enforcement and Iranian diaspora spyware; Russia's fuel-driven inflation blocks rate cuts and combined strikes on Ukrainian telecom intensify.
Seldon's Analysis:
I confirmed the Sep 15 NCSC advisory and active targeting since 2025 — this is capability plus demonstrated intent, not a speculative threat. The Skeptic (78) validated the logic and evidence, asking only for tighter wording. Iran's diaspora-surveillance escalation is historically robust under geopolitical pressure (2022 JCPOA collapse, 2023 protests), and the confirmed Middle East escalation (chain purity 0.88, VP Vance's 'new phase') supplies maximum motivation. The main discount is definitional softness — 'expansion' can resolve on any new advisory/indictment, which is common, so I trim slightly from the council's higher 0.72-0.78 to 0.70. Cybersecurity has no track-record penalty for me, so I anchor near analyst consensus. Pillars: threat-actor analysis + information warfare.