此為 AI 翻譯內容,經編輯審核後發布。
英國、美國與荷蘭發布伊朗相關間諜軟體警示
倫敦,9月15日(路透社)——英國、美國與荷蘭週二發布聯合網路安全警示,詳述三國所稱由伊朗國家相關行為者用來鎖定異議人士、社運人士與記者的間諜軟體。LONDON, Sept 15 (Reuters) - Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory detailing spyware they say is used by Iranian state-linked actors to target dissidents, activists and journalists.
英國國家網路安全中心(National Cyber Security Centre,NCSC)表示,伊朗國家相關網路行為者曾使用一個名為「CHOSEN BRICK」的間諜軟體家族,透過WhatsApp、Telegram等通訊平台上的「魚叉式網路釣魚」攻擊活動,竊取電子郵件、訊息與其他敏感資訊。Britain's National Cyber Security Centre said Iranian state-linked cyber actors had used a spyware family known as "CHOSEN BRICK" to steal emails, messages and other sensitive information through "spear-phishing" campaigns on messaging platforms including WhatsApp and Telegram.
NCSC營運主任保羅・奇切斯特(Paul Chichester)在聲明中表示:「這起網路攻擊活動的細節揭示,伊朗如何為了達成鎮壓政權批評者的目的,冷酷地運用數位監控,竊取電子郵件和訊息,並存取裝置。」"The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices," Paul Chichester, NCSC director of operations, said in a statement.
伊朗駐倫敦大使館未立即回應採訪請求。Iran's embassy in London did not immediately respond to a request for comment.
根據這份警示,該惡意軟體可從聯絡人清單、電子郵件和社群媒體帳號蒐集資訊,擷取螢幕內容,並存取裝置的麥克風。NCSC表示,部分受害者的個人資料後來出現在親伊朗的洩密網站上。美國聯邦調查局(FBI)在其另行發布的警示中表示,伊朗情報與安全部(Ministry of Intelligence and Security,MOIS)正使用該惡意軟體「蒐集情報、進行資料外洩,並對其預定目標造成名譽傷害」。The malware, according to the advisory, can collect information from contact lists, emails and social media accounts, capture screen content and access a device's microphone. The NCSC said some victims' personal details had later appeared on pro-Iranian leak sites. The FBI, in its own advisory, said Iran's Ministry of Intelligence and Security (MOIS) was using the malware to "collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets."
FBI拒絕分享有多少人遭該惡意軟體鎖定,或這些人位於何處的更多細節。The FBI declined to share additional details on how many people have been targeted with the malware, or where they're located.
NCSC表示,攻擊者經常在通訊應用程式上冒充受信任的聯絡人,並針對個別目標量身設計接觸方式。NCSC稱,在某些案例中,攻擊者使用假文件,包括偽造的MRI檢查結果,誘使受害者下載該惡意軟體。The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware.
NCSC與FBI及荷蘭情報暨安全總局(AIVD)表示,伊朗「幾乎可以肯定」利用網路行動,協助壓制其視為威脅的人士。The NCSC, alongside the FBI and the Netherlands' AIVD intelligence service, said Iran "almost certainly" uses cyber operations to help suppress people it sees as threats.
FBI的警示指出,這是對2026年3月一項警告的更新;該警告描述了MOIS據稱利用該惡意軟體蒐集目標資料的作為,而這些資料隨後由一個名為「Handala Hack」的駭客身分在網路上發布。The FBI's advisory said it was an update to a March 2026 warning describing alleged MOIS efforts to use the malware to collect data on targets, which was then posted online by a hacking persona known as "Handala Hack."
自伊朗戰爭開打以來,Handala已鎖定多家美國公司與多名人士,包括3月對總部位於密西根州的醫療用品與服務供應商史賽克(Stryker)發動破壞性網攻,以及同月稍後外洩FBI局長卡什・帕特爾(Kash Patel)的個人電子郵件。Handala has targeted multiple U.S. companies and people since the start of the Iran war, including a destructive cyberattack against Michigan-based medical supplies and services supplier Stryker in March, and the leak of FBI Director Kash Patel's personal emails later that month.
Handala週二未回覆以電子郵件提出的採訪請求。Handala did not respond to an emailed request for comment on Tuesday.
(薩姆・塔巴赫里蒂倫敦報導,A.J. 維森斯底特律報導;威廉・詹姆斯、亞歷珊卓・哈德森與馬克・波特編輯)(Reporting by Sam Tabahriti in London and AJ Vicens in Detroit. Editing by William James, Alexandra Hudson and Mark Potter)