Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. (checkpoint.com) Iranian MOIS-Linked Cyber Actors Increasingly Leverage Criminal Ecosystems for State-Directed Operations

(checkpoint.com) Iranian MOIS-Linked Cyber Actors Increasingly Leverage Criminal Ecosystems for State-Directed Operations

Scheduled Pinned Locked Moved Uncategorized
threatintelcybersecurity
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.com
    wrote last edited by
    #1

    (checkpoint.com) Iranian MOIS-Linked Cyber Actors Increasingly Leverage Criminal Ecosystems for State-Directed Operations

    Iranian threat actors linked to MOIS, including MuddyWater and Void Manticore, are actively integrating criminal ecosystem resources into state directed operations, employing commercial infostealers like Rhadamanthys, RaaS affiliate programs such as Qilin, and shared MaaS infrastructure like CastleLoader. Shared code signing certificates tying FakeSet, StageComp, and DinDoor variants suggest a common procurement source across these groups. The attack on Israel's Shamir Medical Center illustrates this convergence, where operators appeared to use the Qilin RaaS model to disguise a strategically motivated attack as criminal activity.

    IOCs in the article.

    Source: https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/

    Fediverse: Not known 😞

    #ThreatIntel #Cybersecurity

    1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • Popular
    • World
    • Users
    • Groups