INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Iran MOIS Colludes with Criminals to Boost Cyberattacks

| 2026-03-12 21:11 CRITICAL HIGH
Executive Summary AI-generated
Iran's Ministry of Intelligence and Security has long used hacktivism as a cover when carrying out cyberattacks, with the MOIS employing civilians to carry out major cyberattacks. This tactic is not new, having been employed by other countries such as Russia and North Korea in service of state objectives. Recent incidents have highlighted Iran's capabilities, including its intelligence services working with criminals worldwide to achieve state objectives. The MOIS has also hired prominent drug trafficking networks to target dissidents and activists in Iran and the US. This approach is consistent with a broader trend of state-affiliated hackers acting as RaaS affiliates, shifting their focus from nation-state sponsored attacks to more targeted cybercrime operations.
Technical Mitigations AI-generated
* Implement a robust threat intelligence framework: Organizations should have a well-established threat intelligence program to identify and track Iranian state-sponsored threats, including those using cybercrime as a cover for their activities. * Conduct regular security awareness training: Employees should receive regular security awareness training to educate them on the risks of phishing, social engineering, and other types of cyber attacks that may be used by Iranian government-backed snoops or cybercriminals. * Use multi-factor authentication (MFA): Implement MFA to prevent unauthorized access to sensitive systems and data. This can help mitigate the risk of a MOIS hacker using their cybercrime infrastructure to gain access to an organization's network. * Monitor for suspicious activity: Regularly monitor network traffic, system logs, and other sources of information for signs of suspicious activity that may indicate Iranian government-backed snooping or cybercrime operations. * Use sandboxing and isolation techniques: Implement sandboxing and isolation techniques to test and analyze malware in a controlled environment before allowing it to run on production systems. This can help prevent the spread of ransomware and other types of malware used by MOIS hackers.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
MuddyWaterMuddyWater QilinQilinINC RansomwareINC Ransomware
Target & Sectors
DPRK DPRK NORTH_AMERICA NORTH_AMERICA MIDDLE_EAST MIDDLE_EAST NORDICS NORDICS technologytechnology energyenergy defensedefense governmentgovernment telecommunicationstelecommunications healthcarehealthcare
Incident Timeline
about 2018
MuddyWater exploited vulnerabilities in software used by the Islamic Republic of Iran's Ministry of Intelligence and Security (MOIS) to target critical American networks.
target_region Iran, Islamic Republic of
source_region United States
target_region Israel
tactic Espionage
threat_actor MuddyWater
organisation MOIS
late 2023
Threat actors used Iran's Ministry of Intelligence and Special Operations (MOIS) to collude with Hezbollah to target Israeli hospitals.
target_region Israel
organisation Hezbollah
late 2025
The Tsundere Botnet was linked to MuddyWater and targeted in late 2025.
tactic Botnet
threat_actor MuddyWater
tactic T1584.005 - Botnet
summer 2025
Threat actors from Iran, working with criminals, colluded to target the Israeli Shamir Medical Center in summer 2025.
source_region Iran, Islamic Republic of
target_region United States
target_region Israel
tactic Ransomware
attribution the Israeli Shamir Medical Center
October 2025
Iranian-affiliated ransomware groups, including Qilin, colluded with criminals to boost cyberattacks by buying malware and using remote monitoring and management tools.
target_region Iran, Islamic Republic of
tactic Ransomware
malware Qilin
organisation Israeli Shamir Medical Center
target_region United States
target_region Israel
attribution the Israeli Shamir Medical Center
industry Healthcare
malware INC Ransomware
organisation National Cyber Directorate
threat_actor MuddyWater
organisation RMM
financial $500 malware
March 11
Threat actors from Iran's Ministry of Islamic Intelligence and Security (MOIS) collaborated with cybercriminals to launch a targeted attack on the Fortune 500 medical technology company Stryker.
tactic Wiper
industry Technology
general_metric 500 Fortune
2026-03-12
Void Manticore (Handala Hack) is an Iranian threat actor linked to several hack-and-leak personas, including MOIS-linked actors.
organisation Sweden’s Security Service
organisation MOIS Actors &
organisation the Cyber Crime Connection
organisation Void Manticore
organisation MOIS
organisation APT
threat_actor MuddyWater
organisation Hezbollah
organisation Boost Cyberattacks
organisation Homeland Justice
organisation TypeScript
organisation VPS
organisation DinDoor
organisation CastleLoader
organisation IP
organisation Castle Loader Connection
organisation FakeSet
organisation Handala
organisation Node.js
organisation Certificate Thumbprint
organisation FakeSet / CastleLoader
organisation StageComp
organisation U.S. Treasury
organisation Treasury
organisation the Israeli National Cyber Directorate
organisation Check Point
organisation Void Manticore's
organisation Check Point Research
infrastructure 1,025 servers
Tactical Metrics
Metrics
infrastructure
1,025
Servers
Metrics
financial
500
Malware
Intelligence Sources
Zero Day Fans 2026-03-10