logo

Researchers Say Iranian MOIS Uses Multiple Hacker Personas for One Coordinated Cyber Campaign

ID: 159cb8a0-735c-553b-bef5-a53933dbc179

STIX ID: report--159cb8a0-735c-553b-bef5-a53933dbc179

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-20

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Iran’s Ministry of Intelligence and Security (MOIS) operated a coordinated cyber influence and attack ecosystem under multiple personas—Homeland Justice, Karma/KarmaBelow80, and Handala—conducting long-term intrusions, sensitive data theft, destructive wiper attacks, and targeted information operations across multiple countries (notably Albania and Israel). The report links shared tools, infrastructure, and tactics (including Rhadamanthys infostealer, custom wipers, SharePoint exploitation, phishing, and Telegram C2) to the single state-directed operation tracked as “Void Manticore”/MOIST GRASSHOPPER and notes a U.S. Justice Department seizure of related domains in March 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.