Researchers Say Iranian MOIS Uses Multiple Hacker Personas for One Coordinated Cyber Campaign
ID: 159cb8a0-735c-553b-bef5-a53933dbc179
STIX ID: report--159cb8a0-735c-553b-bef5-a53933dbc179
Feed Name: cybersecurityNews.com
Iran’s Ministry of Intelligence and Security (MOIS) operated a coordinated cyber influence and attack ecosystem under multiple personas—Homeland Justice, Karma/KarmaBelow80, and Handala—conducting long-term intrusions, sensitive data theft, destructive wiper attacks, and targeted information operations across multiple countries (notably Albania and Israel). The report links shared tools, infrastructure, and tactics (including Rhadamanthys infostealer, custom wipers, SharePoint exploitation, phishing, and Telegram C2) to the single state-directed operation tracked as “Void Manticore”/MOIST GRASSHOPPER and notes a U.S. Justice Department seizure of related domains in March 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
