Researchers Link MOIS To Coordinated Hacker Persona Operation
ID: 60f5af7a-5218-5878-920f-b057725684e8
STIX ID: report--60f5af7a-5218-5878-920f-b057725684e8
Feed Name: Cyber Press
Researchers attribute a coordinated, MOIS-aligned cyber influence ecosystem—operating under the personas Homeland Justice, Karma, and Handala—to Iran’s Ministry of Intelligence and Security. The assessment links these personas to exploitation of a Microsoft SharePoint vulnerability, deployment of ransomware-style encryption and wipers (including BiBi Wiper), curated hack-and-leak operations, and a March 2026 campaign that abused Microsoft Intune to exfiltrate ~50 TB and remotely wipe 80,000–200,000 devices across multiple countries, indicating high sophistication and state-directed operational control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
