logo

Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations

ID: 78b56046-579f-5292-88b7-756c5b77134f

STIX ID: report--78b56046-579f-5292-88b7-756c5b77134f

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-03-10

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Check Point Research reports that Iranian government-linked operators (MOIS-associated MuddyWater and Void Manticore) are increasingly using commercial cybercrime infrastructure—infostealers (Rhadamanthys), loaders (CastleLoader), and ransomware—alongside custom tools (DinDoor, Tsundere) in espionage, destructive campaigns, and attacks on Israeli hospitals and US critical networks; this blending of state and criminal tooling is used to obfuscate attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.