Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations
ID: 78b56046-579f-5292-88b7-756c5b77134f
STIX ID: report--78b56046-579f-5292-88b7-756c5b77134f
Feed Name: The Register (Security)
Threat Score
Check Point Research reports that Iranian government-linked operators (MOIS-associated MuddyWater and Void Manticore) are increasingly using commercial cybercrime infrastructure—infostealers (Rhadamanthys), loaders (CastleLoader), and ransomware—alongside custom tools (DinDoor, Tsundere) in espionage, destructive campaigns, and attacks on Israeli hospitals and US critical networks; this blending of state and criminal tooling is used to obfuscate attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
