Iranian MOIS Actors & the Cyber Crime Connection
ID: 184619fc-b19c-5ecc-b6b2-9560cded6f0e
STIX ID: report--184619fc-b19c-5ecc-b6b2-9560cded6f0e
Feed Name: Check Point Research
This report outlines a shift in Iranian (MOIS-linked) cyber operations toward direct engagement with the cybercrime ecosystem — using commercial infostealers (Rhadamanthys), botnets/loaders (Tsundere/DinDoor, CastleLoader/FakeSet), and ransomware-as-a-service (Qilin) branding — to enhance operational capability and complicate attribution; it provides case examples, analysis of overlaps, and indicators of compromise including file hashes and suspicious code-signing certificates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
