logo

Iranian MOIS Actors & the Cyber Crime Connection

ID: 184619fc-b19c-5ecc-b6b2-9560cded6f0e

STIX ID: report--184619fc-b19c-5ecc-b6b2-9560cded6f0e

Feed Name: Check Point Research

Threat Score
85/100

Date Published: 2026-03-10

Date Updated: 2026-04-27

Author: stcpresearch

...
...

This report outlines a shift in Iranian (MOIS-linked) cyber operations toward direct engagement with the cybercrime ecosystem — using commercial infostealers (Rhadamanthys), botnets/loaders (Tsundere/DinDoor, CastleLoader/FakeSet), and ransomware-as-a-service (Qilin) branding — to enhance operational capability and complicate attribution; it provides case examples, analysis of overlaps, and indicators of compromise including file hashes and suspicious code-signing certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.