logo

Iran’s MOIS Tied to Coordinated Cyber Campaign Using Multiple Hacker Personas

ID: c25c4d6d-58db-5e66-a934-d1f6a35c2a48

STIX ID: report--c25c4d6d-58db-5e66-a934-d1f6a35c2a48

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report links three branded personas (Homeland Justice, Karma/KarmaBelow80, Handala) to Iran’s MOIS and describes a unified, state‑directed hack‑and‑leak influence campaign that conducts long‑term intrusions, credential theft, data exfiltration, destructive wiping/encryption (including BiBi Wiper and ransomware‑style actions), and abuse of legitimate cloud/admin tools (notably a reported Intune remote‑wipe affecting up to 200,000 devices); the ecosystem uses recurring leak sites and Telegram to publish stolen data and conduct psychological operations, and U.S. authorities have seized related domains and issued defensive guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.