Iran’s MOIS Tied to Coordinated Cyber Campaign Using Multiple Hacker Personas
ID: c25c4d6d-58db-5e66-a934-d1f6a35c2a48
STIX ID: report--c25c4d6d-58db-5e66-a934-d1f6a35c2a48
Feed Name: GBHackers
This report links three branded personas (Homeland Justice, Karma/KarmaBelow80, Handala) to Iran’s MOIS and describes a unified, state‑directed hack‑and‑leak influence campaign that conducts long‑term intrusions, credential theft, data exfiltration, destructive wiping/encryption (including BiBi Wiper and ransomware‑style actions), and abuse of legitimate cloud/admin tools (notably a reported Intune remote‑wipe affecting up to 200,000 devices); the ecosystem uses recurring leak sites and Telegram to publish stolen data and conduct psychological operations, and U.S. authorities have seized related domains and issued defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
