logo

Blurring the Lines: How Iranian State Hackers are Weaponizing RaaS and the Cybercriminal Underground

ID: 82b0a84a-8d94-5b40-aee8-7446cb086815

STIX ID: report--82b0a84a-8d94-5b40-aee8-7446cb086815

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Check Point Research reports that Iranian intelligence-linked groups have shifted from imitating cybercriminals to actively leveraging the cybercrime ecosystem—purchasing commercial malware, using info-stealers like Rhadamanthys, deploying custom wipers, and participating as affiliates in Ransomware-as-a-Service operations—complicating attribution and enabling high-impact attacks such as the reported 8 TB breach of Shamir Medical Center.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.