logo

Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel

ID: 74c22daf-531e-54da-b5f8-078f6216c5a3

STIX ID: report--74c22daf-531e-54da-b5f8-078f6216c5a3

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-05-20

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Check Point attributes destructive wiping campaigns against Albania and Israel to an Iranian MOIS‑linked actor tracked as Void Manticore (Storm‑0842), noting use of bespoke wipers (Cl Wiper, No‑Justice/LowEraser, BiBi), exploitation of known internet‑facing flaws, RDP/SMB/FTP lateral movement, web shells (Karma Shell), and operational handoffs with related Iranian clusters such as Storm‑0861.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.