Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel
ID: 74c22daf-531e-54da-b5f8-078f6216c5a3
STIX ID: report--74c22daf-531e-54da-b5f8-078f6216c5a3
Feed Name: The Hacker News
Threat Score
Check Point attributes destructive wiping campaigns against Albania and Israel to an Iranian MOIS‑linked actor tracked as Void Manticore (Storm‑0842), noting use of bespoke wipers (Cl Wiper, No‑Justice/LowEraser, BiBi), exploitation of known internet‑facing flaws, RDP/SMB/FTP lateral movement, web shells (Karma Shell), and operational handoffs with related Iranian clusters such as Storm‑0861.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
