Threats Feed
- Public
Iran MOIS Cyber Actors Deploy Telegram C2 Malware Against Global Dissidents and Journalists
Iran Ministry of Intelligence and Security (MOIS) cyber actors are executing a global malware campaign targeting Iranian dissidents, journalists, and opposition groups. Using social engineering via messaging platforms, attackers deliver first-stage malware disguised as legitimate software, such as Telegram or KeePass. Upon execution, a persistent second-stage implant establishes a command-and-control channel via Telegram bots. This allows the attackers to harvest and exfiltrate sensitive data, including screen and audio captures from active Zoom sessions. Linked to proxy groups like "Handala Hack," these operations fuel hack-and-leak campaigns and deploy custom wiper malware. The attacks ultimately aim to conduct intelligence collection and inflict reputational damage on individuals threatening the Government of Iran's narratives.
read more about Iran MOIS Cyber Actors Deploy Telegram C2 Malware Against Global Dissidents and Journalists - Public
Handala Hack: Unpacking Void Manticore’s Destructive Wiping and Hack-and-Leak Operations
Handala Hack, an Iranian MOIS-affiliated threat actor also tracked as Void Manticore, executes destructive wiping and hack-and-leak operations against targets in Israel, Albania, and the United States. They primarily target the government, telecommunications, and medical technology sectors. The group relies on compromised VPN accounts for initial access, subsequently moving laterally via RDP and the zero-trust mesh platform NetBird. Their hands-on attacks involve disabling Windows Defender and conducting extensive credential dumping via LSASS extraction and ADRecon. To maximize operational impact, Handala simultaneously deploys custom MBR and PowerShell wipers via Group Policy, leverages VeraCrypt for disk encryption, and manually deletes virtual machines, causing severe data destruction.
read more about Handala Hack: Unpacking Void Manticore’s Destructive Wiping and Hack-and-Leak Operations - Public
Iranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations
Iranian Ministry of Intelligence and Security (MOIS)-linked threat actors, such as Void Manticore and MuddyWater, are actively integrating cybercriminal tools and affiliate networks into their state-sponsored operations. Moving beyond merely using cybercrime as a cover for deniability, these groups are leveraging commercial infostealers like Rhadamanthys, malware-as-a-service networks like CastleLoader, and the Qilin ransomware-as-a-service (RaaS) to enhance their operational reach and obfuscate attribution. Recent campaigns have targeted government and private sectors, including telecommunications, defense, energy, and medical facilities—across the Middle East, Israel, Albania, and the United States. Notably, these operations have utilized ransomware branding to execute destructive and extortion attacks against Israeli hospitals, fulfilling strategic state objectives through the criminal ecosystem.
read more about Iranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations - Public
Homeland Justice Phishing Operation Hits Diplomatic and Government Sectors Globally
Iran-aligned threat actor linked to the MOIS group Homeland Justice conducted a large-scale spear-phishing campaign in August 2025, using a compromised mailbox of the Omani Ministry of Foreign Affairs to target embassies, consulates, and international organizations worldwide. The malicious Word attachments, disguised as official diplomatic notices, executed VBA macros that decoded and dropped the sysProcUpdate malware. Targets included diplomatic and government institutions across Europe, the Middle East, Africa, Asia, and the Americas, notably during sensitive ceasefire negotiations. The operation aimed at espionage and reconnaissance, leveraging obfuscation, sandbox evasion, and encrypted C2 communication with screenai.online.
read more about Homeland Justice Phishing Operation Hits Diplomatic and Government Sectors Globally - Public
Storm-842: Iranian Cyberattacks on Albania and Israel’s Critical Systems
Storm-842 (Void Manticore), linked to Iran’s Ministry of Intelligence and Security (MOIS), has conducted destructive cyberattacks targeting Albania and Israel. Using wiper malware and influence campaigns, the group disrupted Albanian e-government and border systems, targeting sectors like government and infrastructure, while aligning attacks with geopolitical events such as opposition conferences. Operations include exploiting vulnerabilities, deploying web shells, and credential harvesting, often in coordination with Scarred Manticore. The attacks incorporate ransomware-style encryptors, disk wipers, and data leaks through personas like “Homeland Justice” and “Karma,” showcasing a blend of technical and psychological tactics.
read more about Storm-842: Iranian Cyberattacks on Albania and Israel’s Critical Systems - Public
Void Manticore and Scarred Manticore's Coordinated Cyber Assaults Unveiled
Void Manticore, an Iranian threat actor, executed destructive cyberattacks in Israel and Albania, targeting government sectors. They collaborated with Scarred Manticore, using CVE-2019-0604 for initial access, followed by custom tools like Foxshell and Liontail for command execution. The attacks involved data exfiltration and the deployment of wipers, including the custom BiBi wiper. The group employed Remote Desktop Protocol (RDP) for lateral movement and leveraged Domain Admin credentials for network control. Information leaks were disseminated through personas "Karma" and "Homeland Justice".
read more about Void Manticore and Scarred Manticore's Coordinated Cyber Assaults Unveiled - Public
Homeland Justice Wiper Attack Targets Albanian Telecoms and Government
The Iranian psychological operation group "Homeland Justice" launched a destructive cyberattack targeting Albanian organizations on December 24, 2023. Utilizing a "No-justice" wiper, the group attacked telecom, airline, and government sectors, including ONE Albania, Eagle Mobile Albania, Air Albania, and the Albanian parliament. The attacks were facilitated by malware delivered through PowerShell scripts and executables, employing tools like Plink, RevSocks, and the W2K Res Kit for lateral movement and system manipulation. The campaign, which included methods to give malware an appearance of legitimacy, threatens to extend beyond Albania, indicating a broader geopolitical motive.
read more about Homeland Justice Wiper Attack Targets Albanian Telecoms and Government - Public
Analysis of Homeland Justice's Cyberattack on Albanian Government Infrastructure
Homeland Justice, a politically motivated group emerging in mid-2022, has been linked to cyber attacks targeting the Albanian government and related entities. The group employs tactics such as the deployment of PowerShell scripts and .EXE files, with the former managing connectivity and remote operations and the latter potentially wiping host machine disks. Technical analysis of the payloads revealed sophisticated methods including remote execution, credential exploitation, and data destruction. These actions highlight the group's focus on disrupting Albanian government operations and exposing alleged corruption, signaling significant cyber threats to governmental sectors.
read more about Analysis of Homeland Justice's Cyberattack on Albanian Government Infrastructure - Public
Cyber Espionage in Albania: Tracing the Links Between ROADSWEEP, CHIMNEYSWEEP, and Iranian Actors
In July 2022, Mandiant uncovered the ROADSWEEP ransomware, targeting the Albanian government with a politically motivated campaign. The operation, claimed by “HomeLand Justice,” disrupted Albanian government websites and services. This group also shared videos and documents suggesting ties to the Iranian opposition group MEK. Concurrently, CHIMNEYSWEEP, a backdoor linked to ROADSWEEP, was identified, targeting Farsi and Arabic speakers, including the Iranian diaspora, with capabilities like keylogging and file collection. Both ROADSWEEP and CHIMNEYSWEEP shared code and encryption methods. Additionally, a ZEROCLEAR wiper payload was reported, potentially linked to Iranian threat actors, known for targeting Middle Eastern entities.
read more about Cyber Espionage in Albania: Tracing the Links Between ROADSWEEP, CHIMNEYSWEEP, and Iranian Actors