Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign — Threadlinqs Intelligence
As of 2026-05-30, Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign is a critical-severity apt threat attributed to Void Manticore (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0215 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: Void Manticore · Iran · DESTRUCTION
Iranian MOIS-affiliated threat actors Void Manticore and MuddyWater have evolved from imitating cybercriminals to actively leveraging criminal ecosystems including Qilin RaaS, CastleLoader MaaS, and
Check Point Research published a comprehensive analysis on March 10, 2026 documenting how Iranian Ministry of Intelligence and Security (MOIS) threat actors have fundamentally shifted their operational model. Rather than merely mimicking cybercriminal behavior for cover, Void Manticore and MuddyWater now actively participate in criminal ecosystems as affiliates and customers, gaining access to mature tooling, resilient infrastructure, and tested extortion playbooks.
Void Manticore (tracked by Microsoft as Storm-0842, also known as Banished Kitten) operates multiple hack-and-leak personas including Homeland Justice (targeting Albania), Karma, and Handala (targeting Israel). The Handala persona campaigns revealed deployment of Rhadamanthys, a commercial infostealer sold on darknet forums. In several campaigns, Void Manticore operators paired Rhadamanthys with custom wiper malware in phishing emails impersonating the Israeli National Cyber Directorate and F5 software updates. This combination of high-end espionage, data theft, and sabotage with off-the-shelf criminal tooling represents a significant operational evolution.
MuddyWater (tracked as Mango Sandstorm, Seedworm, TEMP.Zagros, Static Kitten, Earth Vetala), confirmed by CISA as a subordinate element within MOIS, has been linked to the Tsundere botnet uncovered in late 2025. The Tsundere botnet uses Node.js and JavaScript scripts for code execution on compromised systems, with the ability to dynamically switch to the Deno runtime — this Deno-based variant has been designated DinDoor. MuddyWater campaigns in early 2026 compromised U.S. banks, airports, and software companies supplying defense/aerospace sectors. The FakeSet Python-based downloader delivers CastleLoader malware-as-a-service payloads, with both tools signed using suspicious code-signing certificates bearing the names Amy Cherne and Donald Gay.
The October 2025 ransomware attack on Shamir Medical Center in Israel was initially attributed to the Qilin ransomware group but Israeli assessments later pointed to Iranian actors as the true operators. By working through Qilin's established RaaS franchise, Iranian actors gained plausible deniability, hardened infrastructure, and tested extortion playbooks. This forms part of a broader MOIS and Hezbollah campaign targeting Israeli hospitals.
Code-signing certificate overlap across FakeSet, CastleLoader, StageComp, DarkComp, and DinDoor samples suggests shared certificate acquisition sources between these tools, though not necessarily shared operators. Data exfiltration via rclone to Wasabi cloud storage has been observed in MuddyWater operations, with IP 18.223.24.218 identified as a Wasabi server previously associated with MuddyWater activity.
This convergence of state-sponsored and criminal cyber operations mirrors MOIS's physical-world use of criminal networks for kidnappings, assassinations, and dissident targeting, as documented by the U.S. Treasury Department. The implications for defenders are significant: attribution becomes more complex, tooling more sophisticated, and the operational tempo higher as state actors leverage commercial criminal infrastructure.
Target sectors: healthcare, government, defense, telecommunications, energy, financial, aviation, critical-infrastructure, software-supply-chain
Target regions: Israel, Middle East, United States, Albania, Europe, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1566, T1566, T1059, T1059, T1059, T1204, T1204, T1547, T1053, T1036