Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
Iranian MOIS Actors Leveraging Cybercrime Ecosystem (TL-2026-0215), also tracked as Operation Handala, is a critical-severity advanced persistent threat campaign, first published 2026-03-12. It is attributed to Void Manticore (Iran) with high confidence, affects Multiple Healthcare Systems, maps to 33 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0215
- Threat ID
- TL-2026-0215
- Also known as
- Operation Handala, MOIS Cyber Crime Connection
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-12
- Last reviewed
- 2026-03-12
- Attribution
- Void Manticore
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- healthcare, government, defense, telecommunications, energy, financial, aviation, critical-infrastructure, software-supply-chain
- Target regions
- Israel, Middle East, United States, Albania, Europe, North America
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Iranian MOIS Actors Leveraging Cybercrime Ecosystem
Malware and tooling: BiBi Wiper, CASTLELOADER, DarkComp, FakeSet, Qilin Ransomware, Rhadamanthys, StageComp, Tsundere Botnet - S9034, Rclone - S1040, Tsundere Botnet
Iranian MOIS-affiliated threat actors Void Manticore and MuddyWater have evolved from imitating cybercriminals to actively leveraging criminal ecosystems including Qilin RaaS, CastleLoader MaaS, and Rhadamanthys infostealer. Campaigns target Israeli healthcare, U.S. critical infrastructure, and Middle Eastern government sectors with phishing, code-signing abuse, wiper malware, and multi-stage delivery chains.
How Iranian MOIS Actors Leveraging Cybercrime Ecosystem works
Check Point Research published a comprehensive analysis on March 10, 2026 documenting how Iranian Ministry of Intelligence and Security (MOIS) threat actors have fundamentally shifted their operational model. Rather than merely mimicking cybercriminal behavior for cover, Void Manticore and MuddyWater now actively participate in criminal ecosystems as affiliates and customers, gaining access to mature tooling, resilient infrastructure, and tested extortion playbooks.
Void Manticore (tracked by Microsoft as Storm-0842, also known as Banished Kitten) operates multiple hack-and-leak personas including Homeland Justice (targeting Albania), Karma, and Handala (targeting Israel). The Handala persona campaigns revealed deployment of Rhadamanthys, a commercial infostealer sold on darknet forums. In several campaigns, Void Manticore operators paired Rhadamanthys with custom wiper malware in phishing emails impersonating the Israeli National Cyber Directorate and F5 software updates. This combination of high-end espionage, data theft, and sabotage with off-the-shelf criminal tooling represents a significant operational evolution.
MuddyWater (tracked as Mango Sandstorm, Seedworm, TEMP.Zagros, Static Kitten, Earth Vetala), confirmed by CISA as a subordinate element within MOIS, has been linked to the Tsundere botnet uncovered in late 2025. The Tsundere botnet uses Node.js and JavaScript scripts for code execution on compromised systems, with the ability to dynamically switch to the Deno runtime — this Deno-based variant has been designated DinDoor. MuddyWater campaigns in early 2026 compromised U.S. banks, airports, and software companies supplying defense/aerospace sectors. The FakeSet Python-based downloader delivers CastleLoader malware-as-a-service payloads, with both tools signed using suspicious code-signing certificates bearing the names Amy Cherne and Donald Gay.
The October 2025 ransomware attack on Shamir Medical Center in Israel was initially attributed to the Qilin ransomware group but Israeli assessments later pointed to Iranian actors as the true operators. By working through Qilin's established RaaS franchise, Iranian actors gained plausible deniability, hardened infrastructure, and tested extortion playbooks. This forms part of a broader MOIS and Hezbollah campaign targeting Israeli hospitals.
Code-signing certificate overlap across FakeSet, CastleLoader, StageComp, DarkComp, and DinDoor samples suggests shared certificate acquisition sources between these tools, though not necessarily shared operators. Data exfiltration via rclone to Wasabi cloud storage has been observed in MuddyWater operations, with IP 18.223.24.218 identified as a Wasabi server previously associated with MuddyWater activity.
This convergence of state-sponsored and criminal cyber operations mirrors MOIS's physical-world use of criminal networks for kidnappings, assassinations, and dissident targeting, as documented by the U.S. Treasury Department. The implications for defenders are significant: attribution becomes more complex, tooling more sophisticated, and the operational tempo higher as state actors leverage commercial criminal infrastructure.
MITRE ATT&CK techniques used in TL-2026-0215
credential-access
T1003 OS Credential Dumping; T1555 Credentials from Password Stores
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
lateral-movement
T1021 Remote Services; T1210 Exploitation of Remote Services
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution
collection
T1056 Input Capture; T1074 Data Staged; T1113 Screen Capture
command-and-control
T1071 Application Layer Protocol; T1102 Web Service; T1104 Multi-Stage Channels; T1105 Ingress Tool Transfer
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1561 Disk Wipe
persistence
T1547 Boot or Logon Autostart Execution
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
initial-access
resource-development
Affected products and versions in Iranian MOIS Actors Leveraging Cybercrime Ecosystem
- Multiple — Healthcare Systems
Vulnerable versions: All - Multiple — Government Networks
Vulnerable versions: All - Multiple — Defense/Aerospace Software Supply Chain
Vulnerable versions: All - Multiple — Banking and Financial Systems
Vulnerable versions: All - Multiple — Airport and Aviation Systems
Vulnerable versions: All
Remediation for Iranian MOIS Actors Leveraging Cybercrime Ecosystem
Immediate actions
- Block known IOC hashes at endpoint and gateway
- Block IP 18.223.24.218 at perimeter firewalls
- Revoke and block code-signing certificates with CN Amy Cherne and Donald Gay
- Hunt for Rhadamanthys infostealer indicators across endpoint fleet
- Implement email filtering for impersonation of government cyber agencies and software vendors
Workarounds
- Block Deno and Node.js execution from non-standard paths
- Restrict rclone usage via application control policies
- Implement code-signing certificate validation and allowlisting
- Enable enhanced email security scanning for phishing impersonation lures
Longer-term hardening
- Deploy EDR with behavioral detection for Deno/Node.js runtime abuse
- Implement DMARC/SPF/DKIM email authentication to prevent sender impersonation
- Monitor for rclone and other legitimate tool abuse for data exfiltration
- Implement DLP controls on cloud storage services including Wasabi and Backblaze
- Deploy network segmentation especially for healthcare and critical infrastructure
- Implement zero-trust architecture with continuous verification
- Establish threat intelligence feeds covering Iranian APT indicators
Timeline of Iranian MOIS Actors Leveraging Cybercrime Ecosystem
- MuddyWater first observed conducting cyber espionage operations targeting Middle Eastern organizations
- CISA publishes advisory confirming MuddyWater as subordinate element within Iranian MOIS
- Sustained MOIS and Hezbollah campaign begins targeting Israeli hospitals and healthcare systems
- Check Point Research publishes detailed analysis of Void Manticore destructive activities in Israel including BiBi wiper
- Shamir Medical Center in Israel attacked with Qilin ransomware; later attributed to Iranian MOIS actors
- Tsundere botnet uncovered and subsequently linked to MuddyWater operations
- MuddyWater DinDoor campaign begins targeting U.S. banks, airports, and defense/aerospace software suppliers
- Certificate overlap discovered between FakeSet, CastleLoader, StageComp, and DinDoor samples signed with Amy Cherne and Donald Gay certificates
- Void Manticore Handala campaigns documented using Rhadamanthys infostealer paired with custom wipers in phishing targeting Israeli organizations
- Check Point Research publishes comprehensive report documenting MOIS actors leveraging cybercrime ecosystems including Qilin RaaS, CastleLoader MaaS, and Rhadamanthys
- As of 2026-05-29, this Iranian MOIS campaign (Void Manticore/MuddyWater) remains ACTIVE and escalating: CISA advisory AA26-097a flagged Iranian PLC attacks, Handala claimed the March Stryker wiper, and new RustyWater/DinDoor and a May 6 Rapid7 false-flag op are reported. No CVE, no actor disruption, sanctions, or superseding successor; confidence high.
Sources cited for Iranian MOIS Actors Leveraging Cybercrime Ecosystem
- Check Point Research: Iranian MOIS Actors & the Cyber Crime Connection
- Malpedia Library Entry — MOIS Cyber Crime Connection
- The Register: Cybercrime Isn't Just a Cover for Iran's Government Goons
- The Hacker News: Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
- Check Point Blog: What Defenders Need to Know about Iran's Cyber Capabilities
- Security Boulevard: Cyber Retaliation — Analyzing Iranian Cyber Activity Following Operation Epic Fury
- GBHackers: Iran-Linked Hackers Tap Criminal Ecosystem to Bolster State Cyber Ops
- Industrial Cyber: Iran-linked cyber espionage surges across Middle East
- Check Point Research: Bad Karma, No Justice — Void Manticore Destructive Activities in Israel
- SOCRadar: Dark Web Profile — Storm-842 (Void Manticore)
- MITRE ATT&CK: MuddyWater (G0069)
- CXO Today: Strategic Intelligence — Decoding Iran's Cyber Capabilities in the 2026 Crisis
Threats related to Iranian MOIS Actors Leveraging Cybercrime Ecosystem
- Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset Backdoors
- Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software Company
- Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure
- Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign)
- Iran Conflict Cyber Operations: MuddyWater (Seedworm) Deploys New Dindoor and Fakeset Backdoors Against US Banks, Airports, Non-Profits, and Defense/Aerospace Software Providers (Feb-Mar 2026)
- MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering, DWAgent Persistence, Game.exe RAT Trojanizing Microsoft WebView2APISample (Operation Olalampo Link)
Detection coverage for TL-2026-0215
As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0215 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.