Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign

Iranian MOIS Actors Leveraging Cybercrime Ecosystem (TL-2026-0215), also tracked as Operation Handala, is a critical-severity advanced persistent threat campaign, first published 2026-03-12. It is attributed to Void Manticore (Iran) with high confidence, affects Multiple Healthcare Systems, maps to 33 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-0215

Threat ID
TL-2026-0215
Also known as
Operation Handala, MOIS Cyber Crime Connection
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-03-12
Last reviewed
2026-03-12
Attribution
Void Manticore
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
healthcare, government, defense, telecommunications, energy, financial, aviation, critical-infrastructure, software-supply-chain
Target regions
Israel, Middle East, United States, Albania, Europe, North America
Detection rules
9
Indicators of compromise
30

Malware and tooling in Iranian MOIS Actors Leveraging Cybercrime Ecosystem

Malware and tooling: BiBi Wiper, CASTLELOADER, DarkComp, FakeSet, Qilin Ransomware, Rhadamanthys, StageComp, Tsundere Botnet - S9034, Rclone - S1040, Tsundere Botnet

Iranian MOIS-affiliated threat actors Void Manticore and MuddyWater have evolved from imitating cybercriminals to actively leveraging criminal ecosystems including Qilin RaaS, CastleLoader MaaS, and Rhadamanthys infostealer. Campaigns target Israeli healthcare, U.S. critical infrastructure, and Middle Eastern government sectors with phishing, code-signing abuse, wiper malware, and multi-stage delivery chains.

How Iranian MOIS Actors Leveraging Cybercrime Ecosystem works

Check Point Research published a comprehensive analysis on March 10, 2026 documenting how Iranian Ministry of Intelligence and Security (MOIS) threat actors have fundamentally shifted their operational model. Rather than merely mimicking cybercriminal behavior for cover, Void Manticore and MuddyWater now actively participate in criminal ecosystems as affiliates and customers, gaining access to mature tooling, resilient infrastructure, and tested extortion playbooks.

Void Manticore (tracked by Microsoft as Storm-0842, also known as Banished Kitten) operates multiple hack-and-leak personas including Homeland Justice (targeting Albania), Karma, and Handala (targeting Israel). The Handala persona campaigns revealed deployment of Rhadamanthys, a commercial infostealer sold on darknet forums. In several campaigns, Void Manticore operators paired Rhadamanthys with custom wiper malware in phishing emails impersonating the Israeli National Cyber Directorate and F5 software updates. This combination of high-end espionage, data theft, and sabotage with off-the-shelf criminal tooling represents a significant operational evolution.

MuddyWater (tracked as Mango Sandstorm, Seedworm, TEMP.Zagros, Static Kitten, Earth Vetala), confirmed by CISA as a subordinate element within MOIS, has been linked to the Tsundere botnet uncovered in late 2025. The Tsundere botnet uses Node.js and JavaScript scripts for code execution on compromised systems, with the ability to dynamically switch to the Deno runtime — this Deno-based variant has been designated DinDoor. MuddyWater campaigns in early 2026 compromised U.S. banks, airports, and software companies supplying defense/aerospace sectors. The FakeSet Python-based downloader delivers CastleLoader malware-as-a-service payloads, with both tools signed using suspicious code-signing certificates bearing the names Amy Cherne and Donald Gay.

The October 2025 ransomware attack on Shamir Medical Center in Israel was initially attributed to the Qilin ransomware group but Israeli assessments later pointed to Iranian actors as the true operators. By working through Qilin's established RaaS franchise, Iranian actors gained plausible deniability, hardened infrastructure, and tested extortion playbooks. This forms part of a broader MOIS and Hezbollah campaign targeting Israeli hospitals.

Code-signing certificate overlap across FakeSet, CastleLoader, StageComp, DarkComp, and DinDoor samples suggests shared certificate acquisition sources between these tools, though not necessarily shared operators. Data exfiltration via rclone to Wasabi cloud storage has been observed in MuddyWater operations, with IP 18.223.24.218 identified as a Wasabi server previously associated with MuddyWater activity.

This convergence of state-sponsored and criminal cyber operations mirrors MOIS's physical-world use of criminal networks for kidnappings, assassinations, and dissident targeting, as documented by the U.S. Treasury Department. The implications for defenders are significant: attribution becomes more complex, tooling more sophisticated, and the operational tempo higher as state actors leverage commercial criminal infrastructure.

MITRE ATT&CK techniques used in TL-2026-0215

credential-access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

lateral-movement

T1021 Remote Services; T1210 Exploitation of Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution

collection

T1056 Input Capture; T1074 Data Staged; T1113 Screen Capture

command-and-control

T1071 Application Layer Protocol; T1102 Web Service; T1104 Multi-Stage Channels; T1105 Ingress Tool Transfer

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1561 Disk Wipe

persistence

T1547 Boot or Logon Autostart Execution

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

initial-access

T1566 Phishing

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Affected products and versions in Iranian MOIS Actors Leveraging Cybercrime Ecosystem

  • Multiple — Healthcare Systems
    Vulnerable versions: All
  • Multiple — Government Networks
    Vulnerable versions: All
  • Multiple — Defense/Aerospace Software Supply Chain
    Vulnerable versions: All
  • Multiple — Banking and Financial Systems
    Vulnerable versions: All
  • Multiple — Airport and Aviation Systems
    Vulnerable versions: All

Remediation for Iranian MOIS Actors Leveraging Cybercrime Ecosystem

Immediate actions

  • Block known IOC hashes at endpoint and gateway
  • Block IP 18.223.24.218 at perimeter firewalls
  • Revoke and block code-signing certificates with CN Amy Cherne and Donald Gay
  • Hunt for Rhadamanthys infostealer indicators across endpoint fleet
  • Implement email filtering for impersonation of government cyber agencies and software vendors

Workarounds

  • Block Deno and Node.js execution from non-standard paths
  • Restrict rclone usage via application control policies
  • Implement code-signing certificate validation and allowlisting
  • Enable enhanced email security scanning for phishing impersonation lures

Longer-term hardening

  • Deploy EDR with behavioral detection for Deno/Node.js runtime abuse
  • Implement DMARC/SPF/DKIM email authentication to prevent sender impersonation
  • Monitor for rclone and other legitimate tool abuse for data exfiltration
  • Implement DLP controls on cloud storage services including Wasabi and Backblaze
  • Deploy network segmentation especially for healthcare and critical infrastructure
  • Implement zero-trust architecture with continuous verification
  • Establish threat intelligence feeds covering Iranian APT indicators

Timeline of Iranian MOIS Actors Leveraging Cybercrime Ecosystem

  • MuddyWater first observed conducting cyber espionage operations targeting Middle Eastern organizations
  • CISA publishes advisory confirming MuddyWater as subordinate element within Iranian MOIS
  • Sustained MOIS and Hezbollah campaign begins targeting Israeli hospitals and healthcare systems
  • Check Point Research publishes detailed analysis of Void Manticore destructive activities in Israel including BiBi wiper
  • Shamir Medical Center in Israel attacked with Qilin ransomware; later attributed to Iranian MOIS actors
  • Tsundere botnet uncovered and subsequently linked to MuddyWater operations
  • MuddyWater DinDoor campaign begins targeting U.S. banks, airports, and defense/aerospace software suppliers
  • Certificate overlap discovered between FakeSet, CastleLoader, StageComp, and DinDoor samples signed with Amy Cherne and Donald Gay certificates
  • Void Manticore Handala campaigns documented using Rhadamanthys infostealer paired with custom wipers in phishing targeting Israeli organizations
  • Check Point Research publishes comprehensive report documenting MOIS actors leveraging cybercrime ecosystems including Qilin RaaS, CastleLoader MaaS, and Rhadamanthys
  • As of 2026-05-29, this Iranian MOIS campaign (Void Manticore/MuddyWater) remains ACTIVE and escalating: CISA advisory AA26-097a flagged Iranian PLC attacks, Handala claimed the March Stryker wiper, and new RustyWater/DinDoor and a May 6 Rapid7 false-flag op are reported. No CVE, no actor disruption, sanctions, or superseding successor; confidence high.

Sources cited for Iranian MOIS Actors Leveraging Cybercrime Ecosystem

Threats related to Iranian MOIS Actors Leveraging Cybercrime Ecosystem

Detection coverage for TL-2026-0215

As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0215 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats