惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
I
InfoQ
U
Unit 42
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
月光博客
月光博客
D
Docker
Stack Overflow Blog
Stack Overflow Blog
D
DataBreaches.Net
阮一峰的网络日志
阮一峰的网络日志
Blog — PlanetScale
Blog — PlanetScale
V
Visual Studio Blog
博客园 - 聂微东
A
About on SuperTechFans
腾讯CDC
Jina AI
Jina AI
Microsoft Azure Blog
Microsoft Azure Blog
GbyAI
GbyAI
博客园 - 【当耐特】
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
M
MIT News - Artificial intelligence

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
Cybercrime isn't just a cover for Iran's government goons
Jessica Lyons Jessica Lyons · 2026-03-11 · via The Register - Security: Cyber-crime

Cyber-crime

Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations

Ransomware, malware-as-a-service, infostealers benefit MOIS, too

Iranian government-backed snoops are increasingly using cybercrime malware and ransomware infrastructure in their operations - not just hiding behind criminal masks as a cover for destructive cyber activity, according to security researchers.

Ministry of Intelligence and Security (MOIS)-linked operatives appear to be the biggest offenders, according to Check Point Research, citing "repeated overlaps" between MuddyWater (aka Seedworm, Static Kitten) and Void Manticore (aka Storm-842, Handala Hack), and various criminal organizations and their tools and services. Both MuddyWater and Void Manticore are affiliated with the Iranian intelligence agency. 

Void Manticore is a hacktivist crew that uses wipers, data leaks, and disinformation to advance Iranian government objectives, usually in campaigns targeting Israel. It also recently added a commercial infostealer - Rhadamanthys - sold on cybercrime forums to its arsenal, according to Check Point.

As The Reg readers likely remember, international cops disrupted Rhadamanthys operators' infrastructure in November, seizing 1,025 servers tied to the malware during a series of raids. But as is usually the case with malware operators and movie monsters, this was more of a setback than an outright kill.

Handala Hack, one of Void Manticore's hacktivist personas, has used Rhadamanthys "on several occasions," according to the Tel Aviv-based security researchers. The Iranian cyberspies typically pair the commercial infostealer with one of their custom data wipers in phishing emails sent to Israeli targets, frequently impersonating F5 updates, we're told. In the Tuesday research, Check Point shows one of these phishes that impersonated the Israeli National Cyber Directorate (INCD).

MuddyWater dips into malware-as-a-service

MuddyWater, on the other hand, has conducted espionage operations on behalf of the MOIS since about 2018, most recently burrowing into critical American networks following the US and Israeli airstrikes against Iran. In these intrusions, the group used a previously unseen backdoor called DinDoor, which is a new variant of the MuddyWater-linked Tsundere botnet, according to Check Point.

Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews. According to Check Point, the link between CastleLoader and MuddyWater stems from the use of a set of code-signing certificates, specifically under the Common Names Amy Cherne and Donald Gay - also spotted in the DinDoor campaign.

These reports linking MuddyWater's operations to several different crime clusters benefit the government-backed group, the Tel Aviv security shop said. 

"The use of such tools has created significant confusion, leading to misattribution and flawed pivoting, and clustering together activities that are not necessarily related," Check Point Research wrote. "This demonstrates that the use of criminal software can be effective for obfuscation, and highlights the need for extreme caution when analyzing overlapping clusters."

Finally, while Iran's goon squads have a history of working with ransomware gangs, and we saw state-sponsored ransomware attempts reemerge during the summer 2025 conflict, offering big bucks for infections against US and Israeli orgs, more recent reports have linked Iranian operatives to an October 2025 ransomware attack against the Israeli Shamir Medical Center. This infection initially appeared to have been carried out by a Qilin affiliate. 

"The emerging picture was that the attackers were likely Iranian-affiliated operators working through the cyber criminal ecosystem, using a criminal ransomware brand and methods associated with the broader extortion market, while serving a strategic Iranian objective," Check Point said, adding that this ransomware infection is part of a larger campaign by MOIS and Hezbollah to target Israeli hospitals. ®