Tag: Ministry of Intelligence and Security (MOIS)

Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle East
News

Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle East

The Ministry of Intelligence and Security (MOIS) is probably connected to an Iranian advanced persistent threat (APT) threat actor that is now serving as an initial access facilitator, granting remote access to target networks. Google-owned Mandiant is following the activity cluster under the pseudonym UNC1860. According to Mandiant, this activity cluster is comparable to intrusion sets that are being tracked by Microsoft, Cisco Talos, and Check Point under the respective names Storm-0861 (previously DEV-0861), ShroudedSnooper, and Scarred Manticore. UNC1860's collection of specialized tooling and passive backdoors is a key component, according to the company, that […] supports multiple objectives, including its potential role as a first access provider and its capacity to obtain co...
Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel
News

Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel

Under the aliases Homeland Justice and Karma, respectively, an Iranian threat actor connected to the Ministry of Intelligence and Security (MOIS) has been implicated in damaging wipe attacks against Israel and Albania. The behavior is being monitored by cybersecurity company Check Point under the code name Void Manticore; Microsoft has also dubbed this code Storm-0842 (formerly DEV-0842). In a report released today, the company stated that there are obvious overlaps between the targets of Void Manticore and Scarred Manticore, as well as signs of a systematic target handoff between those two groups when choosing to carry out destructive activities against Scarred Manticore's current victims. Under the alias Homeland Justice, the threat actor has been well-known for its disruptive ...