Iranian Cyber Activity: Blurring Lines Between State Actors and Cybercrime
For years, Iranian intelligence services have leveraged criminal networks for deniable operations in the physical world. A similar pattern is now emerging in cyberspace, where state objectives are increasingly pursued through the tools, services, and operational models of the cybercrime ecosystem. This shift is particularly noticeable among actors linked to Iran’s Ministry of Intelligence and Security (MOIS).
From Cover to Collaboration: A Changing Landscape
Historically, Iranian actors have masked state-sponsored activity behind the guise of ordinary cybercrime, often posing as ransomware operators. However, the current trend goes beyond mere imitation. Rather than simply adopting criminal personas for attribution obfuscation, some Iranian actors are actively engaging with the cybercriminal ecosystem, utilizing its malware, infrastructure, and affiliate-style mechanisms. This evolution not only enhances deniability but also expands operational reach and technical capabilities.
MOIS and the Criminal Connection
The U.S. Treasury and the FBI have documented instances of cooperation between Iran’s intelligence services and criminal actors, predating the focus on digital arenas. These collaborations provided Tehran with reach, deniability, and access to individuals willing to carry out operations at arm’s length. Similar patterns have been observed in Sweden, where Iranian regime-linked criminal networks have been implicated in violent acts against perceived threats, including attacks targeting Israeli and Jewish interests. Iranian nation-state cyber actors remain a persistent and strategically motivated threat, known for targeting government agencies and critical infrastructure.
Void Manticore (Handala) and Rhadamanthys Infostealer
Void Manticore, an Iranian threat actor affiliated with MOIS, is a prominent group pursuing strategic objectives through cyber operations. Operating under hacktivist personas like Homeland Justice and Handala, it has been linked to disruptive attacks and “hack and leak” operations, particularly targeting Israel. Notably, Void Manticore has begun utilizing Rhadamanthys, a commercially available infostealer sold on darknet forums. Iran-linked actors are increasingly engaging with the cyber crime ecosystem.
Handala has deployed Rhadamanthys in phishing campaigns aimed at Israeli targets, often impersonating legitimate software updates, such as those from F5, and even the Israeli National Cyber Directorate (INCD). Despite international law enforcement efforts to disrupt Rhadamanthys infrastructure in November, including the seizure of 1,025 servers, the malware remains a threat.
MuddyWater and Criminal Tooling
MuddyWater, another MOIS-linked threat actor, has been conducting cyber espionage and malicious operations in the Middle East for years. Recent reports connect MuddyWater’s activities to several cybercrime clusters, creating confusion and potentially hindering accurate attribution. This demonstrates the effectiveness of using criminal software for obfuscation.
Specifically, MuddyWater has been linked to the Tsundere Botnet (also known as DinDoor) and the Castle Loader (FakeSet) malware families. The apply of code-signing certificates under the Common Names “Amy Cherne” and “Donald Gay” across MuddyWater malware, Tsundere Deno malware, and CastleLoader variants suggests a common source for these certificates, though it doesn’t necessarily indicate a direct affiliate relationship.
Qilin Ransomware and Strategic Objectives
In October 2025, the Shamir Medical Center in Israel was targeted in a cyberattack initially attributed to the Qilin ransomware group. However, subsequent assessments pointed to Iranian actors leveraging the Qilin ransomware-as-a-service (RaaS) operation to achieve strategic objectives. This suggests that Iranian-affiliated operators are utilizing criminal ransomware brands and methods to mask their activities and potentially circumvent heightened security measures.
This attack is part of a broader campaign by MOIS and Hezbollah targeting Israeli hospitals, a pattern evident since late 2023.
Conclusion
The examined cases demonstrate a clear shift in Iranian cyber activity. For some actors, cybercrime is no longer simply a cover for state-directed operations but an operational resource. Engagement with criminal tools and services enhances capabilities while complicating attribution. This trend highlights the increasing convergence between state-sponsored cyber activity and the cybercrime ecosystem.
Indicators of Compromise
- Handala Rhadmanthys Variants: aae017e7a36e016655c91bd01b4f3c46309bbe540733f82cce29392e72e9bd1f
- Malware samples signed with suspicious certificates:
| sha256 | Certificate Common Name | Certificate Thumbprint | Certificate Serial Number | Malware Family |
|---|---|---|---|---|
| 077ab28d66abdafad9f5411e18d26e87fe43da1410ee8fe846bd721ab0cb52de | Amy Cherne | 0902d7915a19975817ec1ccb0f2f6714aed19638 | 330007f1068f41bf0f662a03b500000007f106 | FakeSet / CastleLoader |
| ddceade244c636435f2444cd4c4d3dc161981f3af1f622c03442747ecef50888 | Amy Cherne | 0902d7915a19975817ec1ccb0f2f6714aed19638 | 330007f1068f41bf0f662a03b500000007f106 | FakeSet / CastleLoader |
| 2b7d8a519f44d3105e9fde2770c75efb933994c658855dca7d48c8b4897f81e6 | Amy Cherne | 2087bb914327e937ea6e77fe6c832576338c2af8 | 330006df515a14fe3748416fe200000006df51 | FakeSet / CastleLoader |
| 64cf334716f15da1db7981fad6c81a640d94aa1d65391ef879f4b7b6edf6e7f1 | Amy Cherne | 21a435ecaa7b86efbec7f6fb61fcda3da686125c | 330006e75231f49437ae56778a00000006e752 | FakeSet / CastleLoader |
| 74db1f653da6de134bdc526412a517a30b6856de9c3e5d0c742cb5fe9959ad0d | Amy Cherne | 389b12da259a23fa4559eb1d97198120f2a722fe | 330007d5443a7d25208ec5feb100000007d544 | FakeSet / CastleLoader |
| 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444 | Amy Cherne | 389b12da259a23fa4559eb1d97198120f2a722fe | 330007d5443a7d25208ec5feb100000007d544 | FakeSet / CastleLoader |
| 4aef998e3b3f6ca21c78ed71732c9d2bdcc8a4e0284f51d7462c79d446fbc7be | Amy Cherne | 551bdf646df8e9abe04483882650a8ffae43cb55 | 330006e15e43401dbd9416e20e00000006e15e | FakeSet / CastleLoader |
| a4bd1371fe644d7e6898045cc8e7b5e1562bdfd0e4871d46034e29a22dec6377 | Amy Cherne | d920ae0f8ea8b5bd42de49e01c6bbd4c2c6d0847 | 330007ebfbe75a64b52aaf4cb700000007ebfb | FakeSet / CastleLoader |
| 64263640a6fdeb2388bca2e9094a17065308cf8dcb0032454c0a71d9b78327eb | Donald Gay | f8444dfc740b94227ab9b2e757b8f8f1fa49362a | 3300072b29c3bf8403a6c15be2000000072b29 | FakeSet / CastleLoader |
| a8c380b57cb7c381ca6ba845bd7af7333f52ee4dc4e935e98b48bb81facad72b | Donald Gay | 9dcb994ea2b8e6169b76a524fae7b2d2dcd1807d | 33000725fea86dd19e8571b26c0000000725fe | FakeSet / CastleLoader |
| 24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14 | Donald Gay | b674578d4bdb24cd58bf2dc884eaa658b7aa250c | 3300079a51c7063e66053d229b000000079a51 | StageComp |
| a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0 | Donald Gay | b674578d4bdb24cd58bf2dc884eaa658b7aa250c | 3300079a51c7063e66053d229b000000079a51 | StageComp |
| 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5 | Amy Cherne | 551bdf646df8e9abe04483882650a8ffae43cb55 | 330006e15e43401dbd9416e20e00000006e15e | DinDoor / Tsundere Deno |
Worth a look