Iranian Cyber Actors Increasingly Leverage Criminal Ecosystems

0 comments

Iranian Cyber Activity: Blurring Lines Between State Actors and Cybercrime

For years, Iranian intelligence services have leveraged criminal networks for deniable operations in the physical world. A similar pattern is now emerging in cyberspace, where state objectives are increasingly pursued through the tools, services, and operational models of the cybercrime ecosystem. This shift is particularly noticeable among actors linked to Iran’s Ministry of Intelligence and Security (MOIS).

From Cover to Collaboration: A Changing Landscape

Historically, Iranian actors have masked state-sponsored activity behind the guise of ordinary cybercrime, often posing as ransomware operators. However, the current trend goes beyond mere imitation. Rather than simply adopting criminal personas for attribution obfuscation, some Iranian actors are actively engaging with the cybercriminal ecosystem, utilizing its malware, infrastructure, and affiliate-style mechanisms. This evolution not only enhances deniability but also expands operational reach and technical capabilities.

MOIS and the Criminal Connection

The U.S. Treasury and the FBI have documented instances of cooperation between Iran’s intelligence services and criminal actors, predating the focus on digital arenas. These collaborations provided Tehran with reach, deniability, and access to individuals willing to carry out operations at arm’s length. Similar patterns have been observed in Sweden, where Iranian regime-linked criminal networks have been implicated in violent acts against perceived threats, including attacks targeting Israeli and Jewish interests. Iranian nation-state cyber actors remain a persistent and strategically motivated threat, known for targeting government agencies and critical infrastructure.

Void Manticore (Handala) and Rhadamanthys Infostealer

Void Manticore, an Iranian threat actor affiliated with MOIS, is a prominent group pursuing strategic objectives through cyber operations. Operating under hacktivist personas like Homeland Justice and Handala, it has been linked to disruptive attacks and “hack and leak” operations, particularly targeting Israel. Notably, Void Manticore has begun utilizing Rhadamanthys, a commercially available infostealer sold on darknet forums. Iran-linked actors are increasingly engaging with the cyber crime ecosystem.

Handala has deployed Rhadamanthys in phishing campaigns aimed at Israeli targets, often impersonating legitimate software updates, such as those from F5, and even the Israeli National Cyber Directorate (INCD). Despite international law enforcement efforts to disrupt Rhadamanthys infrastructure in November, including the seizure of 1,025 servers, the malware remains a threat.

MuddyWater and Criminal Tooling

MuddyWater, another MOIS-linked threat actor, has been conducting cyber espionage and malicious operations in the Middle East for years. Recent reports connect MuddyWater’s activities to several cybercrime clusters, creating confusion and potentially hindering accurate attribution. This demonstrates the effectiveness of using criminal software for obfuscation.

Specifically, MuddyWater has been linked to the Tsundere Botnet (also known as DinDoor) and the Castle Loader (FakeSet) malware families. The apply of code-signing certificates under the Common Names “Amy Cherne” and “Donald Gay” across MuddyWater malware, Tsundere Deno malware, and CastleLoader variants suggests a common source for these certificates, though it doesn’t necessarily indicate a direct affiliate relationship.

Qilin Ransomware and Strategic Objectives

In October 2025, the Shamir Medical Center in Israel was targeted in a cyberattack initially attributed to the Qilin ransomware group. However, subsequent assessments pointed to Iranian actors leveraging the Qilin ransomware-as-a-service (RaaS) operation to achieve strategic objectives. This suggests that Iranian-affiliated operators are utilizing criminal ransomware brands and methods to mask their activities and potentially circumvent heightened security measures.

This attack is part of a broader campaign by MOIS and Hezbollah targeting Israeli hospitals, a pattern evident since late 2023.

Conclusion

The examined cases demonstrate a clear shift in Iranian cyber activity. For some actors, cybercrime is no longer simply a cover for state-directed operations but an operational resource. Engagement with criminal tools and services enhances capabilities while complicating attribution. This trend highlights the increasing convergence between state-sponsored cyber activity and the cybercrime ecosystem.

Indicators of Compromise

  • Handala Rhadmanthys Variants: aae017e7a36e016655c91bd01b4f3c46309bbe540733f82cce29392e72e9bd1f
  • Malware samples signed with suspicious certificates:
sha256 Certificate Common Name Certificate Thumbprint Certificate Serial Number Malware Family
077ab28d66abdafad9f5411e18d26e87fe43da1410ee8fe846bd721ab0cb52de Amy Cherne 0902d7915a19975817ec1ccb0f2f6714aed19638 330007f1068f41bf0f662a03b500000007f106 FakeSet / CastleLoader
ddceade244c636435f2444cd4c4d3dc161981f3af1f622c03442747ecef50888 Amy Cherne 0902d7915a19975817ec1ccb0f2f6714aed19638 330007f1068f41bf0f662a03b500000007f106 FakeSet / CastleLoader
2b7d8a519f44d3105e9fde2770c75efb933994c658855dca7d48c8b4897f81e6 Amy Cherne 2087bb914327e937ea6e77fe6c832576338c2af8 330006df515a14fe3748416fe200000006df51 FakeSet / CastleLoader
64cf334716f15da1db7981fad6c81a640d94aa1d65391ef879f4b7b6edf6e7f1 Amy Cherne 21a435ecaa7b86efbec7f6fb61fcda3da686125c 330006e75231f49437ae56778a00000006e752 FakeSet / CastleLoader
74db1f653da6de134bdc526412a517a30b6856de9c3e5d0c742cb5fe9959ad0d Amy Cherne 389b12da259a23fa4559eb1d97198120f2a722fe 330007d5443a7d25208ec5feb100000007d544 FakeSet / CastleLoader
94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444 Amy Cherne 389b12da259a23fa4559eb1d97198120f2a722fe 330007d5443a7d25208ec5feb100000007d544 FakeSet / CastleLoader
4aef998e3b3f6ca21c78ed71732c9d2bdcc8a4e0284f51d7462c79d446fbc7be Amy Cherne 551bdf646df8e9abe04483882650a8ffae43cb55 330006e15e43401dbd9416e20e00000006e15e FakeSet / CastleLoader
a4bd1371fe644d7e6898045cc8e7b5e1562bdfd0e4871d46034e29a22dec6377 Amy Cherne d920ae0f8ea8b5bd42de49e01c6bbd4c2c6d0847 330007ebfbe75a64b52aaf4cb700000007ebfb FakeSet / CastleLoader
64263640a6fdeb2388bca2e9094a17065308cf8dcb0032454c0a71d9b78327eb Donald Gay f8444dfc740b94227ab9b2e757b8f8f1fa49362a 3300072b29c3bf8403a6c15be2000000072b29 FakeSet / CastleLoader
a8c380b57cb7c381ca6ba845bd7af7333f52ee4dc4e935e98b48bb81facad72b Donald Gay 9dcb994ea2b8e6169b76a524fae7b2d2dcd1807d 33000725fea86dd19e8571b26c0000000725fe FakeSet / CastleLoader
24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14 Donald Gay b674578d4bdb24cd58bf2dc884eaa658b7aa250c 3300079a51c7063e66053d229b000000079a51 StageComp
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0 Donald Gay b674578d4bdb24cd58bf2dc884eaa658b7aa250c 3300079a51c7063e66053d229b000000079a51 StageComp
2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5 Amy Cherne 551bdf646df8e9abe04483882650a8ffae43cb55 330006e15e43401dbd9416e20e00000006e15e DinDoor / Tsundere Deno

Related Posts

Leave a Comment