Iran-linked cyber activity during the conflict period is characterized by access optionality rather than dramatic disruption. Multiple state-aligned entities (MOIS, IRGC Intelligence Organization, IRGC Cyber-Electronic Command) and persona operations pursue distinct missions including persistent espionage, destructive coercion, high-trust social engineering, dissident surveillance, and opportunistic OT targeting. The principal strategic risk is that compromised accounts, service providers, and remote-management footholds can be repurposed from collection to disruption as tasking changes. OT risk remains exposure-driven, with internet-facing PLCs and weak credentials enabling real but uneven disruption. Inside Iran, shared-service concentration and connectivity controls create cascading operational risk and analytic uncertainty.
MOIS
4 posts
Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters - 7 minWeekly Recap — 2026-06-01 -> 2026-06-08
Trojanized Build Pipelines and Blind-Spot Appliances Redefine the Perimeter Attackers are bypassing traditional network defenses by compromising the tools developers use to build software and the AI assistants they rely on to write code. Campaigns like Mini Shai-Hulud and Miasma - The Spreading Blight flooded package registries with malicious code that steals cloud credentials and CI/CD tokens, while researchers proved that public AI agent skill marketplaces are completely ineffective at catching malicious add-ons. Nation-state actors and cybercriminals are simultaneously shifting their focus to blind spots in corporate networks and trusted platforms. The VerdantBamboo group exploited firewalls to bypass conditional access, while UNC3753 used IT impersonation to trick law firm employees into installing remote access tools, and Kali365 expanded its phishing infrastructure to steal multi-factor authentication tokens. Defenders must shift their focus from perimeter email filtering to securing the software build pipeline and monitoring edge appliances for anomalous traffic. Hunt for unexpected connections to cloud storage APIs and review developer environments for compromised packages or AI skills.
Iran Expands Handala Brand to Physical Threats Iran's Ministry of Intelligence (MOIS) has expanded its 'Handala' operational brand to encompass physical threats and influence operations alongside its established cyber hacktivism. By coordinating personas like Handala Hack Team, HPRF, and VIPEmployment, MOIS leverages global brand recognition to solicit proxies via Telegram for espionage, sabotage, and physical attacks against US and Israeli interests. This multidomain approach combines cyber intrusions with real-world intimidation tactics.
Iranian MOIS Actors & the Cyber Crime Connection Iranian Ministry of Intelligence and Security (MOIS) affiliated threat actors, including Void Manticore and MuddyWater, are increasingly integrating cybercriminal tools, infrastructure, and affiliate models into their operations. This strategic shift, which includes the use of commercial infostealers like Rhadamanthys and RaaS platforms like Qilin, enhances their operational capabilities while complicating attribution efforts.