Researchers Link MOIS To Coordinated Hacker Persona Operation

Security researchers have linked Iran’s Ministry of Intelligence and Security (MOIS) to a long-running, multi-persona cyber operation in which the threat actor groups Homeland Justice, Karma, and Handala are assessed not as independent hacktivist entities but as coordinated operational fronts of a single state-directed capability.

The assessment, supported by U.S. government reporting, private-sector threat intelligence, passive DNS analysis, and longitudinal review of archived web and Telegram content, concludes with high confidence that these three personas form a unified, MOIS-aligned cyber influence ecosystem.

Each brand serves distinct but complementary roles disruption, espionage, leak operations, and psychological coercion while drawing from a shared pool of infrastructure, tooling, and tradecraft.

At the structural center of this assessment is the reported involvement of Seyed Yahya Hosseini Panjaki, an individual assessed to be affiliated with MOIS and linked to its internal security and counter-terrorism apparatus.

His presence signals not a freelance contractor arrangement, but a command-level function within an institutional hierarchy, placing these operations firmly within the formal tasking and strategic alignment of the Iranian state intelligence mandate.

MOIS Runs Fake Personas (Source: domaintools)
MOIS Runs Fake Personas (Source: domaintools)

Three Faces, One Machine

Homeland Justice emerged publicly in 2022 during attacks against Albanian government infrastructure, where Iranian actors exploited a Microsoft SharePoint vulnerability and maintained covert access for approximately 14 months before executing a coordinated destructive phase.

The actors deployed ransomware-style encryption alongside disk wipers, including GoXML.exe and cl.exe, followed by immediate public attribution through controlled Telegram channels and websites establishing a repeatable hack-and-leak operational model that has defined all subsequent phases.

MOIS Runs Fake Personas (Source: domaintools)
MOIS Runs Fake Personas (Source: domaintools)

As the operation evolved, the Karma and KarmaBelow80 personas emerged following the October 2023 Israel-Hamas conflict, with campaigns pivoting toward Israeli organizations using the BiBi Wiper on both Windows and Linux platforms.

The Handala persona then rose to prominence from 2024 onward, representing the most psychologically sophisticated layer of the ecosystem one focused on curated data leaks, narrative shaping, and targeted intimidation of intelligence officials, dissidents, and journalists across borders.

MOIS Runs Fake Personas (Source: domaintools)
MOIS Runs Fake Personas (Source: domaintools)

Escalation to Enterprise-Level Destruction

The campaign’s most significant recent evolution was observed in the March 2026 Stryker Corporation incident, where Handala-linked actors reportedly compromised Microsoft Intune a cloud-based enterprise device management platform and used it to remotely wipe an estimated 80,000 to 200,000 devices across globally distributed infrastructure.

Approximately 50 terabytes of data were exfiltrated before the destructive action, and recovery took multiple days.

This technique domain tools marked a fundamental shift in tradecraft rather than deploying malware at the endpoint level, actors targeted the enterprise control plane itself, effectively weaponizing the organization’s own administrative authority.

The abuse of Intune eliminated the need for detectable malware artifacts, enabled near-simultaneous disruption across dozens of countries, and compressed the timeline from exfiltration to public attribution all core objectives of the MOIS-aligned hack-and-leak doctrine.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories