Iranian MOIS Actors & the Cyber Crime Connection

2026-03-10T20:52:31Zc7a5fe19e4e49189415613812649fcd7dc9cefd9dfa81f8f97130ea46e81c736
AI-as-C2APT41Amaranth-DragonAnthropicCVE-2025-59536CVE-2025-8088CVE-2026-21852Claude CodeEuropeIoT-cameraIranMOISSilver DragonSoutheast Asiacybercrimedata-breacheScanespionagenation-stateransomwaresupply-chain

What happened

This Check Point Research feed covers multiple high-impact intelligence items from early 2026: Iranian MOIS-linked actors increasingly collaborate with the cybercrime ecosystem, using criminal tools and services as cover for destructive and espionage activity. Check Point tracks several state-aligned clusters—Silver Dragon (Chinese-aligned, operationally related to APT41) targeting governments in Southeast Asia and Europe, and Amaranth‑Dragon which weaponized CVE-2025-8088 for targeted espionage. Critical vulnerabilities in Anthropic’s Claude Code (CVE-2025-59536, CVE-2026-21852) enable remote

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
c7a5fe19e4e49189415613812649fcd7dc9cefd9dfa81f8f97130ea46e81c736
Enrichment time
2026-03-10T20:52:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iranian MOIS Actors & the Cyber Crime Connection · Baitaphish