MOISIRAN is a Telegram-based operational persona assessed to be part of an Iran-linked Ministry of Intelligence (MOIS) threat cluster associated with the broader Handala brand and the actor commonly tracked as Void Manticore, also known as TAG-145, Red Sandstorm, and Banished Kitten. The persona emerged in April 2026 and has been used to claim surveillance of Israeli military, intelligence, law-enforcement, and nuclear-related personnel. It fits a wider MOIS pattern of using reusable personas that present as independent activist or resistance entities while supporting coordinated cyber, espionage, influence, intimidation, and proxy-enablement activity. MOISIRAN appears to function primarily as a surveillance, intimidation, and amplification persona rather than as a standalone malware brand. Its activity is consistent with reconnaissance and espionage-oriented operations focused on identifying, monitoring, and psychologically pressuring Israeli targets. Reporting links MOISIRAN to coordination with VIPEmployment-linked channels and assesses that it operates under the same MOIS-controlled Handala ecosystem that also includes Handala Hack Team, Handala Popular Resistance Front, and Brave Israel. Within that ecosystem, associated personas have supported hack-and-leak operations, destructive attacks, recruitment of proxies for espionage and sabotage, and claims of physical attacks, indicating a multidomain operational model in which cyber and non-cyber activities reinforce one another. The broader cluster has historically targeted Israel, Iranian opposition figures, and, increasingly, the United States. In MOISIRAN’s case, the directly observed focus is Israel, especially intelligence, security, and state-linked individuals. The dominant motivation is espionage in service of Iranian state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.