CSIDB logo
Threat actor

MOIS

Attribution profile

Type
Nation State
Location
Iran
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-08-01 04:40
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor identified as MOIS, also referred to as the Ministry of Intelligence and Security, operates from Iran. A March 2019 news report stated that Iranian intelligence compromised the personal cellphone of Benny Gantz, former Israeli defense chief and political rival, during the lead‑up to a national election. Israeli Shin Bet officials notified Gantz approximately five weeks before the vote that his device had been breached and that the attackers possessed the contents of his phone. The officials explained that the accessed data included both personal and professional information, indicating an espionage motive behind the intrusion. They further warned that the harvested material could be used to influence the election process or to disclose sensitive details after voting, pointing to a possible disruption objective. These assertions were consistent with earlier statements from the Shin Bet chief and Israel’s National Cyber Directorate, which had warned of foreign cyber interference aimed at affecting election outcomes.

The available reporting does not describe any specific malware families, exploit tools, or initial access vectors employed in the Gantz phone compromise. Attribution to MOIS is based on the explicit identification of the perpetrators as Iranian intelligence in the news article and the subsequent confirmation from Gantz’s political party. The incident is cited as a concrete example of MOIS using cyber capabilities to collect intelligence on a high‑profile individual during a politically sensitive period. No additional victim sectors, infrastructure details, or repeat tactics are disclosed in the source material, so the profile remains confined to this single publicly documented operation.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB