MOIS
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor identified as MOIS, also referred to as the Ministry of Intelligence and Security, operates from Iran. A March 2019 news report stated that Iranian intelligence compromised the personal cellphone of Benny Gantz, former Israeli defense chief and political rival, during the lead‑up to a national election. Israeli Shin Bet officials notified Gantz approximately five weeks before the vote that his device had been breached and that the attackers possessed the contents of his phone. The officials explained that the accessed data included both personal and professional information, indicating an espionage motive behind the intrusion. They further warned that the harvested material could be used to influence the election process or to disclose sensitive details after voting, pointing to a possible disruption objective. These assertions were consistent with earlier statements from the Shin Bet chief and Israel’s National Cyber Directorate, which had warned of foreign cyber interference aimed at affecting election outcomes.
The available reporting does not describe any specific malware families, exploit tools, or initial access vectors employed in the Gantz phone compromise. Attribution to MOIS is based on the explicit identification of the perpetrators as Iranian intelligence in the news article and the subsequent confirmation from Gantz’s political party. The incident is cited as a concrete example of MOIS using cyber capabilities to collect intelligence on a high‑profile individual during a politically sensitive period. No additional victim sectors, infrastructure details, or repeat tactics are disclosed in the source material, so the profile remains confined to this single publicly documented operation.
Incidents
Attributed incidents are available to members.
0 incidents