• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Doctor Charged For Selling Ransomware Used By Iranian Hackers

May 17, 2022, 13:11 GMT+1
The user interface of the Thanos software, a private ransomware builder used by an Iranian state-sponsored hacking group to attack Israeli companies
The user interface of the Thanos software, a private ransomware builder used by an Iranian state-sponsored hacking group to attack Israeli companies

A French-Venezuelan cardiologist has been accused by the US of selling ransomware to cybercriminals, including malicious actors associated with the government of Iran.

The Brooklyn district attorney's office said Monday that Moises Luis Zagala, 55, not only created and sold ransomware products to hackers, but also trained them on how to extort victims, and then boasted about successful attacks by an Iranian state-sponsored hacking group.

In early 2019, Zagala began advertising his new tool on the web as a "Private Ransomware Builder" which he named "Thanos" after the Marvel Comics villain responsible for destroying the half of life in the universe, as well as Thanatos, the personification of death in Greek mythology.

Zagala publicly bragged about a news story about an Iranian state-sponsored hacking group’s use of Thanos to commit ransomware attacks on Israeli companies.

The Islamic Republic is very active in various malign cyber activities and is also providing cyber technology to its proxies, including the Lebanese Hezbollah, to build their own cyber units.

The National Interest reported in mid-April that Iran has helped Hezbollah become “the most sophisticated and influential Middle Eastern terrorist organization in cyberspace after the collapse of the Islamic State caliphate”.

Earlier in April, Meta, formerly the Facebook company, removed two Iranian cyberespionage groups that were targeting academics, activists, journalists and other victims to collect intelligence, manipulate them into revealing information, and compromise their devices and accounts.

The groups, possibly sponsored by Revolutionary Guard (IRGC), targeted Iranian diaspora, dissidents and human rights activists from Israel and Iran, Iran-focused academics, politicians in the US, people in the Middle East including the Saudi military, and journalists around the world.

Most Viewed

London penthouses linked to Iran’s Supreme Leader put up for sale – Sunday Times
1

London penthouses linked to Iran’s Supreme Leader put up for sale – Sunday Times

2

Iran has only 30 million barrels of oil left for China, Bessent says

3
ANALYSIS

Starlink next door could loosen Iran’s grip on internet

4

Iran doubles gasoline price amid fears of renewed unrest

5
PODCAST

Iran, where eggs are a better bet than cash

Banner
Banner
Banner

Spotlight

  • Europe’s third-way ambitions on Iran give way to alignment with Washington
    ANALYSIS

    Europe’s third-way ambitions on Iran give way to alignment with Washington

  • The gamble behind US attacks on Iran’s oil tankers
    ANALYSIS

    The gamble behind US attacks on Iran’s oil tankers

  • Iran, where eggs are a better bet than cash
    PODCAST

    Iran, where eggs are a better bet than cash

  • Starlink next door could loosen Iran’s grip on internet
    ANALYSIS

    Starlink next door could loosen Iran’s grip on internet

  • Satellite images show Iran’s key ports falling quiet under US blockade
    EXCLUSIVE

    Satellite images show Iran’s key ports falling quiet under US blockade

  • Iran's appliance industry is collapsing, and so is the market it was built for
    INSIGHT

    Iran's appliance industry is collapsing, and so is the market it was built for