• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Doctor Charged For Selling Ransomware Used By Iranian Hackers

May 17, 2022, 13:11 GMT+1
The user interface of the Thanos software, a private ransomware builder used by an Iranian state-sponsored hacking group to attack Israeli companies
The user interface of the Thanos software, a private ransomware builder used by an Iranian state-sponsored hacking group to attack Israeli companies

A French-Venezuelan cardiologist has been accused by the US of selling ransomware to cybercriminals, including malicious actors associated with the government of Iran.

The Brooklyn district attorney's office said Monday that Moises Luis Zagala, 55, not only created and sold ransomware products to hackers, but also trained them on how to extort victims, and then boasted about successful attacks by an Iranian state-sponsored hacking group.

In early 2019, Zagala began advertising his new tool on the web as a "Private Ransomware Builder" which he named "Thanos" after the Marvel Comics villain responsible for destroying the half of life in the universe, as well as Thanatos, the personification of death in Greek mythology.

Zagala publicly bragged about a news story about an Iranian state-sponsored hacking group’s use of Thanos to commit ransomware attacks on Israeli companies.

The Islamic Republic is very active in various malign cyber activities and is also providing cyber technology to its proxies, including the Lebanese Hezbollah, to build their own cyber units.

The National Interest reported in mid-April that Iran has helped Hezbollah become “the most sophisticated and influential Middle Eastern terrorist organization in cyberspace after the collapse of the Islamic State caliphate”.

Earlier in April, Meta, formerly the Facebook company, removed two Iranian cyberespionage groups that were targeting academics, activists, journalists and other victims to collect intelligence, manipulate them into revealing information, and compromise their devices and accounts.

The groups, possibly sponsored by Revolutionary Guard (IRGC), targeted Iranian diaspora, dissidents and human rights activists from Israel and Iran, Iran-focused academics, politicians in the US, people in the Middle East including the Saudi military, and journalists around the world.

Banner

Most Viewed

Iran sets seven terms for renewed US talks, says ready for escalation
1

Iran sets seven terms for renewed US talks, says ready for escalation

2
ANALYSIS

Will shutdowns forced by US blockade damage Iran’s oil wells?

3

Trump weighs Iran options; Tehran signals Hormuz leverage

4

Iran mobilisation drive extends to children under 15

5

Iran threatens regional strikes as MPs question nuclear policy

Banner

Spotlight

  • Will shutdowns forced by US blockade damage Iran’s oil wells?
    ANALYSIS

    Will shutdowns forced by US blockade damage Iran’s oil wells?

  • Tehran ‘ashamed’ as Iranians struggle to make ends meet

    Tehran ‘ashamed’ as Iranians struggle to make ends meet

  • Iran faces postwar winter with a third of gas capacity lost
    ANALYSIS

    Iran faces postwar winter with a third of gas capacity lost

  • Iran’s nightly pro-state rallies become factional battleground
    INSIGHT

    Iran’s nightly pro-state rallies become factional battleground

  • Woman, Life, Freedom and the Iran that cannot go back
    OPINION

    Woman, Life, Freedom and the Iran that cannot go back

  • From Halkbank to Golden Global: Turkey’s Iran banking ties under US scrutiny

    From Halkbank to Golden Global: Turkey’s Iran banking ties under US scrutiny

Banner
Banner