{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreif7iib2vqexcbn5uuqvnurxetg7xwzmb55jekmwh2lgxv3zchr4bu",
"uri": "at://did:plc:tsmoh4imc7gdynr5nxbonvxz/app.bsky.feed.post/3mgy3fxjawmw2"
},
"path": "/posts/threat-actor-profile-handala/",
"publishedAt": "2026-03-13T08:30:32.000Z",
"site": "https://cstromblad.com",
"tags": [
"Unit 42 — Handala Hack Wiper Attacks",
"Check Point Research — Handala Hack: Unveiling the Group’s Modus Operandi",
"Flashpoint — Destructive Activity Targeting Stryker Highlights Emerging Supply Chain Risks",
"Check Point Research — Iranian MOIS Actors: The Cyber Crime Connection",
"SentinelOne — LABScon25: Hacktivism and War",
"Rapid7 — Iran Cyber Playbook: Escalating Regional Conflict",
"KrebsOnSecurity — Iran-Backed Hackers Claim Wiper Attack on MedTech Firm Stryker",
"Flare — Cyberattacks in the US-Israel-Iran Military Conflict",
"Sophos — Hacktivist Campaigns Increase as US-Iran-Israel Conflict Intensifies",
"CloudSEK — Threat Actor Landscape Assessment of ICS/OT Targeting",
"VECert — OSINT Kitten: The Headquarters for Hacktivist Operations Against Israel",
"Security.com — Iran Cyber Threat Activity Against the US",
"Acronis TRU — Mobile Spyware Campaign Impersonates Israel’s Red Alert System"
],
"textContent": "## Identity, Attribution, and Aliases\n\nThe threat actor publicly known as **Handala Hack** (or Handala Hack Team) is assessed with high confidence by multiple cybersecurity firms and government entities to be a **state-directed front for Iran ’s Ministry of Intelligence and Security (MOIS)**.1 2 3 The group operates under several tracked designations:\n\nAlias | Tracked By\n---|---\nVoid Manticore | Check Point Research\nCOBALT MYSTIQUE | Secureworks (CTU)\nStorm-1084 / Storm-0842 | Microsoft\nHandala Hack / Handala Hack Team | Self-designated public persona\n\nBeyond its primary Handala persona, the group has operated under at least two additional personas: **Homeland Justice** (used in operations targeting Albania) and **Karma**.2 This multi-persona model is consistent with a broader Iranian MOIS pattern of using hacktivist fronts to provide plausible deniability for state-directed destructive operations.4 5\n\nSentinelLabs categorises Handala as an example of “**fictivism** ” — state-sponsored proxy operations masquerading as grassroots activism — exhibiting hallmarks of top-tier state-front actors including multi-year consistent messaging, rejection of financial motivation, advanced prepositioning capabilities, and professionally crafted communications.5\n\nIsrael’s **National Cyber Directorate** has formally warned of Handala’s attacks.1\n\n> **Intelligence gap:** The precise organisational relationship between Handala and other MOIS-linked groups such as MuddyWater (Seedworm) remains partially unclear. Check Point has documented shared code-signing certificate infrastructure between Void Manticore and MuddyWater, but notes this may reflect a common procurement source rather than a direct operational merger.4\n\n* * *\n\n## Victimology\n\n### Geographic Targeting\n\nHandala’s targeting has expanded over time:\n\nPriority | Region | Evidence\n---|---|---\nPrimary | **Israel** | Sustained campaigns against government, healthcare, IT, and critical infrastructure sectors1 2 6\nSecondary | **United States** | Recent expansion to US enterprises, including medical technology and critical infrastructure1 3 7\nSecondary | **Albania** | Operations conducted under the Homeland Justice persona2\nTertiary | **UAE, Saudi Arabia, Gulf States** | Claimed exfiltration from oil and gas sector networks6\n\n### Sector Targeting\n\nHandala has demonstrated a strong focus on **critical infrastructure and healthcare supply chains** :\n\n * **Medical technology:** The Stryker attack (March 2026) represents the most high-profile incident, with the group claiming disruption across 79 countries and over 200,000 devices wiped.3 7\n * **Healthcare:** Alleged involvement in the attack on Israel’s Shamir Medical Center using Qilin ransomware-as-a-service branding.4 Separate claims of data theft from Israel’s Clalit healthcare network.8\n * **Oil and gas:** Claims of exfiltrating over 1.3 TB of data from UAE and Israeli oil and gas networks.6 Separate claims of infiltrating a Saudi energy company.6\n * **IT and service providers:** Consistent targeting of IT and managed service providers as a supply chain access vector to reach downstream victims.2 7\n\n\n\n> **Analytical note:** Many of Handala’s data theft claims are self-reported via Telegram and have not been independently verified. Distinction between confirmed intrusions and unverified claims should be maintained.6 9\n\n* * *\n\n## Tactics, Techniques, and Procedures (TTPs)\n\n### Initial Access\n\nHandala employs multiple initial access vectors:\n\n * **Phishing (T1566):** The primary vector for recent destructive operations, used to obtain legitimate user credentials.1 The group has deployed phishing lures impersonating F5 updates to deliver both the Rhadamanthys infostealer and custom wipers.4\n * **Compromised VPN access (T1133):** Brute-force and credential-based VPN access frequently originating from commercial VPN nodes (169.150.227.X, 149.88.26.X) and Starlink IP ranges (188.92.255.X, 209.198.131.X).2\n * **Brute-force attacks (T1110):** Hundreds of logon and brute-force attempts against organisational VPN infrastructure have been linked to Handala-associated infrastructure.2\n * **Supply chain compromise (T1199):** Consistent targeting of IT and service providers to obtain credentials and access to downstream victims.2 7\n * **Valid accounts (T1078):** Use of stolen or supplied credentials, including Domain Admin credentials, for network entry.2\n\n\n\n### Credential Access and Discovery\n\nPost-initial access, the group engages in systematic credential harvesting and network enumeration:\n\n * **LSASS dumping (T1003.001):** Dumping the LSASS process using `comsvcs.dll` via `rundll32.exe`.2\n * **Registry hive export (T1003.002):** Exporting sensitive registry hives (HKLM SAM/SYSTEM) for offline credential extraction.2\n * **Active Directory enumeration (T1087.002):** Execution of ADRecon (named `dra.ps1`), a PowerShell-based reconnaissance framework for enumerating AD environments.2\n * **Disabling defences (T1562.001):** Disabling Windows Defender protections prior to credential theft and wiper deployment.2\n\n\n\n### Lateral Movement\n\nHandala operates in a **manual, hands-on manner** :\n\n * **RDP (T1021.001):** Lateral movement conducted primarily through extensive use of Remote Desktop Protocol.2\n * **NetBird (T1572):** Deployment of NetBird, a zero-trust mesh networking platform, to reach hosts not directly accessible from outside the network. The software is downloaded directly from the official NetBird website via local browsers on compromised hosts.2\n * **WMI (T1047):** Use of `wmic.exe` for remote process creation and file operations across Active Directory hosts.2\n\n\n\n### Destructive Payloads (Impact)\n\nThe group’s primary objective is **destructive disruption** rather than financial gain. Multiple wiper mechanisms have been documented:\n\nPayload | Description | Distribution Method\n---|---|---\n**Handala Wiper** (MD5: `5986ab04dd6b3d259935249741d3eff2`) | Custom binary performing MBR and file overwriting2 | GPO logon scripts, batch file (`handala.bat`), scheduled tasks2\n**PowerShell wiper** (MD5: `3cb9dea916432ffb8784ac36d1f2d3cd`) | AI-assisted PowerShell script deleting user directories and dropping propaganda images2 | Deployed as final-stage destructive payload2\n**VeraCrypt encryption** | Legitimate encryption tool abused to encrypt system drives as an additional destructive layer2 | Manual deployment2\n**Microsoft Intune abuse (T1651)** | Mass remote wipe/factory reset commands issued via legitimate MDM infrastructure1 3 7 | Abuse of compromised administrative Intune access1 3\n**AutoIT/NSIS wiper** | AutoIT-based wiper packaged with NSIS installer, with Telegram C210 | Vendor-impersonation phishing10\n**Manual VM/file deletion** | Direct deletion of virtual machines and files2 | Manual operator activity2\n\nWipers are distributed across networks via **Group Policy Objects (T1484.001)** , using GPO logon scripts and scheduled tasks to maximise reach.2\n\n#### Microsoft Intune Abuse — A Notable TTP Evolution\n\nThe abuse of Microsoft Intune represents a significant evolution in Handala’s destructive capabilities. Because Intune is a **trusted native administrative tool** , mass remote wipe commands do not trigger traditional EDR or antivirus detections — a Living off the Land (LotL) approach that bypasses conventional security controls entirely.3 This was notably observed in the Stryker incident, where no evidence of conventional malware was identified despite massive operational disruption.3 7 Employees with Microsoft Outlook installed on personal (BYOD) devices also reportedly had those devices wiped, indicating exploitation of Intune’s BYOD enrollment scope.7\n\n### Additional Tooling\n\n * **Rhadamanthys infostealer:** A commercial infostealer deployed alongside custom wipers in phishing campaigns targeting Israeli entities, primarily via F5-themed lures.4\n * **Hack-and-leak operations:** The group routinely combines destructive attacks with data exfiltration and selective public release of stolen information for psychological impact.2 6\n * **Website defacement (T1491):** Login pages and web interfaces defaced with the Handala logo during intrusions.7\n * **RedWanted doxxing platform:** Launched on 1 March 2026, listing names and summaries of individuals and organisations who have supported Israel.9\n\n\n\n* * *\n\n## Infrastructure Analysis and Operational Security\n\n### Command and Control Infrastructure\n\nDocumented C2 infrastructure includes VPS nodes at:\n\n * `107.189.19[.]52`\n * `82.25.35[.]25`\n * `31.57.35[.]223`2\n\n\n\nThe group’s wiper variants have used **Telegram** as a C2 channel.10\n\n### Access Infrastructure\n\nHandala’s operational access infrastructure reveals a blend of commercial and unconventional sources:\n\n * **Commercial VPN nodes:** IP ranges 169.150.227.X, 149.88.26.X2\n * **Starlink connections:** IP ranges 188.92.255.X, 209.198.131.X — used to evade geolocation-based blocking2 10\n\n\n\n### Declining Operational Security\n\nCheck Point reports that Handala has exhibited **declining operational security** , resulting in the exposure of Iranian IP addresses and Starlink connections linking back to Iranian operators.2 This erosion of OPSEC has aided attribution efforts.\n\n### Coordination Infrastructure\n\nHandala has been identified as a participant in **“ The Kitten”**, an Iranian-linked hacktivist coordination hub facilitating operations against Israeli infrastructure. The platform connects multiple pro-Iranian groups and was traced to `zagrosguard.ir`, an Iranian cybersecurity network operating through Turkish phone numbers and Telegram channels, hosted on Iranian IP addresses (46.38.147[.]116, 185.164.72[.]226).11\n\nFollowing the February 2026 military strikes, a broader coordination body called the **“ Electronic Operations Room of Islamic Resistance Axis”** was established to synchronise operations across multiple Iranian-aligned hacktivist personas, including Handala.8 9\n\n* * *\n\n## Documented Campaigns and Incidents\n\n### Stryker Medical Technology Attack (March 2026)\n\nThe most significant publicly documented Handala incident to date. Key details:\n\n * **Target:** Stryker Corporation, a global medical technology company\n * **Claimed impact:** Data erased from over 200,000 systems, servers, and mobile devices across 79 countries; 5,000+ workers in Ireland sent home; building emergency notice issued at US headquarters7\n * **Attack vector:** Abuse of Microsoft Intune to issue mass remote wipe commands against all enrolled devices3 7\n * **Additional activity:** Website defacement of device login pages with Handala logo; claims of data exfiltration prior to wiping7\n * **Framing:** Publicly framed as retaliation for a US missile strike on an Iranian school7\n * **Stryker disclosure:** Company confirmed no evidence of ransomware or conventional malware3\n\n\n\n> **Analytical note:** Handala’s claim of 200,000 devices wiped has not been independently verified. Stryker confirmed disruption but the full scope remains under investigation.3 7\n\n### Israeli Organisation Wiper Campaigns (Ongoing)\n\nUnit 42 tracks a sustained surge in destructive wiper attacks against Israeli organisations, with attackers gaining access to corporate networks and deleting servers and workstations to disrupt operations.1 Israel’s National Cyber Directorate has formally warned of these attacks.1\n\n### Albanian Operations (Homeland Justice Persona)\n\nUnder the Homeland Justice persona, the group has conducted destructive operations against Albanian targets, consistent with the broader MOIS campaign against Albania following the country’s hosting of the Iranian opposition group MEK.2\n\n### Shamir Medical Center (October 2025)\n\nCheck Point assesses that Iranian operators appear to have used the **Qilin ransomware-as-a-service** affiliate model to conduct a strategically motivated attack on Israel’s Shamir Medical Center under criminal cover. While initially described as a ransomware incident, the operational intent was assessed as strategic disruption rather than financial extortion.4\n\n### Oil and Gas Sector Claims\n\nHandala has claimed exfiltration of over 1.3 TB of sensitive data from oil and gas sector networks in the UAE and Israel, as well as infiltration of a Saudi energy company.6 These claims remain **unverified by independent sources**.6\n\n### US Targeting Expansion\n\nUnit 42 notes that Handala’s destructive operations have expanded to include US organisations, consistent with broader Iranian escalation following the February 2026 military strikes.1\n\n* * *\n\n## Relationship to the Broader Iranian Cyber Ecosystem\n\nHandala operates within a layered Iranian MOIS cyber ecosystem that includes:\n\n * **MuddyWater (Seedworm):** Shared code-signing certificate infrastructure (Common Names “Amy Cherne” and “Donald Gay”) links Void Manticore and MuddyWater through overlapping malware tooling (FakeSet/CastleLoader, StageComp, DinDoor).4 MuddyWater has been observed conducting concurrent intrusion operations against US organisations.12\n * **Criminal ecosystem integration:** The group has adopted cybercriminal tools and models, including the Rhadamanthys infostealer and Qilin RaaS affiliate program, to obscure attribution and enhance capabilities.4\n * **Hacktivist coordination:** Handala participates in Iranian-directed coordination structures including “The Kitten” platform and the “Electronic Operations Room of Islamic Resistance Axis.”11 8 9\n\n\n\n* * *\n\n## Leadership Disruption\n\nCheck Point reports that the group’s **leadership nexus was reportedly disrupted following Israeli strikes in early 2026**.2 The operational impact of this disruption remains unclear, as the group has continued to claim and conduct operations in subsequent weeks.\n\n* * *\n\n## Key Intelligence Gaps\n\n 1. **Unverified claims:** Many of Handala’s data exfiltration claims (oil and gas, healthcare) are self-reported and unverified.\n 2. **Operational relationship with MuddyWater:** Whether shared certificate infrastructure indicates operational coordination, shared procurement, or a more integrated relationship is not fully established.4\n 3. **Leadership disruption impact:** The degree to which Israeli strikes have degraded the group’s capability versus merely disrupting leadership is uncertain.2\n 4. **Intune access vector:** The precise method by which Handala obtains administrative access to victim Intune tenants (direct phishing of admins vs. privilege escalation vs. supply chain compromise) is not fully documented across incidents.\n 5. **Attribution of the Red Alert mobile spyware campaign:** One source tags Handala/MOIS in connection with a trojanised Red Alert Android app, though the primary attribution points to Arid Viper (APT-C-23).13 The relationship, if any, between these actors in this campaign is unclear.\n\n\n\n## MITRE ATT&CK Summary\n\nThe following table summarises the most confidently attributed techniques based on documented intrusion reporting specific to Handala / Void Manticore. Each entry includes a supporting evidence sentence attributed to its source.\n\n### Initial Access\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1566 | Phishing | “The primary vector for recent destructive operations from the Handala Hack group reportedly involves the exploitation of identity through phishing and administrative access through Microsoft Intune.” | 1\nT1566 | Phishing | “Handala used Rhadamanthys on several occasions, pairing it with one of its custom wipers in phishing lures aimed at Israeli targets, most dominantly impersonating F5 updates.” | 4\nT1133 | External Remote Services | “Use of compromised VPN access for entry into victim environments.” | 2\nT1078 | Valid Accounts | “In some cases, the attacker had access data from legitimate corporate users, which was used to gain initial access to the network.” | 1\nT1078.002 | Valid Accounts: Domain Accounts | “Use of stolen/supplied credentials, including Domain Admin credentials.” | 2\nT1110 | Brute Force | “Throughout the last months, we identified hundreds of logon and brute-force attempts against organizational VPN infrastructure linked to Handala-associated infrastructure.” | 2\nT1199 | Trusted Relationship | “Handala has consistently targeted IT and service providers in an effort to obtain credentials.” | 2\n\n### Execution\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1651 | Cloud Administration Command | “Flashpoint analysts are reviewing indications that attackers may have leveraged enterprise device management infrastructure, including Microsoft Intune, to trigger wiping actions across managed devices.” | 3\nT1059.001 | Command and Scripting Interpreter: PowerShell | “As a final stage of the destructive operation, the attackers deployed an additional custom PowerShell-based wiper.” | 2\nT1047 | Windows Management Instrumentation | “`wmic.exe /node:<active directory hostname> /user:<redacted> /password:<redacted> process call create 'cmd.exe /c copy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1\\windows\\system32\\config\\system c:\\users\\public'`” | 2\nT1037.003 | Boot or Logon Initialization Scripts: Network Logon Script | “The wiper was distributed across the network as a scheduled task using Group Policy logon scripts, which executed a batch file named handala.bat.” | 2\nT1053.005 | Scheduled Task/Job: Scheduled Task | “The wiper was distributed across the network as a scheduled task using Group Policy logon scripts.” | 2\nT1105 | Ingress Tool Transfer | “The attackers first connected to compromised hosts via RDP and then used the local web browser to download the software directly from the official NetBird website.” | 2\n\n### Persistence\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1484.001 | Domain Policy Modification: Group Policy Modification | “To further increase the effect, the threat actor used Group Policy to distribute the different wipers across the network.” | 2\n\n### Privilege Escalation\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1078.004 | Valid Accounts: Cloud Accounts | “Attackers such as Handala target high-value accounts with ‘standing’ (always-on) permissions to facilitate immediate impact.” | 1\nT1098 | Account Manipulation | “Inventory Service Principals with permissions for device management such as DeviceManagementManagedDevices.ReadWrite.All.” (Defensive recommendation implying the attacker abused such permissions.) | 1\n\n### Credential Access\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1003.001 | OS Credential Dumping: LSASS Memory | “These included dumping the LSASS process using comsvcs.dll via rundll32.exe.” | 2\nT1003.002 | OS Credential Dumping: Security Account Manager | “As well as exporting sensitive registry hives such as HKLM [SAM/SYSTEM].” | 2\nT1539 | Steal Web Session Cookie / Token | “Shorten session duration for sensitive administrative portals (e.g., Intune, Entra and Azure portals) to under 1 hour. This helps limit the area of impact for a stolen session token.” (Defensive recommendation implying token theft is a known vector.) | 1\n\n### Discovery\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1087.002 | Account Discovery: Domain Account | “The attacker executed ADRecon (named dra.ps1), a PowerShell-based reconnaissance framework used to enumerate Active Directory environments.” | 2\n\n### Lateral Movement\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1021.001 | Remote Services: Remote Desktop Protocol | “Handala is known to operate primarily in a manual, hands-on manner, with lateral movement conducted largely through extensive use of RDP to move between systems within a compromised environment.” | 2\nT1572 | Protocol Tunneling | “To reach hosts that were not directly accessible from outside the network, the group was observed deploying NetBird, a platform designed to create secure, private zero-trust mesh networks.” | 2\n\n### Defence Evasion\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1562.001 | Impair Defences: Disable or Modify Tools | “The actor disabled Windows Defender protections and executed multiple reconnaissance and credential-theft operations.” | 2\nT1078.004 | Valid Accounts: Cloud Accounts | “Because Intune is a trusted, native Microsoft administrative tool, an attacker weaponizing it to issue mass remote wipe commands would not trigger traditional endpoint detection and response (EDR) or antivirus alerts.” | 3\nT1036 | Masquerading | “To the victim’s security sensors, no malicious files are being dropped; therefore, the activity would appear to be a highly privileged IT administrator executing a standard, albeit catastrophic, compliance policy.” | 3\nT1553.002 | Subvert Trust Controls: Code Signing | “Handala used Rhadamanthys on several occasions, pairing it with one of its custom wipers in phishing lures… [the wiper was] signed with a legitimate certificate, which was probably stolen.” | 4 12\n\n### Collection and Exfiltration\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1530 | Data from Cloud Storage | “If storage accounts send significantly more data outbound than usual, organizations should immediately investigate.” (Defensive recommendation implying observed exfiltration behaviour.) | 1\nT1041 | Exfiltration Over C2 Channel | “Handala claimed that all acquired data is now in the hands of the free people of the world, indicating data was exfiltrated prior to or during the wiper attack.” | 7\nT1048 | Exfiltration Over Alternative Protocol | “Implement technologies to alert and proactively block data exfiltration attempts.” (Defensive recommendation citing observed behaviour.) | 1\n\n### Command and Control\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1572 | Protocol Tunneling (NetBird) | “To reach hosts that were not directly accessible from outside the network, the group was observed deploying NetBird, a platform designed to create secure, private zero-trust mesh networks.” | 2\nT1102 | Web Service (Telegram) | Handala’s AutoIT/NSIS-packaged wiper uses a “Telegram channel as C2.” | 10\nT1219 | Remote Access Software (Intune) | “The perpetrators used Microsoft Intune, a cloud-based administrative console, to monitor and control devices regardless of location and issue remote wipe commands.” | 7\n\n### Impact\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1485 | Data Destruction | “Attackers gained access to corporate networks and deleted servers and workstations, with the aim of disrupting the operations of the attacked organizations.” | 1\nT1561.002 | Disk Wipe: Disk Structure Wipe | “The malware overwrites file contents across the system and additionally leverages MBR-based wiping techniques to corrupt or destroy files on the system.” | 2\nT1486 | Data Encrypted for Impact | “By encrypting the system drives using a legitimate tool (VeraCrypt), the attackers added an additional layer to the destructive process.” | 2\nT1529 | System Shutdown/Reboot (Mass Device Wipe) | “Configure specific alerts for mass wipe events. If more than a specific threshold of devices (e.g., five or 10) is targeted for a wipe within a short window, the system should trigger an immediate automated lockout…” | 1\nT1491 | Defacement | “The login pages coming up on these devices have been defaced with the Handala logo.” | 7\nT1490 | Inhibit System Recovery | “Maintain immutable, air-gapped, offline backups of critical data. As the threat actor’s goal is often pure disruption (wiper activity) rather than financial extortion, the ability to restore from an immutable source may be the only guarantee of recovery.” | 1\nT1489 | Service Stop | “Stryker’s offices in 79 countries have been forced to shut down and more than 5,000 workers in Ireland were sent home as a result of the attack.” | 7\n\n### Resource Development\n\nTechnique ID | Technique Name | Evidence | Source\n---|---|---|---\nT1583 | Acquire Infrastructure | “By operating behind a persona styled as a grassroots, pro-Palestinian resistance movement, Iranian state-nexus actors are able to conduct destructive cyber operations against Western organizations while maintaining a degree of plausible deniability.” | 3\nT1588.001 | Obtain Capabilities: Malware | “The use of Qilin, and participation in its affiliate program, likely serves not only as a layer of cover and plausible deniability, but also as a meaningful operational enabler.” | 4\nT1585 | Establish Accounts | “State actors increasingly adopt hacktivist personas” — Handala cited as a key case study of state-front “fictivism.” | 5\n\n> **Note on evidence quality:** Some techniques are inferred from defensive recommendations issued in direct response to documented Handala intrusions (e.g., token theft, data exfiltration monitoring). These are marked accordingly. Techniques supported by direct forensic observation are given higher confidence.\n\n* * *\n\n 1. Unit 42 — Handala Hack Wiper Attacks ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\n\n 2. Check Point Research — Handala Hack: Unveiling the Group’s Modus Operandi ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\n\n 3. Flashpoint — Destructive Activity Targeting Stryker Highlights Emerging Supply Chain Risks ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\n\n 4. Check Point Research — Iranian MOIS Actors: The Cyber Crime Connection ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\n\n 5. SentinelOne — LABScon25: Hacktivism and War ↩︎ ↩︎ ↩︎\n\n 6. Rapid7 — Iran Cyber Playbook: Escalating Regional Conflict ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\n\n 7. KrebsOnSecurity — Iran-Backed Hackers Claim Wiper Attack on MedTech Firm Stryker ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\n\n 8. Flare — Cyberattacks in the US-Israel-Iran Military Conflict ↩︎ ↩︎ ↩︎\n\n 9. Sophos — Hacktivist Campaigns Increase as US-Iran-Israel Conflict Intensifies ↩︎ ↩︎ ↩︎ ↩︎\n\n 10. CloudSEK — Threat Actor Landscape Assessment of ICS/OT Targeting ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\n\n 11. VECert — OSINT Kitten: The Headquarters for Hacktivist Operations Against Israel ↩︎ ↩︎\n\n 12. Security.com — Iran Cyber Threat Activity Against the US ↩︎ ↩︎\n\n 13. Acronis TRU — Mobile Spyware Campaign Impersonates Israel’s Red Alert System ↩︎\n\n\n",
"title": "Threat Actor Profile - Handala"
}