Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-disruptiongovernment-diplomatic-threatoperational-disruptioncredential-access-method

Iran-Linked Handala Hack Wiper Campaign Against Israeli and U.S. Organizations

Updated 3mo agoFirst seen Mar 12, 20263 sources

Handala Hack, an online persona tied to Void Manticore and assessed by multiple researchers as linked to Iran’s Ministry of Intelligence and Security (MOIS), is being tracked for destructive intrusions involving wiper attacks and related hack-and-leak activity against organizations in Israel and the United States. Public reporting cited by Unit 42 says attackers gained access to corporate networks using legitimate user credentials, while recent tradecraft includes phishing, identity compromise, and abuse of administrative access through Microsoft Intune. Israel’s National Cyber Directorate warned that several incidents involved deletion of servers and workstations to disrupt operations, reinforcing concern that the current regional conflict is increasing the likelihood of further destructive cyber activity.

Technical reporting indicates the actor continues to favor hands-on-keyboard operations, multiple wiping methods, and a mix of custom and publicly available tooling. Check Point said newly observed techniques include use of NetBird for tunneling and an AI-assisted PowerShell script for wiping, while Blackpoint’s advisory highlighted a broader Iranian threat posture featuring credential theft, phishing, password spraying, remote management tools, and exfiltration utilities such as Rclone. The combined reporting points to a near-term risk of disruptive attacks focused on identity compromise, lateral movement, data theft, and system destruction, particularly for organizations with exposed services, weak privilege controls, or insufficiently protected administrative accounts.

Share:
Iran-Linked Handala Hack Wiper Campaign Against Israeli and U.S. Organizations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 12, 20264mo ago

Unit 42 warns of increased risk of Handala-linked wiper attacks

On March 12, Palo Alto Networks Unit 42 warned of an increased risk of destructive wiper attacks tied to the Iran-related conflict, citing multiple incidents affecting organizations in Israel and the United States. The report linked the activity to Handala Hack and described access methods including phishing, identity compromise, and abuse of Microsoft Intune administrative control, while recommending tighter Entra ID and Intune protections and monitoring for mass wipe actions.

Blackpoint issues advisory on elevated Iran-related cyber risk

Blackpoint Cyber published an advisory on March 12 warning that escalating Iran-Israel-U.S. tensions were likely to drive increased Iranian state-linked and aligned cyber activity in the coming days to weeks. The company said it had not yet observed related exploitation in its own client base at the time of writing, but warned of a likely progression from DDoS and nuisance activity to disruptive hack-and-leak and destructive campaigns.

Check Point attributes Handala persona to Void Manticore

Check Point Research reported that the Handala Hack persona is operated by Void Manticore, also known as Red Sandstorm and Banished Kitten, an Iranian MOIS-affiliated threat actor that also runs the Homeland Justice and Karma personas. The report detailed the group’s modus operandi, including NetBird tunneling, ADRecon, credential dumping, Group Policy-based wiper deployment, a custom Handala wiper, an AI-assisted PowerShell wiper, VeraCrypt encryption, and manual destruction of files and virtual machines.

Researchers identify new malware and IOCs tied to recent Iran-linked attacks

Recent attack reporting cited by Blackpoint described likely MuddyWater activity targeting U.S. organizations across multiple critical sectors and identified the Dindoor and FakeSet backdoors, along with related hashes and shared code-signing certificates. The reporting also noted common attacker tradecraft such as phishing, password spraying, exploitation of edge devices and VPNs, use of RMM tools and LOLBins, and Rclone for exfiltration.

Iran-linked Handala conducts destructive hack-and-leak campaigns

Handala Hack, later linked by multiple researchers to the Iranian MOIS-affiliated actor Void Manticore, carried out destructive intrusions primarily against organizations in Israel and Albania and more recently against U.S.-based organizations. The operations involved compromised VPN credentials, phishing, identity compromise, manual lateral movement, data theft, and destructive actions including wiping, encryption, and file deletion.

Mar 6, 20264mo ago

Israeli cyber authority warns of Iranian destructive intrusions

On March 6, Israel’s National Cyber Directorate warned that Iranian attackers had accessed corporate networks, sometimes using legitimate user credentials, and deleted servers and workstations to disrupt operations. The warning highlighted active destructive activity against organizations rather than a purely theoretical threat.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

38 LINKEDOpen in app
Affected products
5 linked
Microsoft Entra IdPowershellMicrosoft OfficeRemote Desktop Protocol (Rdp)Veracrypt
Organizations
17 linked
Microsoft CorporationPalo Alto NetworksYubicoCyberarkCheck Point Software TechnologiesVeracryptSyncroBlackpoint CyberPaperCut SoftwareStarlinkBackblazeStrykerN-AbleSimpleHelpNetBirdOneHubTeraBox
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Iran-Linked Handala Hack Wiper Campaign Against Israeli and U.S. Organizations | Mallory