Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-disruptiondefense-evasion-methodcredential-access-methodlateral-movement-method

Iran-Linked Handala Used VPN Access, RDP, NetBird, and Wipers in Destructive Campaign

Updated 19d agoFirst seen Mar 17, 20265 sources

Researchers linked Handala Hack to Iran’s Ministry of Intelligence and Security as part of the broader Void Manticore cluster, describing a coordinated campaign that targeted organizations in Israel, Albania, and the United States with disruptive and destructive intrusions. Reported victims and incidents included attacks on Stryker, compromises affecting kindergarten emergency alert systems, and a personal Gmail breach publicly attributed to FBI Director Kash Patel that the FBI said involved historical, non-classified data. U.S. authorities also seized four domains allegedly used by the operation to leak stolen data, publicize attacks, and support influence activity.

Investigators said the intrusions commonly began with compromised VPN credentials, followed by hands-on-keyboard movement over RDP, use of NetBird for tunneling, credential theft, Active Directory reconnaissance, and staged malware delivery. The destructive phase combined multiple methods at once, including a custom Handala Wiper, PowerShell-based wiping, VeraCrypt encryption, manual deletion of files and virtual machines, and tooling tied to webshell persistence, Telegram-linked data exfiltration, driver-assisted disk access, and attempts to disable endpoint defenses. Analysts also tied Handala to other MOIS personas including Homeland Justice and Karma, saying the fronts shared infrastructure, domain patterns, Telegram-based communications, and overlapping tradecraft in a single coordinated state-backed campaign.

Share:
Iran-Linked Handala Used VPN Access, RDP, NetBird, and Wipers in Destructive Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 20, 20262mo ago

DOJ seizes four domains tied to the MOIS-linked operation

In March 2026, the U.S. Justice Department announced the seizure of four domains associated with the coordinated MOIS-linked campaign. The domains had allegedly been used to leak stolen data, claim attacks, and call for violence.

Researchers Say Iranian MOIS Uses Multiple Hacker Personas for One Coordinated Cyber Campaign - Cyber Security News

MOIS campaign rebrands toward Israeli targets

DomainTools-linked reporting says the broader MOIS operation shifted activity toward Israeli targets in late 2023 under personas including Handala. The campaign was assessed as a coordinated state operation using multiple hacker personas as fronts.

Researchers Say Iranian MOIS Uses Multiple Hacker Personas for One Coordinated Cyber Campaign - Cyber Security News
Mar 17, 20263mo ago

Handala conducts disruptive attack on Stryker

Multiple references describe a March 2026 destructive or disruptive intrusion affecting medical technology firm Stryker. Check Point says the operation was part of MOIS-linked Void Manticore activity using compromised VPN credentials, RDP movement, NetBird tunneling, and parallel wiping methods.

Handala Hack Uses RDP, NetBird, and Parallel Wipers in MOIS-Linked Destructive Intrusions
Mar 13, 20264mo ago

Handala compromises kindergarten emergency alert systems

SOCRadar reports that in January 2026 Handala conducted a compromise affecting kindergarten emergency alert systems. The incident is cited as a notable disruptive operation attributed to the group.

Dark Web Profile: Handala Hack

Handala runs CrowdStrike-themed phishing and wiper campaign

SOCRadar highlights a notable July 2024 campaign in which Handala used CrowdStrike-themed phishing as part of a disruptive and destructive operation involving wiper activity. The incident is presented as one of the group's notable operations.

Dark Web Profile: Handala Hack

Handala persona emerges and begins claiming attacks

SOCRadar says Handala emerged in December 2023 as a purported pro-Palestinian hacktivist persona and began claiming attacks against Israeli and Western targets. The report notes multiple vendors later assessed it with high confidence as an Iranian MOIS-linked cyber persona.

Dark Web Profile: Handala Hack
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

40 LINKEDOpen in app
Affected products
5 linked
Remote Desktop ProtocolTelegramTorGmailVeracrypt
Organizations
11 linked
Microsoft CorporationDomainToolsF5Check Point Software TechnologiesSplunkStrykerVerifoneSOCRadarCrowdStrikeSophosGoogle
Breaches
3 linked
GOVERNMENTOFALBANIA-2022-07GOVERNMENTOFALBANIA-2026-04STRYKERCORPORATION-2026-03
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.