Tracking an increased risk of wiper attacks related to the conflict with Iran, including multiple related incidents impacting organizations in Israel and the US. For the latest intelligence on cyberattacks.
The campaign uses destructive “wiper” malware designed to erase systems and disrupt business operations permanently. Security experts believe these activities are part of a broader cyber strategy connected to the ongoing regional conflict.
The Handala Hack group, also tracked under several aliases including Void Manticore, COBALT MYSTIQUE, Storm‑1084, and Storm‑0842, first appeared in late 2023.
Initially presenting itself as a hacktivist collective, the group is now widely assessed by the threat intelligence community as a state-directed front linked to Iran’s Ministry of Intelligence and Security (MOIS).
According to threat intelligence from Palo Alto Networks Unit 42, the Iran-linked threat group known as Handala Hack has intensified operations targeting organizations in Israel and Western countries, including the United States.
Researchers note that the group often combines propaganda messaging with disruptive cyber operations targeting organizations perceived as aligned with Israeli or Western interests.
Recent intelligence indicates that Handala Hack relies heavily on identity-based attacks rather than traditional vulnerability exploitation.
Attackers reportedly use phishing campaigns to steal credentials from legitimate corporate users and then leverage administrative tools such as Microsoft Intune update to carry out destructive actions.
Israeli Authorities Warn of Wiper Attacks
On March 6, Israel’s National Cyber Directorate issued an official alert warning that Iranian-linked attackers had infiltrated multiple corporate networks and launched destructive attacks.
According to the agency, attackers gained access using legitimate user credentials and then deleted servers and workstations inside targeted organizations. These operations were intended to disrupt services and damage organizational infrastructure.
Wiper attacks differ from ransomware campaigns because the primary objective is destruction rather than financial gain. Instead of encrypting data for ransom, the malware permanently deletes files, operating systems, or device configurations, making recovery extremely difficult.
Security analysts warn that organizations outside Israel could also become targets as geopolitical tensions continue to rise.
Unit 42 researchers highlight that identity compromise plays a central role in these attacks. Once attackers obtain valid credentials, they may escalate privileges and exploit enterprise management platforms such as Microsoft Entra ID or Intune.
Using these administrative tools, attackers can remotely wipe devices, delete systems, or deploy destructive configurations across an organization’s network.
This technique allows attackers to operate using legitimate administrative functions, which can make detection more difficult for traditional security tools.
Mitigations
Security experts recommend several defensive measures to reduce the risk of destructive attacks:
- Eliminate standing administrative privileges and adopt just-in-time (JIT) access models for sensitive roles.
- Use Microsoft Entra Privileged Identity Management (PIM) to require multi-factor authentication and approval before activating privileged accounts.
- Reduce the number of Global Administrator and Intune Administrator accounts to the minimum necessary.
- Use dedicated privileged access workstations for administrative tasks to prevent credential theft.
- Implement role-based access control rather than broad administrative privileges.
- Enable conditional access policies that require hardware-based authentication, such as FIDO2 security keys.
- Monitor administrative actions such as RemoteWipe and FactoryReset within device management platforms.
- Configure automated alerts for unusual events such as mass device wipe attempts.
- Maintain immutable, offline backups of critical systems to ensure recovery after destructive incidents.
Threat intelligence analysts warn that destructive cyber operations often increase during geopolitical conflicts. Wiper malware campaigns have historically been used by nation-state actors to disrupt government agencies, critical infrastructure, and private organizations.
Unit 42 advises organizations to strengthen identity security, closely monitor administrative activity, and prepare incident response plans for destructive attacks.
As tensions continue to evolve, security teams are encouraged to remain vigilant and review updated threat intelligence regarding Iranian-linked cyber operations targeting organizations across Israel, the United States, and allied regions.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





