Friday, September 11, 2026

Iran-Linked Handala Ramps Up Wiper Attacks on Israeli, Western Targets

Tracking an increased risk of wiper attacks related to the conflict with Iran, including multiple related incidents impacting organizations in Israel and the US. For the latest intelligence on cyberattacks.

The campaign uses destructive “wiper” malware designed to erase systems and disrupt business operations permanently. Security experts believe these activities are part of a broader cyber strategy connected to the ongoing regional conflict.

The Handala Hack group, also tracked under several aliases including Void Manticore, COBALT MYSTIQUE, Storm‑1084, and Storm‑0842, first appeared in late 2023.

Initially presenting itself as a hacktivist collective, the group is now widely assessed by the threat intelligence community as a state-directed front linked to Iran’s Ministry of Intelligence and Security (MOIS).

According to threat intelligence from Palo Alto Networks Unit 42, the Iran-linked threat group known as Handala Hack has intensified operations targeting organizations in Israel and Western countries, including the United States.

Researchers note that the group often combines propaganda messaging with disruptive cyber operations targeting organizations perceived as aligned with Israeli or Western interests.

Recent intelligence indicates that Handala Hack relies heavily on identity-based attacks rather than traditional vulnerability exploitation.

Attackers reportedly use phishing campaigns to steal credentials from legitimate corporate users and then leverage administrative tools such as Microsoft Intune update to carry out destructive actions.

Israeli Authorities Warn of Wiper Attacks

On March 6, Israel’s National Cyber Directorate issued an official alert warning that Iranian-linked attackers had infiltrated multiple corporate networks and launched destructive attacks.

According to the agency, attackers gained access using legitimate user credentials and then deleted servers and workstations inside targeted organizations. These operations were intended to disrupt services and damage organizational infrastructure.

Wiper attacks differ from ransomware campaigns because the primary objective is destruction rather than financial gain. Instead of encrypting data for ransom, the malware permanently deletes files, operating systems, or device configurations, making recovery extremely difficult.

Security analysts warn that organizations outside Israel could also become targets as geopolitical tensions continue to rise.

Unit 42 researchers highlight that identity compromise plays a central role in these attacks. Once attackers obtain valid credentials, they may escalate privileges and exploit enterprise management platforms such as Microsoft Entra ID or Intune.

Using these administrative tools, attackers can remotely wipe devices, delete systems, or deploy destructive configurations across an organization’s network.

This technique allows attackers to operate using legitimate administrative functions, which can make detection more difficult for traditional security tools.

Mitigations

Security experts recommend several defensive measures to reduce the risk of destructive attacks:

  • Eliminate standing administrative privileges and adopt just-in-time (JIT) access models for sensitive roles.
  • Use Microsoft Entra Privileged Identity Management (PIM) to require multi-factor authentication and approval before activating privileged accounts.
  • Reduce the number of Global Administrator and Intune Administrator accounts to the minimum necessary.
  • Use dedicated privileged access workstations for administrative tasks to prevent credential theft.
  • Implement role-based access control rather than broad administrative privileges.
  • Enable conditional access policies that require hardware-based authentication, such as FIDO2 security keys.
  • Monitor administrative actions such as RemoteWipe and FactoryReset within device management platforms.
  • Configure automated alerts for unusual events such as mass device wipe attempts.
  • Maintain immutable, offline backups of critical systems to ensure recovery after destructive incidents.

Threat intelligence analysts warn that destructive cyber operations often increase during geopolitical conflicts. Wiper malware campaigns have historically been used by nation-state actors to disrupt government agencies, critical infrastructure, and private organizations.

Unit 42 advises organizations to strengthen identity security, closely monitor administrative activity, and prepare incident response plans for destructive attacks.

As tensions continue to evolve, security teams are encouraged to remain vigilant and review updated threat intelligence regarding Iranian-linked cyber operations targeting organizations across Israel, the United States, and allied regions.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News