Categories: Cyber Security News

Handala Expands Destructive Cyber Operations Beyond Israeli Targets

A rising wave of destructive wiper attacks is currently threatening organizations across the United States and Israel, driven by the Iranian-linked threat group known as Handala.

While the group initially masqueraded as an independent hacktivist collective when it emerged in late 2023, security analysts now assess that Handala also tracked as Void Manticore, COBALT MYSTIQUE, and Storm-1084 is a state-directed front for Iran’s Ministry of Intelligence and Security

Sponsored
(MOIS).

On March 6, Israel’s National Cyber Directorate issued a stark warning regarding these tactics, confirming that attackers are successfully gaining access to corporate networks and deleting critical servers and workstations to halt business operations.

According to the latest threat intelligence from Palo Alto Networks Unit 42, Handala has shifted its focus to aggressive data-wiping campaigns aimed at pure operational disruption.

The Attack Vector

Rather than relying on highly sophisticated software vulnerabilities, Handala’s primary attack vector targets human error and administrative oversight.

The group heavily leverages phishing campaigns to steal the login credentials of legitimate corporate users to gain an initial foothold.

Once access is secured, the attackers focus on compromising administrative identities, particularly targeting Microsoft Intune environments.

By taking over high-level administrative accounts, Handala weaponizes legitimate network management tools to issue mass-wipe commands across an organization’s infrastructure.

Sponsored

Because the threat actors use valid corporate identities, their devastating activities often blend in with normal administrative traffic until it is too late.

Proactive Defense and Mitigation Strategies

Defending against state-sponsored wiper attacks requires a zero-trust approach to identity management and strict controls over administrative privileges. Organizations should implement the following targeted mitigations to protect their networks:

  • Eliminate standing privileges: Transition to a Just-In-Time (JIT) access model where administrative credentials have zero default permissions and only gain elevated rights through a formal, approved activation process.
  • Harden administrator accounts: Limit the number of Global and Intune Administrator accounts, use cloud-only accounts to prevent lateral movement from on-premises networks, and secure them with hardware-based multi-factor authentication, such as FIDO2 keys.
  • Require multi-administrator approval: Enforce policies that require a second, distinct administrator to review and approve high-impact actions, such as device wipes or data deletions, before they can be executed.

As geopolitical tensions continue to influence the cyber threat landscape, Palo Alto Networks organizations must prioritize hardening their cloud and identity infrastructure.

Stripping attackers of the administrative access they need to deploy wiper malware is the most effective way to neutralize the Handala threat.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post Handala Expands Destructive Cyber Operations Beyond Israeli Targets appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

The Best Deals Today: Trails in the Sky 1st Chapter, Dragon Quest VII Reimagined, Nioh 3, and More

A new weekend has arrived, and today, you can save big on Trails in the…

1 hour ago

Lightweight CSS3 Animation Library with Data Attributes – data-anim

data-anim is a JavaScript animation library that applies CSS-powered animations to HTML elements while scrolling/hovering/clicking/loading…

2 hours ago

Dynamic Inline HTML Importing with i-html Web Component

The <i-html> web component allows you to dynamically import HTML content inline, similar to an…

2 hours ago

Sotomayor’s Wabi Sabi is the funnest record of 2026

Can’t. Stop. Dancing. | Image: Wonderwheel Recordings Shout out to subscriber N_Gorski for today's pick.…

2 hours ago

Chichester town meeting lasts eight hours; call for budget committee rejected

Many Chichester residents carved out their whole Saturday to participate in a marathon-length town meeting,…

3 hours ago

Nathan Fillion’s Big Firefly Tease Is a Canon Animated Series With the Original Actors Reprising Their Roles — but It Needs a Home

Nathan Fillion’s big Firefly tease has been revealed as a new animated series set between…

3 hours ago

This website uses cookies.