Handala Hack Uses RDP, NetBird, and Parallel Wipers in MOIS-Linked Destructive Intrusions
ID: d2fd4a5e-8cdc-5ce1-bc25-e5acc95b5701
STIX ID: report--d2fd4a5e-8cdc-5ce1-bc25-e5acc95b5701
Feed Name: cybersecurityNews.com
This report details a destructive campaign by Iran-linked threat actor Handala Hack / Void Manticore that has executed coordinated multi-vector wiping operations across victims in Israel, Albania, and the United States. The actor leverages compromised VPN credentials and RDP for access, uses NetBird for internal tunneling, and simultaneously deploys multiple wipers (a custom MBR-corrupting Handala Wiper distributed via Group Policy, an AI-assisted PowerShell wiper that propagates a propaganda image, and VeraCrypt-based drive locking) to maximize irreversible data loss; defenders are advised to enforce MFA, restrict RDP, monitor for tunneling tools and suspicious logins, and block known Iranian and Starlink IP ranges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
