Handala Hackers Exploit RDP and NetBird in Coordinated Wiper Attacks
ID: 01ea1dcb-5ab2-56cc-bcdd-e86c7866dfd6
STIX ID: report--01ea1dcb-5ab2-56cc-bcdd-e86c7866dfd6
Feed Name: GBHackers
Handala Hack (aka Void Manticore) is a MOIS-linked Iranian destructive actor that obtains long-term VPN/credential access, uses RDP and manually deployed NetBird mesh networking for lateral movement, and simultaneously deploys multiple wiping techniques (custom wiper binary, AI-assisted PowerShell wiper, and VeraCrypt encryption) to rapidly devastate networks; the report details observed TTPs, multiple IOCs (hashes, IPs, ranges), and prioritized defensive mitigations such as enforcing MFA, hardening RDP, and monitoring for large-scale PowerShell deletions and Group Policy changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
