FBI Warns of Iran’s Handala Hack Group Using Fake Apps to Spy on Windows Users
ID: b3b81e7e-fbce-5525-a6e5-d0b2ecbea9b8
STIX ID: report--b3b81e7e-fbce-5525-a6e5-d0b2ecbea9b8
Feed Name: HackRead
The FBI warns that Iran MOIS-linked actors (Handala Hack / Homeland Justice) have been luring targets into installing fake Windows apps (e.g., WhatsApp.exe, Telegram_authenticator.exe, KeePass.exe) which deploy spyware (MicDriver) capable of audio/screen capture and use secondary malware (Winappx.exe, MsCache.exe) to exfiltrate files; the activity targets journalists and activists and is tied to larger destructive/data-theft campaigns including a claimed attack on Stryker. Recommended mitigations include not installing files received in chats, using official app stores/websites, keeping Windows updated, and enabling multi-factor authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
