logo

FBI Warns of Iran’s Handala Hack Group Using Fake Apps to Spy on Windows Users

ID: b3b81e7e-fbce-5525-a6e5-d0b2ecbea9b8

STIX ID: report--b3b81e7e-fbce-5525-a6e5-d0b2ecbea9b8

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

The FBI warns that Iran MOIS-linked actors (Handala Hack / Homeland Justice) have been luring targets into installing fake Windows apps (e.g., WhatsApp.exe, Telegram_authenticator.exe, KeePass.exe) which deploy spyware (MicDriver) capable of audio/screen capture and use secondary malware (Winappx.exe, MsCache.exe) to exfiltrate files; the activity targets journalists and activists and is tied to larger destructive/data-theft campaigns including a claimed attack on Stryker. Recommended mitigations include not installing files received in chats, using official app stores/websites, keeping Windows updated, and enabling multi-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.