logo

Insights: Increased Risk of Wiper Attacks

ID: b65d5d4b-a866-59f5-9153-c4dbe5c5f794

STIX ID: report--b65d5d4b-a866-59f5-9153-c4dbe5c5f794

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

Author: Andy Piazza, Eric Goldstrom and Steve Elovitz

...
...

Unit 42 warns of heightened risk and reported incidents of destructive wiper attacks attributed to the Handala Hack group (aka Void Manticore/COBALT MYSTIQUE), assessed as an Iranian state-directed actor; primary vectors include identity exploitation via phishing and abuse of Microsoft Intune administrative access. The advisory provides practical mitigations and detection controls—JIT/PIM for admin access, limiting Global/Intune admins, break-glass accounts, conditional access and FIDO2, hardened privileged workstations, reduced session lifetimes and token protection, data classification/DLP, ingesting Intune audit logs into SIEM/XDR, immutable offline backups, and tabletop exercises—to reduce impact and enable rapid response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.