Handala Hack Targets U.S. Troops with Doxxing Threats in Bahrain
ID: ee595e27-5b61-59ea-901b-4fddaec80b83
STIX ID: report--ee595e27-5b61-59ea-901b-4fddaec80b83
Feed Name: SOCRadar Blog
Handala (aka Void Manticore / Storm-0842), an Iran-aligned intelligence-linked actor, has escalated from operations targeting Israeli infrastructure to attacks and doxxing against U.S. entities and personnel in 2026; the group has claimed destructive wiper campaigns (including a large disruption of Stryker via Microsoft Intune abuse), published doxxed records of thousands of U.S. service members, and uses a mix of custom wipers, social engineering, and legitimate admin channels — the report includes MITRE TTP mappings and actionable IOCs (IPs, URLs, file hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
