logo

Handala Hack Targets U.S. Troops with Doxxing Threats in Bahrain

ID: ee595e27-5b61-59ea-901b-4fddaec80b83

STIX ID: report--ee595e27-5b61-59ea-901b-4fddaec80b83

Feed Name: SOCRadar Blog

Threat Score
88/100

Date Published: 2026-04-28

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Handala (aka Void Manticore / Storm-0842), an Iran-aligned intelligence-linked actor, has escalated from operations targeting Israeli infrastructure to attacks and doxxing against U.S. entities and personnel in 2026; the group has claimed destructive wiper campaigns (including a large disruption of Stryker via Microsoft Intune abuse), published doxxed records of thousands of U.S. service members, and uses a mix of custom wipers, social engineering, and legitimate admin channels — the report includes MITRE TTP mappings and actionable IOCs (IPs, URLs, file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.