Operation HamsaUpdate: A Sophisticated Campaign Delivering Wipers Puts Israeli Infrastructure at Risk
ID: 451cd012-278c-53e7-ba8f-5fa5a2ef2867
STIX ID: report--451cd012-278c-53e7-ba8f-5fa5a2ef2867
Feed Name: Intezer Blog
Threat Score
Operation HamsaUpdate is an active, targeted phishing campaign that lures Israeli administrators with F5 BIG-IP-themed messages to execute a multi-stage payload; it deploys a Windows wiper (Hatef) and a Linux wiper (Hamsa) via C# and obfuscated shell/script loaders and a Delphi/AutoIt second-stage (Handala), reports progress to a Telegram channel, and includes numerous IOCs (file hashes, URLs, bot and channel IDs, and a C2 IP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
