logo

Operation HamsaUpdate: A Sophisticated Campaign Delivering Wipers Puts Israeli Infrastructure at Risk

ID: 451cd012-278c-53e7-ba8f-5fa5a2ef2867

STIX ID: report--451cd012-278c-53e7-ba8f-5fa5a2ef2867

Feed Name: Intezer Blog

Threat Score
78/100

Date Published: 2023-12-20

Date Updated: 2026-04-28

Author: Nicole Fishbein

...
...

Operation HamsaUpdate is an active, targeted phishing campaign that lures Israeli administrators with F5 BIG-IP-themed messages to execute a multi-stage payload; it deploys a Windows wiper (Hatef) and a Linux wiper (Hamsa) via C# and obfuscated shell/script loaders and a Delphi/AutoIt second-stage (Handala), reports progress to a Telegram channel, and includes numerous IOCs (file hashes, URLs, bot and channel IDs, and a C2 IP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.