TL;DR
Handala Hack Team is an Iranian state-linked hacktivist group — assessed with medium-high confidence as an asset of Iran's Ministry of Intelligence and Security (MOIS) — that executed the most destructive wartime cyberattack on a U.S. company in documented history. On March 11, 2026, using a single compromised Microsoft Intune administrator credential, they wiped over 200,000 endpoints at Stryker Corporation ($25B med-tech, $450M in U.S. defense contracts) and exfiltrated 50 TB of data. Two weeks later they claimed to have wiped 40 TB of data from Hebrew University of Jerusalem. As of late April 2026, CISA has confirmed Iranian-affiliated actors are sitting inside U.S. water treatment, energy, and wastewater PLCs, treating them as pre-positioned dormant weapons. This is a full technical profile of the crew behind it.
Background: From Telegram Threats to Wartime Cyberweapon
Handala Hack Team surfaced on December 7, 2023 — roughly two months after Hamas's October 7 attacks — naming itself after the Naji al-Ali cartoon character, a Palestinian symbol of resistance. What started as defacement campaigns and DDoS operations against Israeli targets has, over 28 months, evolved into a professional cyberweapon program operating under Iranian state direction.
The attribution chain is solid, if technically "assessed." Multiple intelligence firms — FortiGuard, Outpost24/KrakenLabs, SOCRadar, and CrowdStrike — link Handala to MOIS operational clusters, specifically the same infrastructure and tooling used by Void Manticore and BANISHED KITTEN, two previously tracked Iranian APT sub-groups. The group operates under at least eight tracked aliases:
| Alias | Context |
|-------|---------|
| Handala / Handala Hack Team | Primary public identity |
| Void Manticore | CrowdStrike tracking designation |
| BANISHED KITTEN | Fortinet designation |
| CYBER_HANDALA | Telegram channel handle |
| HANDALA_INTEL | Secondary intel-dump channel |
| HANDALA_HPR | Hacktivism propaganda relay |
| HANDALA_HPR2 | Overflow / backup channel |
This multi-alias structure is deliberate — it creates operational separation between propaganda, intelligence claims, and technical drops, making takedown harder and attribution ambiguous enough for Iranian deniability.
Geopolitical timeline matters. Handala's operational tempo directly maps to geopolitical flashpoints:
- Oct–Dec 2023: Group emerges post-October 7. Initial campaigns: Israeli government defacements, GPS spoofing claims, phishing of Israeli defense contractors.
- 2024: Targeting expands to Gulf energy infrastructure and Israeli tech companies. First credible wiper deployment against mid-tier Israeli IT firm.
- Feb 2026 — Operation Epic Fury: U.S. launches military strikes against Iranian targets. Handala immediately escalates — more targets, faster cadence, first U.S. corporate target (Stryker, flagged weeks before the attack was executed).
- March 11, 2026: Stryker attack — see below.
- April 7, 2026 — Quds Day: Claimed Hebrew University breach, 40 TB wipe; CISA issues advisory on Iranian actors inside U.S. PLCs.
- April 29, 2026: Group remains active. Outpost24 reports they are prioritizing Israeli civilian infrastructure, Gulf energy organizations, and Western government entities.
Technical Analysis: How Handala Operates
Stage 1 — Initial Access
Handala favors two primary initial access vectors:
Vector A: Spear-phishing with credential harvesting
Highly targeted phishing emails impersonating HR departments, security tools, or Microsoft 365 notifications. The lure delivers a credential phishing page (often hosted on compromised infrastructure or bulletproof hosting in MENA region). In the Stryker case, the ultimate credential compromised was a Microsoft Intune global administrator account — almost certainly obtained through phishing, given the group's consistent tooling.
Vector B: Web server exploitation via known CVEs
Two CVEs are formally attributed in the FortiGuard threat actor profile:
- CVE-2023-6895 — Hikvision IP camera remote code execution (CVSS 9.8). Exploited against Israeli and Gulf CCTV/physical security infrastructure to gain initial network presence.
- CVE-2017-7921 — Hikvision authentication bypass (CVSS 9.8). Older but still unpatched at thousands of sites. Handala has been observed using this as an entry point into industrial networks where camera systems share VLANs with operational technology.
Both CVEs targeting Hikvision cameras signal a deliberate strategy: physical security systems are often network-connected, poorly monitored, and provide a pivot point into corporate or industrial networks without triggering conventional EDR.
Stage 2 — Persistence and Lateral Movement
Once inside, the group deploys web shells for persistent server-side access. These are generally PHP-based (variants of China Chopper or custom shells), placed in writable directories of victim web applications — a standard MOIS playbook also seen in previous BANISHED KITTEN campaigns.
Lateral movement leverages valid credentials (stolen in Stage 1 or harvested from the web shell foothold) rather than noisy exploitation. This is the group's key operational security discipline: they avoid deploying exploits post-access, making them harder to detect via exploit-focused signatures.
Stage 3 — Exfiltration
Before detonation, Handala performs systematic exfiltration using cloud-based staging — typically legitimate file hosting services (Mega, anonymous S3-compatible buckets) accessed via proxied connections. The Stryker operation reportedly exfiltrated approximately 50 TB over an extended dwell period before the wiper was triggered.
Dwell time is a critical indicator: the group doesn't rush. In multiple documented campaigns, they sit for weeks to months collecting data before executing the destructive phase.
Stage 4 — Wiper Deployment (The Signature Move)
Handala's defining capability is its custom wiper malware, and the Stryker operation demonstrated a significant evolution in delivery mechanism.
The Intune Kill Switch (March 2026)
Rather than deploying malware through traditional means (lateral movement + manual execution), in the Stryker attack Handala weaponized Microsoft Intune's MDM enrollment — the very tool IT teams use to manage endpoints at scale. The attack chain:
1. Compromised global administrator account (no MFA or MFA bypassed)
2. Logged into Intune admin console
3. Created a PowerShell/custom script payload packaged as a device compliance policy or app deployment
4. Targeted deployment: all 200,000+ managed endpoints
5. Policy pushed simultaneously: wiper executes, MBR overwritten or filesystem destroyed
This is devastatingly elegant. Intune is designed to push scripts to every managed device simultaneously, with high privilege, without user interaction. The attacker didn't need to propagate malware across a network — they used Intune's legitimate distribution mechanism as a force multiplier. One admin credential = 200,000 simultaneous wipes.
Earlier wiper variants (pre-Stryker) were more conventional Linux ELF binaries or Windows PE wipers that overwrote MBR and first N sectors of drive. Delivered via web shells or RDP sessions on individual hosts.
Stage 5 — Amplification and Psychological Operations
Post-attack, Handala immediately pushes to their Telegram channels with screenshots, file trees of exfiltrated data, and video evidence of system disruption. They maintain a dedicated leak site for publishing stolen data in staged releases — maximizing psychological pressure and news coverage over days to weeks.
This two-phase approach (technical destruction + information warfare) is explicitly a MOIS playbook: the physical damage is augmented by the media coverage of the breach, which amplifies economic and reputational harm.
Major Operations: The Operation Record
Stryker Corporation (March 11, 2026) — "The Kill Switch"
- Target: Stryker Corporation — $25B medical device manufacturer, $450M+ in U.S. Department of Defense contracts (orthopedic implants, military surgical equipment)
- Claimed impact: 200,000+ endpoints wiped; 50 TB exfiltrated
- Vector: Compromised Microsoft Intune global administrator credential
- Trigger: Explicitly framed as retaliation for a reported U.S. airstrike on a girls' school in Tehran during Operation Epic Fury
- Status: Under investigation; Stryker confirmed significant disruption to thousands of systems
- Assessment: Most significant wartime cyberattack against a U.S. corporation in documented history
Hebrew University of Jerusalem (April 7, 2026) — "Quds Day Strike"
- Target: Hebrew University of Jerusalem — leading Israeli research institution
- Claimed impact: All servers compromised; 40 TB wiped (research data, financial records, communications)
- Timing: Executed on Quds Day (annual Iranian-designated day of solidarity with Palestine), during a fragile Operation Epic Fury ceasefire
- Assessment: Claim unverified independently; Hebrew University acknowledged disruptions
U.S. Critical Infrastructure PLCs (Q1–Q2 2026) — "The Sleeping Threat"
- CISA Advisory (April 7, 2026): Confirmed Iranian-affiliated actors accessed internet-connected programmable logic controllers (PLCs) in U.S. water, wastewater, and energy sectors
- Scope: Multiple municipal utilities, including small water systems with limited security budgets
- Current status: Access confirmed; no destructive action taken yet
- Assessment: Pre-positioning for deterrence or future kinetic-equivalent cyber strike; consistent with Iran's documented strategy of gaining access to cause fear, not immediate damage
Gulf Energy Infrastructure (Ongoing 2026)
- Targets: Undisclosed Gulf-based energy organizations (UAE, Saudi Arabia probable based on reporting context)
- Current focus: Outpost24 (April 24, 2026) confirms active targeting of Gulf energy sector
- Assessment: Consistent with MOIS targeting of Arab states that normalized relations with Israel and supported U.S. operations
IOCs / Indicators of Compromise
Note: Specific hashes for the Stryker wiper are not publicly released as of April 29, 2026. Listed indicators are drawn from publicly available sources for earlier Handala campaigns.
CVEs actively exploited:
CVE-2023-6895— Hikvision RCE (CVSS 9.8) — patch: Hikvision firmware update, disable UPnP exposureCVE-2017-7921— Hikvision auth bypass (CVSS 9.8) — patch: firmware, network isolation
Infrastructure patterns:
- Web shells in
/uploads/,/images/,/assets/directories on PHP-based web applications - Cloud exfiltration staging to MEGA.nz and anonymous object storage endpoints
- Telegram channels: @CYBER_HANDALA, @HANDALA_INTEL (treat as adversary amplification infrastructure, not IOC per se)
Microsoft Intune abuse indicators (post-Stryker):
- Intune admin console logins from anomalous geographies (MENA IP ranges, VPN/proxy endpoints)
- New PowerShell scripts or device compliance policies created by admin accounts outside change windows
- Bulk device targeting by newly created or modified Intune policies
- Script content referencing
dd,wbadmin, disk overwrites, or base64-encoded executables
Network-level patterns (historical campaigns):
- C2 domains hosted on bulletproof hosting in MENA; short TTLs, frequent rotation
- TLS certificates with self-signed CAs or Let's Encrypt on non-descriptive hostnames
- Exfiltration traffic to cloud storage during off-hours in victim timezone
Lyrie Take: When Hacktivism Is Just APT With Better Marketing
The "hacktivist" label is doing serious political work here that threat defenders can't afford to believe.
Handala has the ideological messaging, the Telegram channels, the political manifestos. They also have professional-grade dwell time, systematic exfiltration, and a novel attack chain (Intune weaponization) that requires significant engineering investment and inside knowledge of enterprise MDM architecture. Actual hacktivists don't build that. MOIS does.
The operational pattern is unmistakable: state actor using hacktivist cover for plausible deniability. Iran gets the damage, the deterrence signal, and the ability to say "we condemn unauthorized cyber activity" in the same breath. It's the same model Russia used with Sandworm under "CyberBerkut" branding during Ukraine operations.
The Intune weaponization is the biggest technical development of Q1 2026 in this actor's profile. It fundamentally changes the threat model for any organization with a large Microsoft Intune-managed fleet. Previously, wiping 200,000 endpoints required months of lateral movement, credential harvesting across multiple domains, and custom worm development. Now it requires one admin credential and thirty minutes in a browser. The attacker's force multiplier is now the victim's own IT infrastructure.
The PLC pre-positioning is the bigger strategic concern. Getting into a small Pennsylvania water system accomplishes little militarily. Getting into 50 water systems, mapped, understood, and left dormant, is a deterrent lever — a way to say "we can cause a civilian infrastructure crisis at a time of our choosing." That's the signal CISA was warning about.
From Lyrie's perspective: this actor is operating at machine speed in one dimension (Intune mass wipe = simultaneous action across 200K endpoints) and is demonstrating that defensive human-speed response is structurally insufficient. You cannot detect an Intune-delivered wiper by watching network traffic. You cannot patch your way out of a compromised admin credential. The only answers are autonomous credential monitoring, anomalous MDM policy detection, and break-glass procedures that assume admin compromise.
Defender Playbook
Immediate (24–72 hours):
1. Audit Intune global administrator accounts: How many exist? Which have MFA? Review sign-in logs for the past 90 days for anomalous authentication (impossible travel, new devices, off-hours access). Require phishing-resistant MFA (FIDO2/passkeys) for all admin accounts.
2. Implement Intune change management controls: Create an alert policy for new PowerShell scripts, new device compliance policies, and bulk device targeting actions. Route these alerts to a 24/7-monitored queue with a minimum review window.
3. Patch Hikvision cameras now: CVE-2023-6895 and CVE-2017-7921 are both CVSS 9.8 and trivially exploitable. Audit your network for all Hikvision devices. Apply vendor firmware updates. Isolate camera VLANs from production networks immediately.
4. Remove internet exposure from PLCs: If you operate any ICS/SCADA environment, conduct an urgent audit of internet-facing PLCs. Apply the principle of network isolation per CISA ICS-CERT guidance (ICS-ALERT-22-137-01 and the April 7, 2026 advisory).
Short-term (1–4 weeks):
5. MDM break-glass procedure: Design a documented procedure for revoking global admin access to your MDM platform within minutes of detecting compromise. This should be executable without logging into the compromised admin account.
6. Conditional Access hardening: Enforce Conditional Access policies that block Intune admin console access from non-corporate-managed devices and restrict to named locations or known IP ranges.
7. Credential monitoring: Deploy credential exposure monitoring for all privileged accounts (Entra ID global admins, Intune admins, Azure subscription owners). Alert on any credentials appearing in breach databases or dark web forums.
8. Tabletop exercise: Run a "compromised Intune admin" scenario. How fast can you detect it? How fast can you revoke access and contain the blast radius? If the answer is "hours," it's not fast enough.
Strategic:
9. Zero-trust admin workstations: All privileged administrative actions (Intune, Entra ID, Azure Portal) should occur from Privileged Access Workstations (PAWs) with hardware security keys. No admin access from regular user endpoints.
10. Segment MDM management plane: Treat the Intune admin console as a crown jewel. Monitor it like you'd monitor your CA. Log everything. Alert on everything.
11. Assume pre-positioning: If you operate any industrial control systems connected to the internet — water, power, building management, industrial automation — assume Iranian-linked actors may already have access. Commission an immediate ICS penetration test and network forensic review.
Sources
1. FortiGuard Labs — Handala Threat Actor Profile (updated April 2026): https://fortiguard.fortinet.com/threat-actor/6378/handala
2. Outpost24 / KrakenLabs — Handala Hack Team Threat Profile (April 24, 2026): https://outpost24.com/blog/handala-hack-threat-profile/
3. SOCRadar — Dark Web Profile: Handala Hack (2026): https://socradar.io/blog/dark-web-profile-handala-hack/
4. The New Yorker — "How Big a Threat Are Iranian-Backed Cyberattacks?" (April 24, 2026): https://www.newyorker.com/news/the-lede/how-big-a-threat-are-iranian-backed-cyberattacks
5. Lumos — "The Stryker Hack: How One Compromised Admin Account Led to 200,000 Wiped Devices" (2026): https://www.lumos.com/blog/stryker-hack
6. Specops Software — "Stryker Cyber-Attack: What We Know About the Remote Wipe Attack" (2026): https://specopssoft.com/blog/stryker-cyber-attack-what-we-know-remote-wipe/
7. CISA Advisory AA21-321a — Iranian State-Sponsored Cyber Activity: https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-321a
8. SOCRadar Iran–Israel Cyber Conflict Dashboard (April 29, 2026): https://socradar.io/iran-israel-cyber-conflict-dashboard/
9. Wikipedia — Handala Hack Team: https://en.wikipedia.org/wiki/Handala_Hack_Team
10. CyberExpress — 2026 Threat Landscape: Ransomware, Breaches & Exploits (April 2026): https://thecyberexpress.com/march-2026-threat-landscape/
Lyrie.ai Cyber Research Division — Senior Analyst Desk
Lyrie Verdict
Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.