Cybersecurity & Privacy — 2026-03-22

DOJ/FBI Seize Four Handala Domains, Formally Attribute Group to Iran's MOIS

DOJ seized four Handala domains and formally attributed the group to MOIS's Void Manticore unit — establishing it as state-directed, not independent hacktivism. The Stryker attack chain compromised Intune administrator dashboards, enabling mass device wiping across a 150M-patient service chain.

Analysis
Formal MOIS attribution of Handala confirms what Sophos advisory and prior INTSUM flagged: state-directed cyber operations masquerading as hacktivism. The Stryker attack chain (Intune compromise → mass device wipe) is the most damaging healthcare sector cyber incident since Change Healthcare in 2024.
2 sources
  1. US accuses Iran's government of operating hacktivist group that hacked Stryker - TechCrunch
  2. FBI Seizes MOIS Leak Sites After Handala Attack Hit Hospitals - Cyberwarzone

View in full brief →

UNCLASSIFIED // OPEN SOURCE