Threats Feed
- Public
Handala Hack: Unpacking Void Manticore’s Destructive Wiping and Hack-and-Leak Operations
Handala Hack, an Iranian MOIS-affiliated threat actor also tracked as Void Manticore, executes destructive wiping and hack-and-leak operations against targets in Israel, Albania, and the United States. They primarily target the government, telecommunications, and medical technology sectors. The group relies on compromised VPN accounts for initial access, subsequently moving laterally via RDP and the zero-trust mesh platform NetBird. Their hands-on attacks involve disabling Windows Defender and conducting extensive credential dumping via LSASS extraction and ADRecon. To maximize operational impact, Handala simultaneously deploys custom MBR and PowerShell wipers via Group Policy, leverages VeraCrypt for disk encryption, and manually deletes virtual machines, causing severe data destruction.
read more about Handala Hack: Unpacking Void Manticore’s Destructive Wiping and Hack-and-Leak Operations - Public
Storm-842: Iranian Cyberattacks on Albania and Israel’s Critical Systems
Storm-842 (Void Manticore), linked to Iran’s Ministry of Intelligence and Security (MOIS), has conducted destructive cyberattacks targeting Albania and Israel. Using wiper malware and influence campaigns, the group disrupted Albanian e-government and border systems, targeting sectors like government and infrastructure, while aligning attacks with geopolitical events such as opposition conferences. Operations include exploiting vulnerabilities, deploying web shells, and credential harvesting, often in coordination with Scarred Manticore. The attacks incorporate ransomware-style encryptors, disk wipers, and data leaks through personas like “Homeland Justice” and “Karma,” showcasing a blend of technical and psychological tactics.
read more about Storm-842: Iranian Cyberattacks on Albania and Israel’s Critical Systems - Public
Void Manticore and Scarred Manticore's Coordinated Cyber Assaults Unveiled
Void Manticore, an Iranian threat actor, executed destructive cyberattacks in Israel and Albania, targeting government sectors. They collaborated with Scarred Manticore, using CVE-2019-0604 for initial access, followed by custom tools like Foxshell and Liontail for command execution. The attacks involved data exfiltration and the deployment of wipers, including the custom BiBi wiper. The group employed Remote Desktop Protocol (RDP) for lateral movement and leveraged Domain Admin credentials for network control. Information leaks were disseminated through personas "Karma" and "Homeland Justice".
read more about Void Manticore and Scarred Manticore's Coordinated Cyber Assaults Unveiled - Public
BiBi Wiper: A Politically Charged Cyberattack Targets Israeli Defense and Data Sectors
In October, a significant cyberattack targeted Israel, affecting defense contractors and a data-hosting company. This operation, known as "Mission: Data Destruction," employed a new data-wiping malware, BiBi-Linux, with a Windows variant called bibi.exe, to cause extensive data loss. The hacktivist group Karma, linked to these attacks, used this campaign to express political dissent against Israeli Prime Minister Benjamin Netanyahu. These incidents were part of a larger trend of hacktivist groups using data destruction methods, with similar tactics observed in other groups like the Iranian-linked APT, Moses Staff. The campaign involved manual data deletion and spreading malware within networks.
read more about BiBi Wiper: A Politically Charged Cyberattack Targets Israeli Defense and Data Sectors - Public
BiBi-Linux Wiper: New Malware Targets Israeli Companies Amidst Conflict
The Security Joes team discovered a new Linux Wiper malware, dubbed BiBi-Linux Wiper, used by a pro-Hamas hacktivist group during the conflict between Israel and Hamas. This malware, an x64 ELF executable, is designed to destroy systems by overwriting and renaming files, particularly targeting Israeli companies. It lacks obfuscation, utilizes multi-threading for efficiency, and avoids corruption of certain file types crucial for its operation. The term "BiBi" in the malware's naming convention is a political reference to Israeli Prime Minister Benjamin Netanyahu, suggesting a targeted political motive behind the attacks.
read more about BiBi-Linux Wiper: New Malware Targets Israeli Companies Amidst Conflict