Government

US Confirms Handala Link to Iran Government Amid Takedown of Hackers’ Sites

The US has seized several domains used by Handala in cyber-enabled psychological operations.

Handala website seized

The United States government has for the first time officially linked the notorious Handala hacker group to the Iranian government. The announcement came amid the takedown of several websites used by Handala.

Handala has been on the radar of cybersecurity firms for years, but it gained widespread attention in recent days after ramping up its activity following the start of the US-Israel-Iran conflict

Handala has allegedly launched many attacks against Israel, including wiping military weather servers, hijacking security camera feeds, exfiltrating and deleting corporate data, publicly exposing details of intelligence personnel, and compromising an oil and gas exploration firm.

However, its best-known attack targeted the US-based medical technology giant Stryker, causing significant disruption after wiping thousands of its systems.

Handala portrays itself as a pro-Palestinian hacktivist group motivated by anti-Israeli ideology. The cybersecurity community, however, widely regards it as a cover for Void Manticore, an Iranian state-sponsored threat actor believed to operate under the direction of Iran’s Ministry of Intelligence and Security (MOIS).

The Justice Department has now confirmed the connection between Handala and Iran’s MOIS, after it took down four websites used by the hacker group for psychological operations.

Advertisement. Scroll to continue reading.

Specifically, authorities seized four domains: Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, and Handala-Redwanted[.]to. 

The Justice Department said Iran’s MOIS used the seized websites “in furtherance of attempted psychological operations targeting adversaries of the regime by claiming credit for hacking activity, posting sensitive data stolen during such hacks, and calling for the killing of journalists, regime dissidents, and Israeli persons”.

An X account used by the hacker group was also suspended in recent days.

The US Department of State is offering a reward of up to $10 million for information on foreign hackers who target critical infrastructure. 

Related: Aisuru and Kimwolf DDoS Botnets Disrupted in International Operation

Related: Tycoon 2FA Phishing Platform Dismantled in Global Takedown

Related: RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement

Related Content

Malware & Threats

Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out.

ICS/OT

An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers.

Cyberwarfare

Researchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel.

ICS/OT

Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Malware & Threats

Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.

ICS/OT

California Water Service says there is no indication of operational disruptions to its water and wastewater systems. 

ICS/OT

The hackers published 5GB of data, including customer personal information and credentials for the RTKBase platform.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version