Back to Feed
Nation-stateMar 12, 2026

Insights: Increased Risk of Wiper Attacks

Iran-linked threat actor Handala Hack (also known as Void Manticore and COBALT MYSTIQUE) has been observed conducting an increased campaign of wiper attacks, leveraging phishing and Microsoft Intune misuse as attack vectors. The group is exploiting identity management weaknesses to deploy destructive malware, prompting security teams to implement enhanced controls and proactive defenses.

Summary

Iran-linked threat actor Handala Hack (also known as Void Manticore and COBALT MYSTIQUE) has been observed conducting an increased campaign of wiper attacks, leveraging phishing and Microsoft Intune misuse as attack vectors. The group is exploiting identity management weaknesses to deploy destructive malware, prompting security teams to implement enhanced controls and proactive defenses.

Indicators of Compromise

  • malware — Handala Hack
  • malware — Void Manticore
  • malware — COBALT MYSTIQUE