- HandalaIranian-linked hacktivist group, also known as Handala Hack, Hatef, Hamsa; associated with MOIS
- HatefAlias for Handala threat actor group
- HamsaAlias for Handala threat actor group
ThreatNoir Morning Brief — March 30
Morning Review in IT Security — March 30, 2026
The cybersecurity landscape continues to face significant threats as of March 30, 2026, with high-profile breaches affecting government leadership, healthcare platforms, and widespread WordPress installations. These incidents underscore persistent vulnerabilities in both infrastructure and third-party software, while emerging threat tools demonstrate the evolving sophistication of cybercriminal operations.
FBI Confirms Hack of Director Patel's Personal Email Inbox
The personal email account of FBI Director Kash Patel has been compromised by Handala hackers, a group associated with Iran. The breach resulted in the publication of photos and documents obtained from the director's inbox, marking a significant security incident targeting U.S. government leadership. The attack involved multiple malware variants including Hamsa, Handala, and Hatef. Source: FBI confirms hack of Director Patel's personal email inbox
Doctor.com Compromised by Infostealer and Qilin Ransomware
The healthcare platform Doctor.com has fallen victim to a serious infostealer infection that subsequently led to a ransomware attack by the Qilin group. This incident demonstrates the chained attack methodology where initial information-stealing malware creates an entry point for ransomware deployment against healthcare infrastructure. Source: ‼️🇺🇸 Doctor[.]com has a serious infostealer problem. They also just got claimed by Qilin Ransom...
File Read Vulnerability Impacts Hundreds of Thousands of WordPress Sites
A critical vulnerability identified as CVE-2026-3098 in the Smart Slider 3 WordPress plugin exposes arbitrary file access to subscriber-level users on affected servers. The plugin, active on more than 800,000 websites globally, places approximately 500,000 sites at immediate risk of exploitation through this file read flaw. The vulnerability stems from inadequate access controls that fail to properly restrict user permissions. Source: File read flaw in Smart Slider plugin impacts 500K WordPress sites
Threat Actor Sells AI-Powered MailPro Phishing Tool
A malicious actor is actively marketing MailPro, a sophisticated email campaign management panel that incorporates artificial intelligence capabilities for content optimization. The tool features SMTP integration, automated warm-up functionality, bulk mailing capabilities, server deployment options, proxy support, and comprehensive campaign analytics. This represents a concerning trend of lowering technical barriers for cybercriminals to conduct large-scale phishing operations. Source: ‼️ A threat actor claims to be selling MailPro, an email campaign management panel featuring AI-a...
These developments reflect an active threat environment where adversaries continue to target high-value assets while simultaneously developing and commercializing tools that democratize attack capabilities across the cybercriminal ecosystem.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- QilinRansomware group claiming responsibility for Doctor.com compromise
- Authenticated arbitrary file read vulnerability in Smart Slider 3 WordPress plugin affecting versions through 3.5.1.33
- MailProAI-assisted email campaign management panel sold by threat actor; used for bulk mailing, phishing, and spam operations