Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
US Links Handala Hackers to Iranian Government

US Links Handala Hackers to Iranian Government

Posted on March 20, 2026 By CWS

The United States has officially established a link between the Handala hacker group and the Iranian government. This confirmation coincided with the dismantling of several websites utilized by the group.

Handala’s Cyber Activities

For years, Handala has been a subject of interest for cybersecurity experts. Recently, the group intensified its operations amid the ongoing US-Israel-Iran tensions. Handala has been accused of multiple cyber-attacks against Israel, including disrupting military weather servers, seizing control of security camera feeds, and exposing intelligence personnel details.

One of its most notorious attacks was against the US-based medical technology company Stryker, where the group caused significant disruption by erasing thousands of systems.

Handala’s Alleged Connections

While the group projects itself as a pro-Palestinian hacktivist entity driven by anti-Israel sentiments, experts widely perceive Handala as a façade for Void Manticore. This is believed to be an Iranian state-sponsored threat actor operating under Iran’s Ministry of Intelligence and Security (MOIS).

The US Justice Department has now verified this connection, following the seizure of four domains used by Handala for psychological warfare.

Seized Websites and Government Actions

Authorities have taken control of four domains: Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, and Handala-Redwanted[.]to. The Justice Department stated that Iran’s MOIS used these sites for psychological operations against regime adversaries, claiming responsibility for cyber-attacks, and inciting violence against journalists and regime critics.

Additionally, a social media account linked to the hacker group was suspended recently. The US Department of State is offering a reward of up to $10 million for information on foreign hackers targeting critical infrastructure.

Related operations have also targeted other cyber threats, such as the disruption of Aisuru and Kimwolf DDoS botnets, and dismantling the Tycoon 2FA phishing platform.

Security Week News Tags:cyber attacks, Cybersecurity, Hackers, Handala, Intelligence, Iran, Israel, MOIS, Stryker, US government

Post navigation

Previous Post: Magento Flaw Risks RCE and Account Security
Next Post: Critical Zero-Day in Cisco Products Exploited in Attacks

Related Posts

Microsoft Patches 86 Vulnerabilities – SecurityWeek Microsoft Patches 86 Vulnerabilities – SecurityWeek Security Week News
Insights from Sophos CISO Ross McKerchar Insights from Sophos CISO Ross McKerchar Security Week News
Enhancing Application Security in the AI Age Enhancing Application Security in the AI Age Security Week News
3.5 Million Affected by University of Phoenix Data Breach 3.5 Million Affected by University of Phoenix Data Breach Security Week News
640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack Security Week News
Data Breach Affects 250,000 at Nacogdoches Hospital Data Breach Affects 250,000 at Nacogdoches Hospital Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark