Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack

Handala Hack, a group linked to Iranian intelligence, breached FBI Director Kash Patel's personal email and launched a destructive wiper attack against Fortune 500 medical firm Stryker.
Threat actors with ties to Iran successfully broke into the personal email account of Kash Patel, the director of the U.S. Federal Bureau of Investigation (FBI), and leaked a cache of photos and other documents to the internet.
Handala Hack Team, which carried out the breach, said on its website that Patel "will now find his name among the list of successfully hacked victims." In a statement shared with Reuters, the FBI confirmed Patel's emails had been targeted, and noted necessary steps have been taken to "mitigate potential risks associated with this activity."
The agency also said the published data was "historical in nature and involves no government information." The leak includes emails from 2010 and 2019 allegedly sent by Patel.
Handala Hack is assessed to be a pro-Iranian, pro-Palestinian hacktivist persona adopted by Iran's Ministry of Intelligence and Security (MOIS). It's tracked by the cybersecurity community under the monikers Banished Kitten, Cobalt Mystique, Red Sandstorm, and Void Manticore, with the group also operating another persona called Homeland Justice to target Albanian entities since mid-2022.
Data gathered by StealthMole has revealed that Handala's online presence extends beyond messaging platforms and cybercrime forums like BreachForums to publicize its activities, maintaining a layered infrastructure that includes surface web domains, Tor-hosted services, and external file-hosting platforms such as MEGA.
"Handala has consistently targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access," Check Point said in a report published this month. "Throughout the last months, we identified hundreds of logon and brute-force attempts against organizational VPN infrastructure linked to Handala-associated infrastructure."
Attacks mounted by the proxy group are known to leverage RDP for lateral movement and initiate destructive operations by dropping wiper malware families such as Handala Wiper and Handala PowerShell Wiper via Group Policy logon scripts. Also used are legitimate disk encryption utilities like VeraCrypt to complicate recovery efforts.
"Unlike financially motivated cybercriminal groups, Handala-associated activity has historically emphasized disruption, psychological impact, and geopolitical signaling," Flashpoint said. "Operations attributed to the persona frequently align with periods of heightened geopolitical tension and often target organizations with symbolic or strategic value."
The development comes against the backdrop of the U.S.-Israel-Iran conflict, prompting Iran to go on a retaliatory cyber offensive against Western targets. Notably, Handala Hack claimed credit for crippling the networks of medical devices and services provider Stryker by deleting a huge trove of company data and wiping thousands of employee devices. The attack is the first confirmed destructive wiper operation targeting a U.S. Fortune 500 company.
In an update issued on its website this week, Stryker said "the incident is contained," adding it "reacted quickly to not only regain access but to remove the unauthorized party from our environment" by dismantling the persistence mechanisms installed. The breach, it stated, was confined to its internal Microsoft environment.
Palo Alto Networks Unit 42 said the primary vector for recent destructive operations from Handala Hack likely involves the "exploitation of identity through phishing and administrative access through Microsoft Intune."
In the wake of the breach, both Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA) have released guidance on hardening Windows domains and fortifying Intune to defend against similar attacks. This includes using the principle of least privilege, enforcing phishing-resistant multi-factor authentication (MFA), and enabling multi-admin approval in Intune for sensitive changes.
Handala Hack's leak of Patel's personal emails comes in response to a court-authorized operation that led to the seizure of four domains operated by MOIS since 2022 as part of an effort to disrupt its malicious activities in cyberspace. The U.S. government is also offering a $10 million reward for information on members of the group.
Source: The Hacker News















