Iran-Linked Wiper Wave Targets Global Networks via Identity Attacks

1 min read
Source: Unit 42
Iran-Linked Wiper Wave Targets Global Networks via Identity Attacks
Photo: Unit 42
TL;DR Summary

Unit 42 warns of a rising risk of wiper attacks tied to the Iran conflict, led by Handala Hack (aka Void Manticore) using phishing and compromised admin access via Microsoft Intune to disrupt networks in Israel and the US; Israel's National Cyber Directorate reports cases where attackers used legitimate credentials to delete servers. The advisory outlines zero trust privileged access, Just-In-Time admin rights, MFA, break-glass accounts, PIM/PAM, MAA, RBAC with Intune Admin roles, and Group-based PIM; plus shorter session lifetimes, token protection, DSPM/DLP, MDR/XDR monitoring, offline immutable backups, and ongoing phishing training. If compromised, contact incident response teams.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

5 min

vs 6 min read

Condensed

91%

1,05898 words

Want the full story? Read the original article

Read on Unit 42