Iran-Linked Wiper Wave Targets Global Networks via Identity Attacks

Unit 42 warns of a rising risk of wiper attacks tied to the Iran conflict, led by Handala Hack (aka Void Manticore) using phishing and compromised admin access via Microsoft Intune to disrupt networks in Israel and the US; Israel's National Cyber Directorate reports cases where attackers used legitimate credentials to delete servers. The advisory outlines zero trust privileged access, Just-In-Time admin rights, MFA, break-glass accounts, PIM/PAM, MAA, RBAC with Intune Admin roles, and Group-based PIM; plus shorter session lifetimes, token protection, DSPM/DLP, MDR/XDR monitoring, offline immutable backups, and ongoing phishing training. If compromised, contact incident response teams.
- Insights: Increased Risk of Wiper Attacks Unit 42
- Hackers join U.S. and Israel's fight with Iran Axios
- Iran-linked hackers take aim at U.S. and other targets, raising risk of cyberattacks during war PBS
- What role has cyber warfare played in Iran? BBC
- US intelligence community ramps up warnings of possible retaliatory attacks by Iran CNN
Reading Insights
0
10
5 min
vs 6 min read
91%
1,058 → 98 words
Want the full story? Read the original article
Read on Unit 42