Handala Wiper is a custom destructive malware family associated with the Iranian MOIS-linked threat cluster tracked as Handala, Void Manticore, Red Sandstorm, and Banished Kitten. It has been used in destructive operations against organizations in Israel, Albania, and the United States, including activity tied to the March 2026 Stryker incident. The malware is described as a Windows wiper and is also referenced alongside related aliases or variants including win.handala and Hamsa Wiper in broader Handala tooling discussions.
High-confidence reporting in the provided content describes Handala Wiper as being deployed through Group Policy logon scripts and scheduled tasks, including via a batch file named handala.bat, often executed from a Domain Controller so the payload is not necessarily written to disk on every endpoint. Its destructive behavior includes overwriting file contents and corrupting or overwriting the Master Boot Record (MBR) to cause deep system damage. In some incidents the executable was named handala.exe. The actor has also used the wiper in parallel with other destructive methods, including a PowerShell-based wiper that deletes user directories and drops handala.gif, VeraCrypt-based disk encryption, and manual deletion of files and virtual machines.
Historical malware-analysis context in the content links Handala Wiper to a staged delivery chain using an NSIS-packaged dropper, an obfuscated batch script, an AutoIt3 loader, and injection into regasm.exe. The tooling also reportedly used a vulnerable driver in a BYOVD-style technique for privileged file operations, specifically ListOpenedFileDrv_32.sys loaded via OpenFileFinder.dll, and leveraged Regasm.exe for .NET injection. The malware performed host and network reconnaissance, including collecting hostname, username, domain, disk space, and public IP address via icanhazip.com, and exfiltrated victim details and undeleted-file information to a Telegram bot used as command-and-control. Reported anti-analysis or evasion behavior included checks for security products and delayed execution.
The content attributes use of Handala Wiper to the Handala Hack persona within the broader Void Manticore ecosystem, assessed with high confidence as MOIS-affiliated. Reported intrusion tradecraft around deployment includes compromised VPN credentials, brute force or credential stuffing, RDP-based lateral movement, AD reconnaissance, credential dumping, and use of NetBird for tunneling before destructive impact. Relevant indicators and artifacts directly mentioned in the content include filenames handala.exe, handala.bat, handala.gif, use of Regasm.exe, the vulnerable driver ListOpenedFileDrv_32.sys, and infrastructure such as 107.189.19.52 and 82.25.35.25.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Historically they deployed the Handala Wiper, an NSIS-packaged dropper using an AutoIt3 loader, a vulnerable driver (BYOVD) for privileged file operations, and Regasm.exe for .NET injection. That toolchain is still in use elsewhere. At Stryker they skipped it entirely and used Intune.
The first is the custom Handala Wiper, distributed via Group Policy logon scripts through a batch file named handala.bat. This wiper overwrites file contents and applies Master Boot Record (MBR) corruption for deep, low-level damage.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
During impact, Void Manticore combines multiple destructive methods: a custom Handala Wiper (sometimes handala.exe) with MBR-based wiping, distributed via Group Policy logon scripts and scheduled tasks...
The wiper was distributed across the network as a scheduled task using Group Policy logon scripts...
initiate destructive operations by dropping wiper malware families such as Handala Wiper and Handala PowerShell Wiper via Group Policy logon scripts.
The wiper was distributed across the network as a scheduled task using Group Policy logon scripts, which executed a batch file named handala.bat.
initiate destructive operations by dropping wiper malware families such as Handala Wiper and Handala PowerShell Wiper via Group Policy logon scripts.
The wiper was distributed across the network as a scheduled task using Group Policy logon scripts, which executed a batch file named handala.bat.
During impact, Void Manticore combines multiple destructive methods: a custom Handala Wiper (sometimes handala.exe) with MBR-based wiping, distributed via Group Policy logon scripts and scheduled tasks...
The wiper was distributed across the network as a scheduled task using Group Policy logon scripts...
Handala Destructive Wiper detection involves monitoring for suspicious activities such as ... the dropping of malicious drivers.
“Obfuscated Files or Information (T1027) …scatters garbage or invalid Windows commands among legitimate batch script instructions… effectively masks the true functionality of the script while allowing it to run as intended.”
Handala Destructive Wiper is a potent malware strain known for its destructive capabilities. It targets and irreversibly wipes data from infected systems, rendering them inoperable.
Handala Malware Capability: While OT/ICS disruption is not confirmed in this incident, Handala’s deployed toolkit includes custom wipers (win.handala, Handala Wiper, Hamsa Wiper) and MBR-overwriting capabilities.
Handala Malware Capability: While OT/ICS disruption is not confirmed in this incident, Handala’s deployed toolkit includes custom wipers (win.handala, Handala Wiper, Hamsa Wiper) and MBR-overwriting capabilities.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom wiper malware associated with Handala, described as capable of destructive operations including MBR overwriting.
A destructive wiper historically used by Handala, delivered via an NSIS-packaged dropper with AutoIt3, BYOVD, and Regasm-based .NET injection for privileged destructive operations.
Destructive wiper malware used by Handala-associated operators to erase data and disrupt operations, delivered via Group Policy logon scripts during destructive intrusions.
A custom destructive wiper used by Handala Hack that overwrites file contents and corrupts the MBR to make systems and data difficult to recover. It is distributed via Group Policy logon scripts and executed remotely from the Domain Controller so it is not written to disk on targeted machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.