The FBI seized two websites used by the pro-Iranian hacktivist group Handala after the group claimed responsibility for a destructive cyberattack against Stryker. The seized domains, including Handala’s leak and publicity sites, were replaced with a U.S. law enforcement banner stating the infrastructure was used to support malicious cyber activity conducted on behalf of, or in coordination with, a foreign state actor. Reporting indicates the domains’ nameservers were changed to FBI-controlled infrastructure, and Handala later acknowledged on Telegram that its sites had been taken offline.
The takedown followed a major intrusion into Stryker’s Microsoft environment that was described as highly destructive and involved abuse of legitimate endpoint management capabilities to wipe large numbers of devices and exfiltrate data. Public reporting differs on the scale of the impact, with estimates ranging from roughly 80,000 to 200,000 affected systems, while CISA said the incident should be treated as a warning that cyber activity tied to Middle East conflict may spill into U.S. organizations. CISA urged defenders to harden platforms such as Microsoft Intune by enforcing least privilege, role-based access controls, phishing-resistant MFA, and approval workflows for sensitive actions such as device wiping.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
The FBI warned that Handala and Homeland Justice, linked to Iran’s MOIS, used Telegram as command-and-control infrastructure in malware campaigns targeting journalists critical of Iran, Iranian dissidents, and other opposition groups worldwide. The campaigns reportedly relied on social engineering and Windows malware to steal screenshots and files for intelligence collection, data leaks, and reputational harm.
Court documents and U.S. authorities said the seized MOIS/Handala-linked domains were also tied to Iran's 2022 cyberattacks on Albania, which disrupted government services and exposed government email data. Authorities also announced a $10 million reward for information on those responsible, signaling an expanded ongoing investigation into Iranian cyber operations.
The U.S. Justice Department said Iran’s Ministry of Intelligence and Security operates the Handala persona for cyberattacks, influence operations, and publishing stolen data. DOJ and FBI also said Handala, Justice Homeland, and Karma Below are part of the same conspiracy, expanding the public attribution of the group behind the Stryker attack.
After the domain seizures, Handala said on Telegram that the takedown had occurred, noted its X account had been suspended, and indicated it was building new infrastructure. Analysis assessed the seizure as a temporary disruption rather than a lasting operational setback.
U.S. authorities seized the domains handala-hack.to and handala-redwanted.to under a warrant, replacing them with notices alleging the sites supported malicious cyber activities on behalf of or in coordination with a foreign state actor. The sites included Handala's leak and publicity infrastructure.
Post-incident guidance from Microsoft and CISA advised organizations to harden Windows domains and protect Microsoft Intune against similar abuse. The recommendations focused on preventing misuse of legitimate administrative tools and privileged actions.
After the Stryker incident, CISA warned that the attack may signal spillover from Middle East-linked cyber activity into U.S. organizations. The agency urged organizations to secure endpoint management systems such as Microsoft Intune with least privilege, role-based access controls, phishing-resistant MFA, Entra ID protections, and multi-admin approval for sensitive actions.
Following the attack, Handala said it had stolen 50 terabytes of data from Stryker and wiped more than 200,000 devices. The incident reportedly also affected Stryker employees in Ireland, while the company said it was still restoring computers and its internal network.
In the Stryker incident, attackers reportedly compromised privileged accounts, created or used high-level administrator access, took over Microsoft Intune management, and used legitimate wipe functionality to reset devices at scale. Reports say the attack affected tens of thousands to more than 200,000 systems, servers, and mobile devices, including some employee-managed personal devices.
By 2026, Handala's operations expanded beyond Israeli targets to include U.S.-based medical technology company Stryker. The group claimed responsibility for a destructive intrusion into Stryker's internal Microsoft environment.
According to the new report and an FBI affidavit, Handala allegedly compromised Stryker's Active Directory on March 11, 2026. The intrusion caused ongoing disruption to ordering and shipping and reportedly interfered with some emergency medical care workflows at Maryland hospitals.
Handala began operating in late 2023, initially targeting Israeli organizations and presenting itself as a hacktivist group. Multiple reports assess the group as Iranian-linked and likely aligned with state-backed cyber activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
12 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceitpro.com
Open sourcetherecord.media
Open sourcetechcrunch.com
Open sourceflare.io
Open sourcetechcrunch.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.