Handala Hits Stryker in Iranian Cyber Retaliation

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Handala launched a cyberattack on Stryker that disabled up to tens of thousands of computers, paralyzing much of the company’s global operations, and claimed it was retaliation for U.S. and Israeli strikes on Iran.
- Handala referenced the U.S. missile strike on a girl’s school in Minab, Iran, which killed at least 165 civilians, as justification for its cyber campaign against Western targets.
- Check Point identifies Handala as a front for Iran’s Ministry of Intelligence (MOIS), part of a broader state-sponsored hacking group it calls Void Manticore, which also operates under names like Red Sandstorm and Cobalt Mystique.
- Handala has claimed over a dozen victims since the war began, primarily in Israel, using destructive wiper malware like Coolwipe and Bibiwiper, often deployed through phishing and fake security updates.
- Stryker was targeted due to its acquisition of Israeli firm Orthospace and a $450 million U.S. military contract, according to Handala, though analysts suggest the breach may have been opportunistic rather than strategic.
- Void Manticore, linked to MOIS, previously targeted Albanian government agencies in 2022 under the name Homeland Justice, using data-destroying wiper malware in response to Iran’s diplomatic dispute with Albania.
- Handala used Starlink satellite internet to bypass Iranian internet blackouts and has publicly posted breach updates on Telegram and X, blending hacktivist branding with state-level cyber capabilities.
Why it matters: The Stryker breach marks a significant escalation in Iran’s cyber retaliation, shifting from symbolic attacks to disruptive operations on critical infrastructure. With tens of thousands of systems affected and ties to U.S. defense contracts, the incident raises stakes for Western firms facing state-backed hackers exploiting geopolitical conflict for operational impact.



