Stryker has suffered a major cyberattack involving wiper malware claimed by Handala, a pro-Palestinian hacktivist group linked to Iran.
Handala
Handala is a destructive malware designation associated with Iran-aligned disruptive operations and with a campaign that used politically themed social engineering against Israeli targets.
Profile source: Mallory opens in a new tabHandala
Family profile
Handala is a destructive malware designation associated with Iran-aligned disruptive operations and with a campaign that used politically themed social engineering against Israeli targets. The malware has been described primarily as a wiper capable of irreversibly destroying data and rendering infected systems inoperable. Reporting also links the name to a second-stage Delphi loader used in a multi-stage intrusion chain, indicating that Handala may refer both to a broader operation and to a specific loader component within that operation.
Observed delivery in the documented campaign relied on phishing themed around urgent security updates for F5 BIG-IP systems. On Windows, victims were induced to execute a disguised .NET updater from an archive, which extracted and launched additional payloads. On Linux, victims were instructed to run a shell command that fetched and executed a heavily obfuscated script. The Windows path could culminate in a wiper payload that overwrote files with random data and deleted them across major system and user directories on connected drives. The Linux path used a destructive script that delayed execution, profiled the host environment, removed user accounts, wiped home directories, destroyed partition structures, reformatted storage, deleted core system binaries, and rebooted the host to leave it unusable.
The intrusion chain also included a Delphi-coded second-stage loader referred to as Handala, which launched an AutoIt-based injector. That injector decrypted and decompressed shellcode and communicated with remote infrastructure, demonstrating a modular architecture beyond simple file destruction. Defensive reporting further notes suspicious AutoIt execution, malicious driver drops, unexpected regasm activity, abrupt system slowdowns, and creation of unknown files or processes as behaviors associated with Handala activity. The malware has also been characterized as capable of rapid spread across networks and of using evasion techniques.
Handala has been associated with disruptive and destructive incidents affecting organizations, including critical infrastructure and healthcare-adjacent entities. Public reporting tied the name to an attack on a medical technology organization involving both data exfiltration and destructive actions, and to a major claimed wiper incident affecting a multinational healthcare technology company. Because attribution around some Handala-branded operations remains contested, high-confidence characterization is strongest on its destructive wiping role, phishing-led delivery in at least one campaign, and use in politically motivated disruptive activity.
Capabilities
- Defense Evasion
- Exfiltration
Operational record
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK