Iran-Linked Handala Hackers Launch New Domain Hours After FBI Seized the Older One
好,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户给了一篇关于伊朗黑客组织Handala Hack Team的文章,内容涉及FBI查封其域名,黑客随后在Telegram上承认并转移至新域名,以及对Stryker公司的网络攻击情况。 首先,我得通读整篇文章,抓住主要信息点。FBI查封了Handala的相关域名,这些域名被指控为伊朗情报机构的幌子。Handala随后在Telegram上承认,并表示会转移到新平台继续活动。同时,他们提到了伊朗国内的网络审查情况。此外,文章还提到Handala对Stryker公司的攻击及其影响。 接下来,我需要将这些信息浓缩到100字以内。重点包括:FBI查封域名、Handala转移至新域名、伊朗网络审查、对Stryker的攻击及其影响。 现在开始组织语言,确保简洁明了。例如:“FBI查封伊朗黑客组织Handala相关域名后,该组织迅速转移至新平台继续活动,并指责对手压制其声音。同时,伊朗国内持续实施网络审查。此前,Handala声称对美国医疗科技公司Stryker发动大规模网络攻击。” 这样大约控制在100字左右。 最后检查是否有遗漏的重要信息点,并确保语句通顺、准确。 </think> FBI查封伊朗黑客组织Handala相关域名后,该组织迅速转移至新平台继续活动,并指责对手压制其声音。同时,伊朗国内持续实施网络审查。此前,Handala声称对美国医疗科技公司Stryker发动大规模网络攻击。 2026-3-20 13:51:11 Author: thecyberexpress.com(查看原文) 阅读量:12 收藏

Handala, Stryker Cyberattack, Iran Israel War, Handala Hackers

Iranian hacker group Handala Hack Team, the collective behind the famed cyberattack on U.S. MedTech firm Stryker, is back online just hours after the FBI announced its clearnet domains seizure.

On Thursday, FBI’s official announcement said that the domains connected to Iranian hacker groups—Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, and Handala-Redwanted[.]to—which are allegedly a front for Iran’s Ministry of Intelligence and Security (MOIS) were seized and unreachable. Law enforcers said these sites were used for ‘name and shame’ purposes and issuance of threats to journalists, dissidents, and individuals linked to Israel.

Read: U.S. Shuts Down Websites Behind Iran-Linked Cyber Attacks and Death Threats

As per the court documents, all these domains were operated by “same individuals” (MOIS) and were a part of the “same conspiracy.”

Handala Hackers Post Acknowledgement on Telegram

Handala hackers acknowledged the law enforcement seizure on their Telegram channel putting screenshots of their domain information and name servers that now read seized by FBI (ns1[.]fbi[.]seized[.]gov).

Handala Domain Seizure Acknowledgement 1
Handala Hack Team acknowledges FBI’s domain seizure on its Telegram channel. (Image: Cyble Vision)

Handala claimed that this act was the tactics of its adversaries to “erase,” “hide,” and enforce “censorship” on its voices and that their efforts “will continue on new platforms.”

Strikingly, the claims of digital repression from its adversaries come amid Iran’s own efforts of country-wide Internet censorship that has entered the 21st day.

report-ad-banner

Internet censorship in Iran 21st day
Internet remains blocked in Iran for over 480 hours (Image: Netblocks.org)

Within hours, the threat group, however released another statement on their Telegram channel announcing the launch of its new domain infrastructure at handala-hack[.]ps. The quick turn-around suggests the hackers want to maintain operational continuity, said researchers at threat intelligence company Cyble.

Handala New Domain
Telegram announcement from Handala of new domain (Source: Cyble Vision)

With a fairly “moderate” confidence, researchers say these claims may hold true as the domains named in the messages are re-routing to a clearnet website that looks similar to the one Handala hackers had prior to FBI’s seizure. The Cyber Express reached out to the respective law enforcement offices for a statement on the latest turn of events but has not received any comment, as of the time of publishing this article.

Stryker Acknowledges the Takedown

Although Handala has been front ending for MOIS since 2023, the group became its face in the recent conflict when it attacked the U.S.-based MedTech company Stryker, earlier this month. Handala claimed it wiped more than 200,000 devices and siphoned petabytes worth of data but the company although acknowledging the attack, said the incident was limited to its Microsoft environment and was contained with no impact to its customers.

Read: Who Is Handala — The Iran-Linked Ghost Group That Just Wiped 200K Stryker Devices

In a Thursday update, Stryker appreciated FBI’s takedown stating: “We’re grateful to the government for their efforts to seize domains linked to the purported threat actors.”

The company had earlier said that its supply chain was however impacted in the attack and restoration was undertaken. In the latest update it reiterated the same saying restoration efforts had made “significant progress” but some of its personalized implants customers were still experiencing some disruptions that were being taken on priority.

Read: Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

文章来源: https://thecyberexpress.com/handala-hackers-launch-new-domain/
如有侵权请联系:admin#unsafe.sh