U.S. accuses Iran’s government of operating hacktivist group that hacked Stryker
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述就行。好的,首先我得仔细阅读这篇文章,了解主要信息。 文章主要讲的是美国司法部指控伊朗政府支持黑客组织Handala,他们最近对美国医疗科技巨头Stryker发动了网络攻击。司法部指出,Handala实际上是伊朗情报和安全部门MOIS用来进行心理战和发布被盗信息的假扮活动。此外,FBI已经查封了Handala的两个网站,并且还关联到另一个黑客组织Justice Homeland。 接下来,我需要把这些关键点浓缩到100字以内。要包括指控方、被指控方、攻击目标、背后的机构以及FBI的行动。同时要保持语言简洁明了。 可能的结构是:美国司法部指控伊朗政府支持Handala黑客组织对Stryker发动网络攻击,并通过该组织进行心理战和发布信息。FBI已查封相关网站,并关联到另一个由伊朗情报部门控制的组织。 这样大概在100字左右,符合用户的要求。 </think> 美国司法部指控伊朗政府支持黑客组织Handala对医疗科技公司Stryker发动网络攻击,并通过该组织进行心理战和发布被盗信息。FBI已查封Handala相关网站,并关联到另一个由伊朗情报部门控制的黑客组织。 2026-3-20 16:50:38 Author: techcrunch.com(查看原文) 阅读量:6 收藏

The U.S. Justice Department accused Iran’s government of being behind the hacktivist group Handala, which last week claimed responsibility for the destructive cyberattack against the U.S. medical tech giant Stryker. 

In a press release published on Thursday, the Justice Department said Iran’s Ministry of Intelligence and Security (MOIS) is operating Handala. 

The Justice Department called the group a fake activist persona that the Iranian ministry used to carry out “psychological operations” against the regime’s enemies, to claim responsibility for cyberattacks, and to publish stolen information obtained during those hacks. The group also called for the killing of journalists, regime dissidents, and Israeli persons, per the DOJ. 

The announcement came hours after the FBI seized two websites linked to Handala, as first reported by TechCrunch. The group used the websites to publicize its alleged cyberattacks, as well as to publish the personal information of dozens of people who allegedly worked for the Israeli military and defense contractors. 

Handala took credit on its website for the March 11 cyberattack on Stryker, during which the hackers remotely wiped tens of thousands of employee devices. The hackers said the breach was in retaliation for a U.S. air strike on an Iranian school, which killed 168 children, according to Iranian officials.

FBI director Kash Patel was quoted in the DOJ’s press release as saying that the FBI “took down four of their operation’s pillars and we’re not done.”

Apart from the two websites used by Handala, the DOJ also seized two other domains allegedly used by Iran’s MOIS via another hacktivist persona calling themselves “Justice Homeland” or “Homeland Justice.” The DOJ accused Iranian government hackers of using those two domains to claim responsibility for hacking the Albanian government in 2022, in a cyberattack that resulted in government servers being taken offline and the theft of sensitive data. Microsoft also linked the attack against the Albanian government to the MOIS.

In an affidavit submitted in court to support the seizure of Handala’s websites, the FBI said that Handala, Justice Homeland, and another hacktivist persona called Karma Below, “are part of the same conspiracy because they are operated by the same individuals.”

Contact Us

Do you have more information about Handala, or other Iran-linked hacking operations? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or by email.

Handala responded to the DOJ’s announcement in a statement posted on its official Telegram channel, where the hackers called the U.S. government actions “nothing more than the latest desperate attempts by the United States and its allies to silence the voice of Handala.”

DomainTools’ cybersecurity researcher Keith O’Neill told TechCrunch that Handala has already set up new domains that have not yet been seized.

The hacking group did not respond to a request for comment sent to a chat account publicized by the hackers, as well as an email address identified by the Justice Department in its affidavit. 

A spokesperson for Iran’s Permanent Mission to the United Nations did not respond to TechCrunch’s request for comment. Stryker also did not respond to a request for comment.

Alex Orleans, the head of threat intelligence at Sublime Security who has tracked Iranian hackers for years, told TechCrunch that it is possible that the people behind the Handala persona are not the same individuals doing the actual hacking. 

“Handala does not necessarily equate, one-to-one, with the actors conducting the activities it’s taking credit for,” said Orleans. “There could be multiple teams conducting actual intrusions while a distinct team is responsible for maintaining the persona — with all of these distinct elements coexisting within a larger unified MOIS element.”

“There’s a level of opacity there that can be difficult to penetrate,” he said.

Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.

You can contact or verify outreach from Lorenzo by emailing [email protected], via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

View Bio


文章来源: https://techcrunch.com/2026/03/20/u-s-accuses-irans-government-of-operating-hacktivist-group-that-hacked-stryker/
如有侵权请联系:admin#unsafe.sh