Lotus Wiper Hits Venezuela: When Cyber War Targets the Grid

Lotus Wiper has been quietly targeting Venezuelan energy and utility firms since late last year. This isn't about intelligence gathering; it's about disruption. When the goal is to stop the lights, the defensive playbook has to change.

Read More

Stryker Recovered from an Iranian Wiper Attack. It Took Three Weeks and 80,000 Devices.

Iran's Handala group wiped 80,000 devices across Stryker's global network. Maryland EMS lost digital ECG transmission. The DOJ confirmed Iran's government runs Handala.

Read More

Iran Is Running Every Cyberattack at Once

Iran isn't running a cyber campaign right now. It's running all of them simultaneously, and Unit 42's latest brief documents exactly that.

Read More

CanisterWorm: TeamPCP Hides Its C2 on a Blockchain You Can't Take Down

TeamPCP's new wiper, CanisterWorm, uses an ICP blockchain canister as its C2 resolver -- no domain to seize, no server to kill. And it now runs on any system, not just Kubernetes.

Read More

CanisterWorm: How TeamPCP Hijacked Your Security Scanners and Built an Untakeable Botnet

TeamPCP compromised Trivy and KICS CI/CD scanner tags, spread CanisterWorm to 47 npm packages, and deployed a Kubernetes wiper targeting Iranian timezones -- all controlled via blockchain C2 that can't be taken down.

Read More

Handala, Publicly Attributed: What the FBI Seizure Changes About Iran Cyber Signaling

The FBI seized Handala's sites and released a 40-page warrant formally linking the group to Iran's intelligence ministry. Attribution just moved from analyst opinion to federal court filing.

Read More

Iran Didn't Need Malware to Cripple Stryker. They Just Used Microsoft Intune.

The Handala group wiped tens of thousands of Stryker devices using the company's own MDM platform. No malware. No exploit. Just admin access and the willingness to press the button.

Read More

Hackers Used Stryker's Own IT Tool to Nuke Its Entire Device Fleet

An Iranian-linked group called Handala reportedly hijacked Microsoft Intune and wiped Stryker's devices at scale. The tool designed to secure their fleet became the weapon that destroyed it.

Read More