The United States Department of Justice has seized four domains linked to Iran-related cyberattacks. Officials described the attacks as a coordinated effort to combine hacking with online terror propaganda. The domains—Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, and Handala-Redwanted[.]to—were allegedly operated by Iran’s Ministry of Intelligence and Security (MOIS).

According to researchers, these websites were used to claim responsibility for cyberattacks, publish stolen data , and issue threats targeting journalists, dissidents, and individuals affiliated with Israel. This action highlights a shift in the way cyberattacks are being carried out —moving beyond system breaches to public messaging and pressure tactics.
See also: Iran was preparing cyberattacks before Epic Fury
Iranian cyber attacks use fake hacktivist fronts
Authorities say the domains were connected through shared infrastructure, including Iranian IPs and shared leak platforms. They also followed a similar pattern of activity.
The websites operated under the guise of hacker groups, but researchers say they were part of a state-sponsored effortthat included launching disruptive cyberattacks, leaking sensitive data , and amplifying the impact with public accountability.
One such platform, Handala-hack[.]to, was used to claim responsibility for a malware attack on a US-based medical technology company. The group presented the attack as retaliation linked to ongoing geopolitical tensions.
This combination of hacking and messaging is becoming a hallmark of cyberattacks linked to Iran, where the goal is not only access, but also visibility.

Data leaks and threats directly target individuals
The same infrastructure was also used to expose personal information and issue threats. According to court documents, the domain Handala-redwanted[.]to published identifying information for nearly 190 individuals associated with the Israel Defense Forces and the government. The posts included messages suggesting that these individuals were being monitored and could face consequences.
See also: Russian hackers target Ukraine via Zimbra vulnerability
Other posts named individuals allegedly connected to Israeli institutions, warning that their locations were known and encouraging others to take action. In another case, the group claimed to have stolen 851 gigabytes of data from members of the Sanzer Hasidic Jewish community, along with a warning that more information would follow. These actions show how Iran-linked cyberattacks are increasingly targeting individuals, not just organizations.
The threats expanded beyond the websites
Researchers found that the campaign did not stop at public postings.
Email accountslinked to the same business were used to send direct threats to journalists and Iranian dissidents living in the United States and abroad. In some messages, the senders claimed to have shared the home addresses of the victims and offered monetary rewards for acts of violence. The emails also mentioned alleged connections to criminal groups, adding another layer of intimidation.
The use of direct communication alongside public leaks suggests a more aggressive approach to Iran-linked cyberattacks, where the goal is to pressure targets both publicly and privately.
The DoJ targets the infrastructure behind the cyber attacks
The Justice Department's move focused on dismantling the infrastructure that enables these activities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: China tops America's cyber threat list

“Terrorist propaganda online can cause real violence around the world — thanks to the Department of Homeland Security and the U.S. Attorney’s Office for the District of Maryland, this network of Iranian websites will no longer be spreading anti-American hatred,” said Attorney General Pamela Bondi. FBI Director Kash Patel added, “Iran thought it could hide behind fake websites and keyboard threats to terrorize Americans and silence dissent. We have taken down four of the pillars of their operation, and we are not done. The FBI will hunt down every perpetrator behind these cowardly death threats and cyberattacks and bring the full force of American law enforcement to bear on them.”
Officials also confirmed that the domains Justicehomeland[.]org and Karmabelow80[.]org had previously been used to claim responsibility for data theft targeting Albanian government systems.
The takedown reflects a broader pattern. Iran-linked cyberattacks are no longer limited to stealing data or disrupting systems—they are used to send messages, target individuals, and amplify political narratives. By combining cyberattacks with data leaks and direct threats, these campaigns extend their reach beyond technical impact.
