The Iranian hacker group Handala, which was behind the infamous cyberattack on the American MedTech company Stryker, is back online a few hours after the FBI announced the seizure of their clearnet domains.
See also: US takes down sites linked to Iranian cyberattacks

On Thursday, the FBI announced that domains associated with Iranian hacker groups—Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, and Handala-Redwanted[.]to—which allegedly serve as fronts for Iran’s Ministry of Intelligence and Security (MOIS)—have been seized and are inaccessible. Law enforcement said these websites were used for “name and shame” purposes and to issue threats against journalists, dissidents, and individuals associated with Israel.
According to court documents, all of these domains were operated by the “same individuals” (MOIS) and were part of the “same conspiracy.” The Handala hackers acknowledged the seizure by law enforcement on their Telegram channel, posting screenshots of their domain information and name servers now listed as seized by the FBI (ns1[.]fbi[.]seized[.]gov).
Οι Ηandala ισχυρίστηκαν ότι αυτή η πράξη ήταν τακτική των αντιπάλων τους για να ‘διαγράψουν’, ‘κρύψουν’ και να επιβάλουν ‘λογοκρισία’ στις φωνές τους και ότι οι προσπάθειές τους ‘θα συνεχιστούν σε νέες πλατφόρμες’. Εντυπωσιακά, οι ισχυρισμοί για ψηφιακή καταπίεση από τους αντιπάλους τους έρχονται εν μέσω των προσπαθειών του Ιράν για λογοκρισία του Διαδικτύου σε όλη τη χώρα που έχει εισέλθει στην 21η ημέρα.
See also: Stryker: Iranian hackers used stolen credentials

Within hours, however, the threat group released another statement on their Telegram channel announcing the launch of their new domain infrastructure at handala-hack[.]ps . The quick response suggests that the hackers want to maintain operational continuity, researchers from threat intelligence firm Cyble said .
With relatively ‘moderate’ confidence, researchers say that these claims may be true as the domains referenced in the messages are redirected to a clearnet website that resembles the one the hackers Handala had before the seizure by the FBI.
Although the Handala hackers have been spearheading MOIS since 2023, the group became its face in the recent conflict when it attacked US medtech company Strykerearlier this month. The hackers claimed to have wiped more than 200,000 devices and extracted petabytes of data, but the company, while acknowledging the attack, said the incident was limited to the Microsoft environment and was resolved without impacting its customers.
See also: CRIL: Growing threat of cyberattacks in the Middle East

In a Thursday update, Stryker praised the FBI's seizure, stating: 'We are grateful to the government for their efforts to seize domains associated with alleged threat actors.'
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
