🔴 [LATEST] IRAN DEPLOYS 2 CYBER FRONTS: HANDALA TARGETS ISRAEL, CYBERAV3NGERS TARGETS US    ◆    🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS

~/Threat Intelligencearticle

Threat Intelligence

Iran Deploys 2 Cyber Fronts: Handala Targets Israel, CyberAv3ngers Targets US

> By Clara | Aug 19, 2026 | 7 min read

Iran is running two cyber fronts at once. On one side, Handala Hack Team is concentrating its digital pressure on Israel, wrapped in pro-Palestinian narratives. On the other, CyberAv3ngers has directed its operations across the Atlantic, striking directly at the backbone of United States critical infrastructure. Both groups are believed to originate from Iran’s cyber ecosystem, yet they operate with different doctrines, targets, and levels of technical maturity — a division of labor that lets Tehran project pressure on two geographic fronts simultaneously.

Iran Deploys 2 Cyber Fronts: Handala Targets Israel, CyberAv3ngers Targets US - CyberAsia Threat Intel Evidence

Activity from both groups has intensified sharply since open military conflict broke out between Iran, Israel, and the United States on February 28, 2026, through a joint operation named Operation Epic Fury. Since then, the cyber domain has become an additional battlefield alongside the ground and air confrontation already underway, with each front carrying its own distinct character.

> TABLE_OF_CONTENTS [toggle]

First Front: Handala Pressures Israel

On June 7, 2026, Handala announced via its official Telegram channel that it had successfully disrupted Israeli military signal networks and radar systems, while also claiming to have breached the digital government systems of the central Israeli town of Kfar Yona. The announcement came just as a two-month ceasefire between Israel and Iran collapsed, with both sides once again exchanging large-scale missile strikes. In its message, the group issued a dramatic warning that the day marked the beginning of a new phase of confrontation, describing its actions as an initial warning to Israel and its supporting nations.

A follow-up investigation by threat research firm SOCRadar, whose findings were shared with cybersecurity media, painted a far more limited picture than the initial narrative suggested. The screenshots Handala circulated as evidence of a radar system breach actually showed an administrative panel for an Interactive Voice Response (IVR) system belonging to a Tadiran Telecom Aeonix office phone system, not a military radar network as claimed. The finding reinforced a familiar pattern for Handala: inflating the technical impact of access that is, in reality, far more limited — a tactic commonly used by state-linked cyber actors to maximize psychological effect amid military escalation.

Handala’s targets have continued to expand across sectors: Israeli energy exploration firms, civilian healthcare systems, Jordan’s fuel networks, municipal telephone offices, and historic institutions such as Israel’s National Center for Support of Holocaust Victims, whose databases were breached on May 31, 2026, with thousands of documents and confidential correspondence extracted. The group has also carried its tactics into the United States, tied to a data-wiping incident via the Microsoft Intune device management platform that struck Stryker Corporation, a Michigan-based medical equipment manufacturer whose products are used by more than 150 million patients worldwide. The incident reportedly wiped data from more than 200,000 employee devices across 79 countries, making it one of the most significant wartime cyber incidents to hit a US entity.

Technically, Handala builds its campaigns on a combination of targeted phishing, wiper malware that overwrites data at random to render systems unbootable, and Telegram-based command-and-control infrastructure. The approach is relatively unsophisticated, yet operationally effective because it relies on social engineering and exploiting user carelessness — as seen when the group compromised the personal phone of a senior Israeli official in December 2025 and the personal email of a US law enforcement director in March 2026.

The group first surfaced in December 2023, shortly after the October 7 attacks, and has since been widely known as a hacktivist entity describing itself as independent and pro-Palestinian. However, several threat intelligence analysts assess Handala as one of several personas operated by Iran’s Ministry of Intelligence (MOIS), running alongside other personas such as KarmaBelow and Homeland Justice under an umbrella linked to Void Manticore and MOIS’s Counterterrorism Division. Since late April 2026, the “Handala” brand has even been tied to physical threats against Israeli law enforcement, intelligence, and military officials, including an arson incident targeting a security official’s vehicle carried out by an entity calling itself the Handala Popular Resistance Front.

Although the technical evidence behind Handala’s claims is often far smaller than the narrative it broadcasts, the psychological and reputational impact remains real, particularly when targets touch sensitive institutions such as a Holocaust memorial center or personal data belonging to military personnel. Doxxing Israeli air force pilots and Lockheed Martin employees, for instance, carries direct physical security risks for the individuals whose data is exposed publicly.

Second Front: CyberAv3ngers Targets US Infrastructure

Across the ocean, CyberAv3ngers has taken a more technical and physically direct approach. Throughout July 2026, the group has been linked to a coordinated attack that disrupted operations at more than 30 water treatment facilities in Minnesota, with similar activity patterns detected in several other US states. On August 3, 2026, CyberAv3ngers published a statement via its social media channels confirming its involvement in a series of operations against American critical infrastructure, while also signaling further operations to come.

The group consistently targets small and mid-sized operators in the US water and wastewater sector, a category of facilities researchers regard as among the weakest points in US critical infrastructure due to limited dedicated cybersecurity resources. Since March 2026, its targeting has expanded to programmable logic controllers (PLCs) made by Rockwell Automation/Allen-Bradley, and a CISA advisory update on July 22, 2026, added Schneider Electric and Siemens equipment to the list of potential targets. Beyond the water sector, the energy sector and government facilities have also been urged to raise their alert levels.

In terms of technical maturity, CyberAv3ngers sits a notch above Handala. Security firm Tenable found the group had compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland by exploiting factory-default passwords that operators never changed. Between 2024 and 2025, the group developed a malware toolkit called IOCONTROL, purpose-built to attack operational technology (OT) and Internet of Things (IoT) devices. Notably, OpenAI reported in 2024 that members of the group had used ChatGPT during the development of their tools. Many of the affected facilities were found to manage their OT environments using remote-access software such as TeamViewer and AnyDesk, or left their PLCs directly exposed to the public internet without additional safeguards.

CyberAv3ngers is tracked under several aliases, including Hydro Kitten, Storm-0784, APT Iran, Bauxite, Mr. Soul, Soldiers of Solomon, UNC5691, and the Shahid Kaveh Group. The group is assessed as affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) and has been active since 2020, with its first operational activity recorded in 2023 — including a breach of a water facility in Pittsburgh, Pennsylvania, which CISA attributed to the group at the time. Its pattern of operations reflects Iran’s broader strategy of using cyber capabilities as a tool of geopolitical pressure against an adversary’s vital infrastructure.

The risk posed by this second front is far more physically concrete, given its focus on industrial control systems that manage public water supplies. Disruption to PLCs at water facilities could trigger operational issues involving water pressure, treatment chemical dosing, or monitoring system failures, though US authorities have so far stated there is no evidence of direct impact on public drinking water quality. The expansion of targets to Schneider Electric and Siemens equipment also signals potential escalation toward the broader energy and manufacturing sectors.

Response and Mitigation on Both Fronts

US authorities responded to this second front fairly quickly. The Federal Bureau of Investigation (FBI), alongside CISA, the National Security Agency (NSA), the Environmental Protection Agency (EPA), the Department of Energy (DOE), and US Cyber Command’s Cyber National Mission Force (CNMF), issued a joint advisory urging critical infrastructure operators to immediately isolate their OT devices from other networks and apply urgent technical mitigations. Since July 27, 2026, at least seven states have reported related incidents to the FBI, with some confirming actual disruption to water operations. FBI Cyber Division Assistant Director Brett Leatherman reaffirmed the bureau’s commitment to identifying and imposing consequences on those responsible for attacks against US critical infrastructure.

On the first front, Israel’s response has focused more on public clarification and independent technical verification of each announcement from pro-Iranian groups, given the recurring pattern in which actual impact tends to be far smaller than the narrative circulated. This approach is important to prevent public opinion from escalating disproportionately relative to the adversary’s real capabilities.

Conclusion

The two cyber fronts Iran has deployed complement one another despite following different approaches. Handala relies on a combination of digital propaganda, data theft, and small-scale disruptions framed dramatically for maximum psychological effect against Israel. CyberAv3ngers takes a more technical path, striking directly at the physical backbone of US infrastructure and turning the water and energy sectors into a new battleground. For critical infrastructure operators in both countries, technical vigilance — from replacing factory-default passwords to isolating OT networks — remains the most practical line of defense as this two-front escalation shows no signs of slowing down.

Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Iran Deploys 2 Cyber Fronts: Handala Targets Israel, CyberAv3ngers Targets US is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Clara

Senior Threat Intelligence Analyst and former Cyber Policy Consultant focusing on geopolitical cyber warfare and data privacy.

> related_intel --suggest