Insights: Increased Risk of Wiper Attacks
2026-03-13T08:51:45Z•3b90b50d11025990fce6ce2936749a40ced06304302f15fbfa6a48381e8ef580
AI agentsAI prompt injectionBeyondTrustCL-UNK-1068China-linked espionageChrome GeminiHandala HackIvantiMicrosoft IntuneMuddled LibraNotepad++OT securityQR code phishingVoid Manticorecloud detectioncredential theftphishingsupply chain compromiseweb shellswiper attacks
What happened
Unit42 reports multiple high-risk trends and active campaigns: an increase in wiper attacks by Iran-linked Handala Hack (aka Void Manticore) leveraging phishing and Microsoft Intune misuse; China-linked espionage targeting military assets in Southeast Asia and prolonged operations (CL-UNK-1068, Muddled Libra) using custom backdoors, tunneling and credential theft; widespread exploitation of critical vulnerabilities including BeyondTrust RCE (CVE-2026-1731) with VShell and SparkRAT and Ivanti EPMM zero-days (CVE-2026-1281, CVE-2026-1340) leading to web shells and backdoors; a high-severity flaw
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 3b90b50d11025990fce6ce2936749a40ced06304302f15fbfa6a48381e8ef580
- Enrichment time
- 2026-03-13T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.