BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
NERF
The Vault
Threat Actors
Privacy Threats
Malware IoC
Dashboard
CVEs
Tags
Intel
NERFThe VaultThreat ActorsPrivacy ThreatsMalware IoCDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Iran-Linked Handala Breaches Israeli Defense Contractor, UAC-0255 Spreads AGEWHEEZE via CERT-UA Impersonation

Iran-Linked Handala Breaches Israeli Defense Contractor, UAC-0255 Spreads AGEWHEEZE via CERT-UA Impersonation

highNation-State & APT|April 3, 20262 min read

Originally reported by Security Affairs, The Record

#iran#handala#israel#defense-contractor#uac-0255#agewheeze#cert-ua#phishing
Share

TL;DR

Pro-Iran Handala group claimed breach of Israeli air defense contractor PSK Wind Technologies, which develops command and control systems. Separately, UAC-0255 conducted large-scale phishing campaign impersonating CERT-UA to distribute AGEWHEEZE malware to approximately one million users.

Why high?

The breach of Israeli defense contractor PSK Wind Technologies by Iran-linked Handala represents a significant compromise of critical infrastructure and military systems. The targeted nature of the attack on command and control systems for air defense elevates this to high severity.

Iran-Linked Handala Breaches Israeli Defense Contractor

The pro-Iran Handala group announced on April 2 that it successfully breached PSK Wind Technologies, an Israeli engineering and IT firm specializing in integrated systems for defense and critical communications. PSK Wind develops command and control solutions for air defense systems, making this breach particularly significant for Israeli national security infrastructure.

The company provides specialized systems for defense contractors and operates in the critical communications sector. Security Affairs reports the breach represents another escalation in cyber operations between Iran-linked groups and Israeli infrastructure targets.

UAC-0255 Impersonates CERT-UA in Mass Phishing Campaign

Threat actor UAC-0255 conducted a sophisticated phishing campaign impersonating Ukraine's Computer Emergency Response Team (CERT-UA), targeting approximately one million users. The attackers sent emails urging victims to download password-protected archives from Files.fm and install what they claimed was "specialized software" for security purposes.

The malicious payload was identified as AGEWHEEZE malware, distributed through the fake security tool installation process. The campaign demonstrates the continued use of trusted cybersecurity organizations as impersonation vectors to increase victim compliance rates.

Hasbro Reports Cyberattack and Operational Disruption

Toy manufacturer Hasbro disclosed a cyberattack on Wednesday that disrupted certain company operations. The company is currently investigating the full scope of the incident, including potential data compromise, while working to restore normal business functions.

Hasbro has not yet disclosed the attack vector or whether customer data was affected. The company continues its investigation to determine what files or sensitive information may have been accessed during the breach.

French Senate Passes Child Social Media Ban

The French Senate passed legislation that would ban children under 15 from accessing social media platforms. If enacted, France would become the first European country to implement such restrictions, following Australia's similar approach to protecting minors online.

The bill represents a significant regulatory shift in how European nations approach social media platform governance and child protection in digital spaces.

Sources

  • https://securityaffairs.com/190319/data-breach/pro-iran-handala-group-breached-israeli-defence-contractor-psk-wind-technologies.html
  • https://securityaffairs.com/190287/hacking/threat-actor-uac-0255-impersonate-cert-ua-to-spread-agewheeze-malware-via-phishing.html
  • https://securityaffairs.com/190306/security/hasbro-hit-by-cyberattack-investigates-possible-data-breach.html
  • https://therecord.media/french-senate-passes-bill-child-ban-social-media

Originally reported by Security Affairs, The Record

Tags

#iran#handala#israel#defense-contractor#uac-0255#agewheeze#cert-ua#phishing

Related Intelligence

  • Nation-State Roundup: Iran's Handala Wiper Campaign Escalates, China Targets Southeast Asian Military

    highMar 13, 2026
  • Nation-State Roundup: Iran-linked Handala Targets FBI Director, ShinyHunters Breaches EU Commission, Apple Warns of Active Web Exploits

    highMar 29, 2026
  • Nation-State Activity Roundup: Iranian Actors Hit Stryker, Dutch Finance Ministry Breached, Critical NetScaler Flaw

    highMar 25, 2026

Related Knowledge

  • Threat Intelligence Deep Training

    reference
  • MITRE ATT&CK / D3FEND Deep Reference

    reference
  • NERF Training: Emerging Threats Deep Dive (2025-2026)

    reference

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Privacy Surveillance Roundup: Secret Zoom Recording Service, US Router Ban, and CBP Security Leaks

Next Article

Google Details Continuous Defense Strategy Against AI Indirect Prompt Injection Attacks→