“Handala Hack” – Unveiling Group’s Modus Operandi
ID: 0398b247-52a9-54ae-969d-7c1bb8341783
STIX ID: report--0398b247-52a9-54ae-969d-7c1bb8341783
Feed Name: Check Point Research
This report profiles Handala Hack (Void Manticore), an Iranian MOIS‑linked APT persona responsible for destructive "hack-and-wipe" campaigns against Israel, Albania, and U.S. targets; it documents consistent hands-on TTPs (compromised VPN/valid accounts, RDP lateral movement, NetBird tunneling), multiple parallel wiping methods (custom MBR wiper, AI-assisted PowerShell deletion, VeraCrypt disk encryption, and manual deletion), provides hashes/IPs/hostnames as IOCs, and recommends mitigations such as enforcing MFA, hardening RDP, and monitoring for NetBird/Starlink activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
