logo

“Handala Hack” – Unveiling Group’s Modus Operandi

ID: 0398b247-52a9-54ae-969d-7c1bb8341783

STIX ID: report--0398b247-52a9-54ae-969d-7c1bb8341783

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-03-12

Date Updated: 2026-04-27

Author: matthewsu

...
...

This report profiles Handala Hack (Void Manticore), an Iranian MOIS‑linked APT persona responsible for destructive "hack-and-wipe" campaigns against Israel, Albania, and U.S. targets; it documents consistent hands-on TTPs (compromised VPN/valid accounts, RDP lateral movement, NetBird tunneling), multiple parallel wiping methods (custom MBR wiper, AI-assisted PowerShell deletion, VeraCrypt disk encryption, and manual deletion), provides hashes/IPs/hostnames as IOCs, and recommends mitigations such as enforcing MFA, hardening RDP, and monitoring for NetBird/Starlink activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.