logo

Handala and the release of strategic information regarding Israeli organizations

ID: 5716606a-fa61-58d9-80f0-f3ba381f3fd3

STIX ID: report--5716606a-fa61-58d9-80f0-f3ba381f3fd3

Feed Name: deepdarkCTI

Threat Score
78/100

Date Published: 2026-03-11

Date Updated: 2026-05-12

Author: fastfire

...
...

Handala is a pro‑Iran hacktivist group active since December 2023 conducting hack‑and‑leak and psychological operations against Israeli government, military, critical infrastructure, and private-sector targets. The group has publicly released ~184 personal profiles (including 50 Israeli Air Force profiles), operates via Telegram/X and data leak sites, and deploys destructive tools (COOLWIPE, CHILLWIPE), backdoors (ShadowCradle), and modular suites (CobaltDusk) while conducting phishing and exploit-based intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.