Dark Web Profile: Handala Hack
ID: eb3bd907-4ba1-53dd-93f3-8c84e162c331
STIX ID: report--eb3bd907-4ba1-53dd-93f3-8c84e162c331
Feed Name: SOCRadar Blog
Handala (aka Handala_hack) is presented as a pro-Palestinian hacktivist persona but is assessed with high confidence to be a destructive cyber persona operated by Iran's Ministry of Intelligence and Security (MOIS). Since December 2023 the group has claimed dozens of attacks against Israeli, Gulf, and Western targets, using custom wiper families (e.g., BiBi Wiper, Hatef, Hamsa) and pragmatic intrusion chains (phishing, NSIS/AutoIT staging, process hollowing, and MDM abuse); its most significant claimed operation is a March 2026 campaign that allegedly wiped ~200,000 Stryker devices globally. The report details attribution, actor relationships (Scarred Manticore / Void Manticore), observed TTPs mapped to MITRE ATT&CK, notable incidents, and monitoring/mitigation services offered by SOCRadar.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
