logo

Dark Web Profile: Handala Hack

ID: eb3bd907-4ba1-53dd-93f3-8c84e162c331

STIX ID: report--eb3bd907-4ba1-53dd-93f3-8c84e162c331

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-03-13

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Handala (aka Handala_hack) is presented as a pro-Palestinian hacktivist persona but is assessed with high confidence to be a destructive cyber persona operated by Iran's Ministry of Intelligence and Security (MOIS). Since December 2023 the group has claimed dozens of attacks against Israeli, Gulf, and Western targets, using custom wiper families (e.g., BiBi Wiper, Hatef, Hamsa) and pragmatic intrusion chains (phishing, NSIS/AutoIT staging, process hollowing, and MDM abuse); its most significant claimed operation is a March 2026 campaign that allegedly wiped ~200,000 Stryker devices globally. The report details attribution, actor relationships (Scarred Manticore / Void Manticore), observed TTPs mapped to MITRE ATT&CK, notable incidents, and monitoring/mitigation services offered by SOCRadar.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.