Grupo hacktivista

Handala Team

Handala (often branded as Handala Hack Team / Handala Hack) is a pro-Palestinian, Iran-aligned cyber actor that emerged around December 2023, shortly after the outbreak of the Israel–Hamas war. While initially framed as another “hacktivist” outfit running DDoS and simple website attacks, multiple government and private-sector assessments now attribute Handala to Iran’s Ministry of Intelligence (MOIS), tracked in some taxonomies as Storm-0842 / Banished Kitten / Void Manticore, i.e. a state-directed psychological warfare unit masquerading as a grassroots collective.

Handala’s activity focuses overwhelmingly on Israeli targets (and, to a lesser extent, foreign entities linked to Israel), including government, defense, healthcare, high-tech, telecom, transportation, and education sectors. Their core pattern is “hack-and-leak with psy-ops”: compromise, selective data theft, release of mixed authentic and fabricated data, and aggressive messaging aimed at eroding public trust in Israeli institutions, senior officials and security services rather than monetizing access.

Technically, Handala has demonstrated mid-to-high capability: phishing and spear-phishing, exploitation of internet-facing systems, ransomware-style encryption and extortion (with political rather than financial demands), custom wipers (e.g. Hatef for Windows, Hamsa for Linux), and opportunistic use of crises such as the CrowdStrike global outage by pushing fake “CrowdStrike fixes” that delivered wiper payloads. Their operational tempo has been sustained: some Israeli and academic sources count dozens of attacks between early 2024 and early 2025, including repeated campaigns against sensitive datasets (gun license records, justice ministry archives, medical records of soldiers, radar/defense contractors, and kibbutz communities).

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-20

ATT&CK

MITRE ATT&CK

T1005Data from Local System
T1041Exfiltration Over C2 Channel
T1055.012Process Hollowing
T1059.005Visual Basic
T1114Email Collection
T1204.002Malicious File
T1218.009Regsvcs/Regasm
T1486Data Encrypted for Impact
T1561.001Disk Content Wipe
T1566.001Spearphishing Attachment
T1585.001Social Media Accounts
T1589.001Credentials

Research

OSINT seleccionado