Handala Team
Handala (often branded as Handala Hack Team / Handala Hack) is a pro-Palestinian, Iran-aligned cyber actor that emerged around December 2023, shortly after the outbreak of the Israel–Hamas war. While initially framed as another “hacktivist” outfit running DDoS and simple website attacks, multiple government and private-sector assessments now attribute Handala to Iran’s Ministry of Intelligence (MOIS), tracked in some taxonomies as Storm-0842 / Banished Kitten / Void Manticore, i.e. a state-directed psychological warfare unit masquerading as a grassroots collective.
Handala’s activity focuses overwhelmingly on Israeli targets (and, to a lesser extent, foreign entities linked to Israel), including government, defense, healthcare, high-tech, telecom, transportation, and education sectors. Their core pattern is “hack-and-leak with psy-ops”: compromise, selective data theft, release of mixed authentic and fabricated data, and aggressive messaging aimed at eroding public trust in Israeli institutions, senior officials and security services rather than monetizing access.
Technically, Handala has demonstrated mid-to-high capability: phishing and spear-phishing, exploitation of internet-facing systems, ransomware-style encryption and extortion (with political rather than financial demands), custom wipers (e.g. Hatef for Windows, Hamsa for Linux), and opportunistic use of crises such as the CrowdStrike global outage by pushing fake “CrowdStrike fixes” that delivered wiper payloads. Their operational tempo has been sustained: some Israeli and academic sources count dozens of attacks between early 2024 and early 2025, including repeated campaigns against sensitive datasets (gun license records, justice ministry archives, medical records of soldiers, radar/defense contractors, and kibbutz communities).
ATT&CK
MITRE ATT&CK
Research