Activity timeline
Handala appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1003 OS Credential Dumping — Credential Accessobserved in 3 of 3 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 3 of 3 tracked threats
- T1053 Scheduled Task/Job — Executionobserved in 3 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 3 tracked threats
- T1087 Account Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1485 Data Destruction — Impactobserved in 3 of 3 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 3 of 3 tracked threats
- T1561 Disk Wipe — Impactobserved in 3 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 2 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 2 of 3 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 2 of 3 tracked threats
- T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 3 tracked threats
- T1110 Brute Force — Credential Accessobserved in 2 of 3 tracked threats
Tracked threats
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker CorporationCRITICAL
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)CRITICAL
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater CampaignCRITICAL