Threadlinqs IntelligenceStart free

Threat actorIranTracked since 2026-03

Handala

Also known as:BANISHED KITTENCOBALT MYSTIQUEHandala HackHomeland JusticeKarmaKarmabelow80Red SandstormHandala Hack TeamStorm-0842Storm-842Dune

As of 2026-05-30, Handala is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt. Also known as BANISHED KITTEN, COBALT MYSTIQUE, Handala Hack, Homeland Justice. ATT&CK coverage spans 54 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1021 (Remote Services), T1053 (Scheduled Task/Job).

Tracked threats
33 critical
First seen
2026-03-12
Last seen
2026-03-22
ATT&CK techniques
54across 3 of 3 threats
Related CVEs
0None referenced
Attribution
IranNation or origin
Nation: Iran · 3 tracked threat(s) · Categories: APT

Activity timeline

Handala appears in 3 tracked threats between and .

ATT&CK techniques observed

54 techniques observed across 3 of 3 tracked threats · Impact (7), Execution (6), Command and Control (5), Discovery (5), Stealth (formerly Defense Evasion) (5), Collection (4)
  • T1003 OS Credential Dumping — Credential Accessobserved in 3 of 3 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 3 of 3 tracked threats
  • T1053 Scheduled Task/Job — Executionobserved in 3 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 3 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1485 Data Destruction — Impactobserved in 3 of 3 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 3 of 3 tracked threats
  • T1561 Disk Wipe — Impactobserved in 3 of 3 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 2 of 3 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 3 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 2 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 3 tracked threats
  • T1110 Brute Force — Credential Accessobserved in 2 of 3 tracked threats

Tracked threats