Activity timeline
Handala Hack appears in 5 tracked threats between and ; the busiest month was 2026-03 with 4 reports.
ATT&CK techniques observed
- T1059 Command and Scripting Interpreter — Executionobserved in 5 of 5 tracked threats
- T1485 Data Destruction — Impactobserved in 5 of 5 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 4 of 5 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 4 of 5 tracked threats
- T1053 Scheduled Task/Job — Executionobserved in 4 of 5 tracked threats
- T1087 Account Discovery — Discoveryobserved in 4 of 5 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 4 of 5 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 4 of 5 tracked threats
- T1561 Disk Wipe — Impactobserved in 4 of 5 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 5 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
- T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 3 of 5 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 5 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 5 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 5 tracked threats
Tracked threats
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)MEDIUM
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker CorporationCRITICAL
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)CRITICAL
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker AttackCRITICAL
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater CampaignCRITICAL