Activity timeline
Handala Hack Team appears in 4 tracked threats between and ; the busiest month was 2026-03 with 3 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 4 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 4 tracked threats
- T1110 Brute Force — Credential Accessobserved in 3 of 4 tracked threats
- T1485 Data Destruction — Impactobserved in 3 of 4 tracked threats
- T1561 Disk Wipe — Impactobserved in 3 of 4 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 2 of 4 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 4 tracked threats
- T1020 Automated Exfiltration — Exfiltrationobserved in 2 of 4 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 2 of 4 tracked threats
- T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 2 of 4 tracked threats
- T1047 Windows Management Instrumentation — Executionobserved in 2 of 4 tracked threats
- T1053 Scheduled Task/Job — Executionobserved in 2 of 4 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 2 of 4 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 2 of 4 tracked threats
Tracked threats
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU InfrastructureHIGH
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker CorporationCRITICAL
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)CRITICAL
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)CRITICAL