# Handala

> As of 2026-05-30, Handala is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt. Also known as BANISHED KITTEN, COBALT MYSTIQUE, Handala Hack, Homeland Justice. ATT&CK coverage spans 54 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1021 (Remote Services), T1053 (Scheduled Task/Job).

- **Nation:** Iran
- **Tracked threats:** 3
- **Categories:** APT
- **Also known as:** BANISHED KITTEN, COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, Red Sandstorm, Handala Hack Team, Storm-0842, Storm-842, Dune
- **As of:** 2026-05-30

## ATT&CK techniques observed

54 techniques observed across 3 of 3 tracked threats. Tactics: Impact (7), Execution (6), Command and Control (5), Discovery (5), Stealth (formerly Defense Evasion) (5), Collection (4).

- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 3 of 3 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 3 of 3 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Execution — observed in 3 of 3 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 3 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 3 of 3 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 3 of 3 tracked threats
- [T1561](https://intel.threadlinqs.com/technique/T1561) Disk Wipe — Impact — observed in 3 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1037](https://intel.threadlinqs.com/technique/T1037) Boot or Logon Initialization Scripts — Persistence — observed in 2 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 2 of 3 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 3 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 2 of 3 tracked threats

## Tracked threats

- [Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation](https://intel.threadlinqs.com/threat/TL-2026-0268) — CRITICAL
- [Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)](https://intel.threadlinqs.com/threat/TL-2026-0237) — CRITICAL
- [Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign](https://intel.threadlinqs.com/threat/TL-2026-0215) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Handala
