Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)

Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate (TL-2026-1309), also tracked as Pro-Iran Hacktivist Ecosystem, is a medium-severity tracked intrusion set, first published 2026-07-14. It is attributed to Handala Hack (Iran) with medium confidence, affects Canonical Ubuntu.com / Launchpad / security update APIs, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-1309

Threat ID
TL-2026-1309
Also known as
Pro-Iran Hacktivist Ecosystem, Axis of Resistance Cyber Ecosystem, Iranian Wartime Hacktivist Coalition
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-14
Last reviewed
2026-07-14
Attribution
Handala Hack
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
HACKTIVISM
Target sectors
government administration, critical-infrastructure, financial-services, telecoms, health, news - media, software-supply-chain, open-source-infrastructure
Target regions
Middle East, kuwait, israel, jordan, Europe, North America, iraq
Detection rules
9
Indicators of compromise
16

Malware and tooling in Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate

Malware and tooling: HamsaUpdate, Beamed DDoS-for-hire platform, Telegram Bot API

DomainTools Investigations documents a decentralized pro-Iran hacktivist ecosystem — including Handala, 313 Team, Cyber Fattah, Fatimiyoun/FAD Team, Dark Storm, CJM, Keymous+, DieNet, and supporting reconnaissance/doxxing cells — coordinating via Telegram channels, shared target lists, and the Beamed DDoS-for-hire platform to conduct high-volume DDoS, hack-and-leak, and credential-theft campaigns against government, critical-infrastructure, finance, and media organizations. Researchers assess several of these personas are interchangeable 'skins' operated by Iran's MOIS over shared technical infrastructure.

How Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate works

DomainTools Investigations (DTI) analysts assess that a broad set of pro-Iran and 'Axis of Resistance' hacktivist identities operating on Telegram — Homeland Justice, Karma/KarmaBelow80, and Handala Hack among them — function as a single coordinated cyber-influence ecosystem aligned with Iran's Ministry of Intelligence and Security (MOIS), rather than as distinct grassroots hacktivist groups. These personas are described as interchangeable 'skins' layered over the same technical team, shared infrastructure, and common playbook, allowing Tehran to segment messaging and target sets across audiences while retaining centralized operational control.

The ecosystem's coordination and attack-tooling infrastructure spans Telegram (primary command, claim, and amplification channel), GitHub (tooling/target-list distribution), leak sites, and the commercially available 'Beamed' DDoS-for-hire/booter platform (marketed capability exceeding 3.5 Tbps, aliased in some claims as beamed.cc). Check-host[.]net is used across the ecosystem as a third-party 'proof-of-impact' validation service to lend credibility to DDoS claims.

Named collectives observed operating within this ecosystem include primary disruptors Handala (aka Homeland Justice, Karma/KarmaBelow80, linked to MOIS-attributed cluster Banished Kitten/Storm-0842/Void Manticore/Dune/Red Sandstorm), 313 Team (aka Islamic Cyber Resistance in Iraq), Cyber Fattah, Fatimiyoun/FAD Team, and Dark Storm (Dark Storm Team); secondary/opportunistic operators Keymous+, DieNet, NoName057(16), Killnet, and MONARCH; and enabling-function cells Evil Markhors (reconnaissance and credential harvesting) and Cyber Isnaad Front (doxxing and intimidation). Additional groups observed claiming activity in the same wartime wave include Nation of Saviors, Conquerors Electronic Army (operating under the Cyber Islamic Resistance/CIR umbrella), Sylhet Gang, APT Iran, PalachPro, and Hider Nex/Tunisian Maskers Cyber Force.

The ecosystem is low-sophistication by design: rather than novel intrusion tradecraft, it leans on high-volume/high-visibility DDoS floods, recycled or exaggerated breach data repackaged as new 'leaks,' website defacements, doxxing/identity-exposure campaigns, and propaganda amplification timed to kinetic events (e.g., the 2025-2026 Iran-Israel-US conflict). A representative high-profile action attributed to this ecosystem is the May 2026 DDoS campaign by 313 Team against Canonical/Ubuntu infrastructure: beginning around May 1, 2026, the group used the Beamed booter service against roughly 14 Ubuntu-related domains (ubuntu.com, Launchpad package repositories, and security-update API endpoints), disrupting site availability and package-update functionality. The action was accompanied by a Telegram-posted extortion/ceasefire demand and coincided with Canonical's disclosure of the high-severity 'Copyfail' Linux vulnerability, amplifying reputational impact; X/Twitter subsequently suspended the group's account.

Separately, the FBI (IC3 alert, ref. 260320, published March 23, 2026) documented Iranian state-linked actors — assessed as connected to the Handala persona and broader MOIS-run operations — using Telegram bot infrastructure as command-and-control against political dissidents, opposition figures, and journalists critical of the Iranian regime. The technique involves social-engineering victims (impersonating known contacts or tech support) into installing trojanized apps disguised as legitimate Telegram/WhatsApp builds; once installed, Telegram's own Bot API is abused as a C2 channel to remotely command the implant, exfiltrate files, capture screenshots, and record video calls — blending malicious C2 traffic with legitimate Telegram network traffic to evade detection.

During the February 28-March 5, 2026 hacktivist surge tied to the Iran-Israel-US conflict, 149 DDoS claims were logged against 110 distinct organizations across 16 countries, with Keymous+, DieNet, and NoName057(16) responsible for nearly 70% of claimed activity in the peak Feb 28-Mar 2 window. Targeting concentrated heavily on the Middle East (107 of 149 claims), led by Kuwait (28%), Israel (27.1%), and Jordan (21.5%), with Europe absorbing 22.8% of remaining activity; government entities represented 47.8% of targets, followed by finance (11.9%) and telecommunications (6.7%).

Handala itself (established December 18, 2023, in the weeks following the October 7, 2023 attacks) has a documented history beyond pure DDoS, including the HamsaUpdate wiper deployment (December 2023), high-profile email/data breaches of senior Israeli officials (Ehud Barak, Gadi Eisenkot, Benny Gantz, Naftali Bennett), an alleged Shin Bet personnel-data infiltration (~30,000 records), an alleged 197GB exfiltration from Soreq Nuclear Research Center, a March 2026 attack claim against Stryker Corporation (healthcare device manufacturer, allegedly affecting data tied to 150 million patients), and a claimed compromise of FBI Director Kash Patel's personal email account. US DOJ and FBI attribution places a Handala-linked MOIS unit under identified leadership, including Yahya Hosseini Panjaki, reported killed during the June 2025/2026 Iran war.

Overall, DomainTools and downstream reporting (Cyberpress, SOCRadar, Unit 42, Rapid7, Sophos, Infosecurity Magazine, GBHackers, The Hacker News) characterize this as a durable, reusable wartime cyber-influence apparatus: personas can be spun up, retired, or rebranded quickly, infrastructure (Telegram channels, booter services, leak sites) is shared and recycled across identities, and impact is measured as much in psychological/propaganda terms as in technical damage — while still producing real operational disruption against government, critical-infrastructure, financial, healthcare, and media targets globally.

MITRE ATT&CK techniques used in TL-2026-1309

Collection

T1005 Data from Local System; T1113 Screen Capture; T1125 Video Capture

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage

Discovery

T1046 Network Service Discovery

Credential Access

T1056.004 Credential API Hooking

Execution

T1059 Command and Scripting Interpreter; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1102.002 Bidirectional Communication

Initial Access

T1133 External Remote Services; T1566.002 Spearphishing Link

Impact

T1485 Data Destruction; T1491.002 External Defacement; T1498.001 Direct Network Flood; T1498.002 Reflection Amplification; T1499.004 Application or System Exploitation; T1565.002 Transmitted Data Manipulation

Persistence

T1505.003 Web Shell

Resource Development

T1583.005 Botnet; T1584.006 Web Services; T1585.001 Social Media Accounts; T1587.001 Malware

Reconnaissance

T1589.001 Credentials; T1593.002 Search Engines

reconnaissance

T1598 Phishing for Information

Affected products and versions in Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate

  • Canonical — Ubuntu.com / Launchpad / security update APIs
    Vulnerable versions: public-facing web and package-distribution infrastructure, May 2026
    Fixed in: N/A - availability incident, not a code vulnerability
  • Multiple — Government, critical infrastructure, financial services, telecommunications, healthcare, and media sector internet-facing services
    Vulnerable versions: Internet-exposed web applications and services lacking DDoS mitigation, primarily in Middle East (Kuwait, Israel, Jordan) and Europe
    Fixed in: N/A
  • Meta/WhatsApp, Telegram FZ-LLC — Trojanized/impersonated Telegram and WhatsApp application builds
    Vulnerable versions: unofficial/sideloaded builds distributed to political dissidents, opposition figures, and journalists
    Fixed in: official app-store builds with verified signing

Remediation for Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate

Patches

  • Apply vendor patches promptly during hacktivist-exploited disclosure windows (e.g., Canonical's high-severity 'Copyfail' Linux vulnerability disclosed concurrently with the May 2026 DDoS campaign) to prevent opportunistic pivoting from disruption to exploitation.

Immediate actions

  • Enable and tune DDoS scrubbing/CDN protection (rate limiting, anycast, upstream scrubbing) for internet-facing web, package-repository, and API endpoints ahead of anticipated wartime escalation windows.
  • Block or throttle known booter/stresser infrastructure (e.g., beamed.cc and associated DDoS-for-hire endpoints) at perimeter and CDN layers.
  • Monitor Telegram Bot API traffic patterns (recurring polling to api.telegram.org from unexpected endpoints/processes) as a potential C2 indicator.
  • Alert on installation of Telegram/WhatsApp application binaries from non-official sources; verify code-signing and distribution channel for messaging-app installers.
  • Flag and triage 'proof of impact' claims validated only via check-host[.]net as unverified until independently confirmed.
  • Brief communications/PR and executive-protection teams on hack-and-leak/extortion patterns (Telegram-posted ceasefire/extortion demands) to avoid amplifying unverified claims.

Workarounds

  • Where scrubbing capacity is insufficient, implement geofencing/rate-limiting biased against traffic surges correlated with regional conflict escalation events.
  • Maintain out-of-band/mirrored update-distribution channels for critical software repositories to preserve availability during sustained DDoS against primary infrastructure.

Longer-term hardening

  • Deploy behavioral EDR/NDR detection for messaging-app-disguised C2 (screenshot capture, video-call recording, remote-command execution triggered via chat-bot commands).
  • Establish DDoS incident-response runbooks with pre-negotiated scrubbing-provider failover for public-facing infrastructure, especially package/update-distribution systems.
  • Maintain a recurring-breach-data watchlist: correlate newly claimed 'leaks' against previously known breach corpora to rapidly identify recycled/exaggerated data.
  • Track hacktivist Telegram channel churn (persona rebranding, channel bans/reinstatement) as an ecosystem-tracking signal rather than treating each named group as fully independent.
  • Extend executive and staff digital-protective-intelligence monitoring to cover doxxing/identity-exposure campaigns from Evil Markhors/Cyber Isnaad Front-style enabling cells.

Weaknesses (CWE) in Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate

CWE-400, CWE-770, CWE-451

Timeline of Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate

  • Handala-linked HamsaUpdate wiper malware deployed against Israeli targets.
  • Handala Hack persona established on Telegram and X in the weeks following the October 7, 2023 attacks.
  • Hider Nex/Tunisian Maskers Cyber Force launches the first DDoS attack of the Feb 28-Mar 5, 2026 hacktivist surge tied to the Iran-Israel-US conflict.
  • Keymous+, DieNet, and NoName057(16) drive nearly 70% of claimed DDoS activity during the Feb 28-Mar 2 peak window; total reaches 149 claims against 110 organizations in 16 countries by March 5.
  • FBI/IC3 publishes advisory 260320 documenting Iranian state-linked actors (assessed connection to Handala/MOIS) using Telegram Bot API C2 against dissidents, opposition figures, and journalists via trojanized Telegram/WhatsApp builds.
  • 313 Team (Islamic Cyber Resistance in Iraq) launches a Beamed-powered DDoS campaign against ~14 Ubuntu-related domains including ubuntu.com and Launchpad, disrupting Canonical infrastructure; extortion/ceasefire demand posted via Telegram.
  • Canonical confirms the DDoS disruption; the incident coincides with disclosure of the high-severity 'Copyfail' Linux vulnerability; X/Twitter later suspends 313 Team's account.
  • DomainTools Investigations publishes analysis characterizing Handala, Homeland Justice, and Karma/KarmaBelow80 as interchangeable MOIS-operated 'skins' over shared infrastructure and tooling.
  • Cyber Security News reports on the broader pro-Iran hacktivist ecosystem's continued use of Telegram, shared target lists, DDoS-for-hire tooling, and leak-amplification campaigns against government, infrastructure, finance, and media targets.

Sources cited for Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate

Threats related to Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate

Detection coverage for TL-2026-1309

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1309 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats