Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas) — Threadlinqs Intelligence
As of 2026-07-14, Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas) is a medium-severity threat intel threat attributed to Handala Hack (aka Homeland Justice (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1309 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Handala Hack (aka Homeland Justice · Iran · HACKTIVISM
DomainTools Investigations documents a decentralized pro-Iran hacktivist ecosystem — including Handala, 313 Team, Cyber Fattah, Fatimiyoun/FAD Team, Dark Storm, CJM, Keymous+, DieNet, and supporting
DomainTools Investigations (DTI) analysts assess that a broad set of pro-Iran and 'Axis of Resistance' hacktivist identities operating on Telegram — Homeland Justice, Karma/KarmaBelow80, and Handala Hack among them — function as a single coordinated cyber-influence ecosystem aligned with Iran's Ministry of Intelligence and Security (MOIS), rather than as distinct grassroots hacktivist groups. These personas are described as interchangeable 'skins' layered over the same technical team, shared infrastructure, and common playbook, allowing Tehran to segment messaging and target sets across audiences while retaining centralized operational control.
The ecosystem's coordination and attack-tooling infrastructure spans Telegram (primary command, claim, and amplification channel), GitHub (tooling/target-list distribution), leak sites, and the commercially available 'Beamed' DDoS-for-hire/booter platform (marketed capability exceeding 3.5 Tbps, aliased in some claims as beamed.cc). Check-host[.]net is used across the ecosystem as a third-party 'proof-of-impact' validation service to lend credibility to DDoS claims.
Named collectives observed operating within this ecosystem include primary disruptors Handala (aka Homeland Justice, Karma/KarmaBelow80, linked to MOIS-attributed cluster Banished Kitten/Storm-0842/Void Manticore/Dune/Red Sandstorm), 313 Team (aka Islamic Cyber Resistance in Iraq), Cyber Fattah, Fatimiyoun/FAD Team, and Dark Storm (Dark Storm Team); secondary/opportunistic operators Keymous+, DieNet, NoName057(16), Killnet, and MONARCH; and enabling-function cells Evil Markhors (reconnaissance and credential harvesting) and Cyber Isnaad Front (doxxing and intimidation). Additional groups observed claiming activity in the same wartime wave include Nation of Saviors, Conquerors Electronic Army (operating under the Cyber Islamic Resistance/CIR umbrella), Sylhet Gang, APT Iran, PalachPro, and Hider Nex/Tunisian Maskers Cyber Force.
The ecosystem is low-sophistication by design: rather than novel intrusion tradecraft, it leans on high-volume/high-visibility DDoS floods, recycled or exaggerated breach data repackaged as new 'leaks,' website defacements, doxxing/identity-exposure campaigns, and propaganda amplification timed to kinetic events (e.g., the 2025-2026 Iran-Israel-US conflict). A representative high-profile action attributed to this ecosystem is the May 2026 DDoS campaign by 313 Team against Canonical/Ubuntu infrastructure: beginning around May 1, 2026, the group used the Beamed booter service against roughly 14 Ubuntu-related domains (ubuntu.com, Launchpad package repositories, and security-update API endpoints), disrupting site availability and package-update functionality. The action was accompanied by a Telegram-posted extortion/ceasefire demand and coincided with Canonical's disclosure of the high-severity 'Copyfail' Linux vulnerability, amplifying reputational impact; X/Twitter subsequently suspended the group's account.
Separately, the FBI (IC3 alert, ref. 260320, published March 23, 2026) documented Iranian state-linked actors — assessed as connected to the Handala persona and broader MOIS-run operations — using Telegram bot infrastructure as command-and-control against political dissidents, opposition figures, and journalists critical of the Iranian regime. The technique involves social-engineering victims (impersonating known contacts or tech support) into installing trojanized apps disguised as legitimate Telegram/WhatsApp builds; once installed, Telegram's own Bot API is abused as a C2 channel to remotely command the implant, exfiltrate files, capture screenshots, and record video calls — blending malicious C2 traffic with legitimate Telegram network traffic to evade detection.
During the February 28-March 5, 2026 hacktivist surge tied to the Iran-Israel-US conflict, 149 DDoS claims were logged against 110 distinct organizations across 16 countries, with Keymous+, DieNet, and NoName057(16) responsible fo
Weaknesses (CWE)
CWE-400, CWE-770, CWE-451
Target sectors: government administration, critical-infrastructure, financial-services, telecoms, health, news - media, software-supply-chain, open-source-infrastructure
Target regions: Middle East, kuwait, israel, jordan, Europe, North America, iraq
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1583.005, T1587.001, T1585.001, T1584.006, T1593.002, T1589.001, T1566.002, T1133, T1204.002, T1059