Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)
Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate (TL-2026-1309), also tracked as Pro-Iran Hacktivist Ecosystem, is a medium-severity tracked intrusion set, first published 2026-07-14. It is attributed to Handala Hack (Iran) with medium confidence, affects Canonical Ubuntu.com / Launchpad / security update APIs, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-1309
- Threat ID
- TL-2026-1309
- Also known as
- Pro-Iran Hacktivist Ecosystem, Axis of Resistance Cyber Ecosystem, Iranian Wartime Hacktivist Coalition
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- Handala Hack
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- HACKTIVISM
- Target sectors
- government administration, critical-infrastructure, financial-services, telecoms, health, news - media, software-supply-chain, open-source-infrastructure
- Target regions
- Middle East, kuwait, israel, jordan, Europe, North America, iraq
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate
Malware and tooling: HamsaUpdate, Beamed DDoS-for-hire platform, Telegram Bot API
DomainTools Investigations documents a decentralized pro-Iran hacktivist ecosystem — including Handala, 313 Team, Cyber Fattah, Fatimiyoun/FAD Team, Dark Storm, CJM, Keymous+, DieNet, and supporting reconnaissance/doxxing cells — coordinating via Telegram channels, shared target lists, and the Beamed DDoS-for-hire platform to conduct high-volume DDoS, hack-and-leak, and credential-theft campaigns against government, critical-infrastructure, finance, and media organizations. Researchers assess several of these personas are interchangeable 'skins' operated by Iran's MOIS over shared technical infrastructure.
How Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate works
DomainTools Investigations (DTI) analysts assess that a broad set of pro-Iran and 'Axis of Resistance' hacktivist identities operating on Telegram — Homeland Justice, Karma/KarmaBelow80, and Handala Hack among them — function as a single coordinated cyber-influence ecosystem aligned with Iran's Ministry of Intelligence and Security (MOIS), rather than as distinct grassroots hacktivist groups. These personas are described as interchangeable 'skins' layered over the same technical team, shared infrastructure, and common playbook, allowing Tehran to segment messaging and target sets across audiences while retaining centralized operational control.
The ecosystem's coordination and attack-tooling infrastructure spans Telegram (primary command, claim, and amplification channel), GitHub (tooling/target-list distribution), leak sites, and the commercially available 'Beamed' DDoS-for-hire/booter platform (marketed capability exceeding 3.5 Tbps, aliased in some claims as beamed.cc). Check-host[.]net is used across the ecosystem as a third-party 'proof-of-impact' validation service to lend credibility to DDoS claims.
Named collectives observed operating within this ecosystem include primary disruptors Handala (aka Homeland Justice, Karma/KarmaBelow80, linked to MOIS-attributed cluster Banished Kitten/Storm-0842/Void Manticore/Dune/Red Sandstorm), 313 Team (aka Islamic Cyber Resistance in Iraq), Cyber Fattah, Fatimiyoun/FAD Team, and Dark Storm (Dark Storm Team); secondary/opportunistic operators Keymous+, DieNet, NoName057(16), Killnet, and MONARCH; and enabling-function cells Evil Markhors (reconnaissance and credential harvesting) and Cyber Isnaad Front (doxxing and intimidation). Additional groups observed claiming activity in the same wartime wave include Nation of Saviors, Conquerors Electronic Army (operating under the Cyber Islamic Resistance/CIR umbrella), Sylhet Gang, APT Iran, PalachPro, and Hider Nex/Tunisian Maskers Cyber Force.
The ecosystem is low-sophistication by design: rather than novel intrusion tradecraft, it leans on high-volume/high-visibility DDoS floods, recycled or exaggerated breach data repackaged as new 'leaks,' website defacements, doxxing/identity-exposure campaigns, and propaganda amplification timed to kinetic events (e.g., the 2025-2026 Iran-Israel-US conflict). A representative high-profile action attributed to this ecosystem is the May 2026 DDoS campaign by 313 Team against Canonical/Ubuntu infrastructure: beginning around May 1, 2026, the group used the Beamed booter service against roughly 14 Ubuntu-related domains (ubuntu.com, Launchpad package repositories, and security-update API endpoints), disrupting site availability and package-update functionality. The action was accompanied by a Telegram-posted extortion/ceasefire demand and coincided with Canonical's disclosure of the high-severity 'Copyfail' Linux vulnerability, amplifying reputational impact; X/Twitter subsequently suspended the group's account.
Separately, the FBI (IC3 alert, ref. 260320, published March 23, 2026) documented Iranian state-linked actors — assessed as connected to the Handala persona and broader MOIS-run operations — using Telegram bot infrastructure as command-and-control against political dissidents, opposition figures, and journalists critical of the Iranian regime. The technique involves social-engineering victims (impersonating known contacts or tech support) into installing trojanized apps disguised as legitimate Telegram/WhatsApp builds; once installed, Telegram's own Bot API is abused as a C2 channel to remotely command the implant, exfiltrate files, capture screenshots, and record video calls — blending malicious C2 traffic with legitimate Telegram network traffic to evade detection.
During the February 28-March 5, 2026 hacktivist surge tied to the Iran-Israel-US conflict, 149 DDoS claims were logged against 110 distinct organizations across 16 countries, with Keymous+, DieNet, and NoName057(16) responsible for nearly 70% of claimed activity in the peak Feb 28-Mar 2 window. Targeting concentrated heavily on the Middle East (107 of 149 claims), led by Kuwait (28%), Israel (27.1%), and Jordan (21.5%), with Europe absorbing 22.8% of remaining activity; government entities represented 47.8% of targets, followed by finance (11.9%) and telecommunications (6.7%).
Handala itself (established December 18, 2023, in the weeks following the October 7, 2023 attacks) has a documented history beyond pure DDoS, including the HamsaUpdate wiper deployment (December 2023), high-profile email/data breaches of senior Israeli officials (Ehud Barak, Gadi Eisenkot, Benny Gantz, Naftali Bennett), an alleged Shin Bet personnel-data infiltration (~30,000 records), an alleged 197GB exfiltration from Soreq Nuclear Research Center, a March 2026 attack claim against Stryker Corporation (healthcare device manufacturer, allegedly affecting data tied to 150 million patients), and a claimed compromise of FBI Director Kash Patel's personal email account. US DOJ and FBI attribution places a Handala-linked MOIS unit under identified leadership, including Yahya Hosseini Panjaki, reported killed during the June 2025/2026 Iran war.
Overall, DomainTools and downstream reporting (Cyberpress, SOCRadar, Unit 42, Rapid7, Sophos, Infosecurity Magazine, GBHackers, The Hacker News) characterize this as a durable, reusable wartime cyber-influence apparatus: personas can be spun up, retired, or rebranded quickly, infrastructure (Telegram channels, booter services, leak sites) is shared and recycled across identities, and impact is measured as much in psychological/propaganda terms as in technical damage — while still producing real operational disruption against government, critical-infrastructure, financial, healthcare, and media targets globally.
MITRE ATT&CK techniques used in TL-2026-1309
Collection
T1005 Data from Local System; T1113 Screen Capture; T1125 Video Capture
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage
Discovery
T1046 Network Service Discovery
Credential Access
T1056.004 Credential API Hooking
Execution
T1059 Command and Scripting Interpreter; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1102.002 Bidirectional Communication
Initial Access
T1133 External Remote Services; T1566.002 Spearphishing Link
Impact
T1485 Data Destruction; T1491.002 External Defacement; T1498.001 Direct Network Flood; T1498.002 Reflection Amplification; T1499.004 Application or System Exploitation; T1565.002 Transmitted Data Manipulation
Persistence
Resource Development
T1583.005 Botnet; T1584.006 Web Services; T1585.001 Social Media Accounts; T1587.001 Malware
Reconnaissance
T1589.001 Credentials; T1593.002 Search Engines
reconnaissance
Affected products and versions in Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate
- Canonical — Ubuntu.com / Launchpad / security update APIs
Vulnerable versions: public-facing web and package-distribution infrastructure, May 2026
Fixed in: N/A - availability incident, not a code vulnerability - Multiple — Government, critical infrastructure, financial services, telecommunications, healthcare, and media sector internet-facing services
Vulnerable versions: Internet-exposed web applications and services lacking DDoS mitigation, primarily in Middle East (Kuwait, Israel, Jordan) and Europe
Fixed in: N/A - Meta/WhatsApp, Telegram FZ-LLC — Trojanized/impersonated Telegram and WhatsApp application builds
Vulnerable versions: unofficial/sideloaded builds distributed to political dissidents, opposition figures, and journalists
Fixed in: official app-store builds with verified signing
Remediation for Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate
Patches
- Apply vendor patches promptly during hacktivist-exploited disclosure windows (e.g., Canonical's high-severity 'Copyfail' Linux vulnerability disclosed concurrently with the May 2026 DDoS campaign) to prevent opportunistic pivoting from disruption to exploitation.
Immediate actions
- Enable and tune DDoS scrubbing/CDN protection (rate limiting, anycast, upstream scrubbing) for internet-facing web, package-repository, and API endpoints ahead of anticipated wartime escalation windows.
- Block or throttle known booter/stresser infrastructure (e.g., beamed.cc and associated DDoS-for-hire endpoints) at perimeter and CDN layers.
- Monitor Telegram Bot API traffic patterns (recurring polling to api.telegram.org from unexpected endpoints/processes) as a potential C2 indicator.
- Alert on installation of Telegram/WhatsApp application binaries from non-official sources; verify code-signing and distribution channel for messaging-app installers.
- Flag and triage 'proof of impact' claims validated only via check-host[.]net as unverified until independently confirmed.
- Brief communications/PR and executive-protection teams on hack-and-leak/extortion patterns (Telegram-posted ceasefire/extortion demands) to avoid amplifying unverified claims.
Workarounds
- Where scrubbing capacity is insufficient, implement geofencing/rate-limiting biased against traffic surges correlated with regional conflict escalation events.
- Maintain out-of-band/mirrored update-distribution channels for critical software repositories to preserve availability during sustained DDoS against primary infrastructure.
Longer-term hardening
- Deploy behavioral EDR/NDR detection for messaging-app-disguised C2 (screenshot capture, video-call recording, remote-command execution triggered via chat-bot commands).
- Establish DDoS incident-response runbooks with pre-negotiated scrubbing-provider failover for public-facing infrastructure, especially package/update-distribution systems.
- Maintain a recurring-breach-data watchlist: correlate newly claimed 'leaks' against previously known breach corpora to rapidly identify recycled/exaggerated data.
- Track hacktivist Telegram channel churn (persona rebranding, channel bans/reinstatement) as an ecosystem-tracking signal rather than treating each named group as fully independent.
- Extend executive and staff digital-protective-intelligence monitoring to cover doxxing/identity-exposure campaigns from Evil Markhors/Cyber Isnaad Front-style enabling cells.
Weaknesses (CWE) in Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate
CWE-400, CWE-770, CWE-451
Timeline of Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate
- Handala-linked HamsaUpdate wiper malware deployed against Israeli targets.
- Handala Hack persona established on Telegram and X in the weeks following the October 7, 2023 attacks.
- Hider Nex/Tunisian Maskers Cyber Force launches the first DDoS attack of the Feb 28-Mar 5, 2026 hacktivist surge tied to the Iran-Israel-US conflict.
- Keymous+, DieNet, and NoName057(16) drive nearly 70% of claimed DDoS activity during the Feb 28-Mar 2 peak window; total reaches 149 claims against 110 organizations in 16 countries by March 5.
- FBI/IC3 publishes advisory 260320 documenting Iranian state-linked actors (assessed connection to Handala/MOIS) using Telegram Bot API C2 against dissidents, opposition figures, and journalists via trojanized Telegram/WhatsApp builds.
- 313 Team (Islamic Cyber Resistance in Iraq) launches a Beamed-powered DDoS campaign against ~14 Ubuntu-related domains including ubuntu.com and Launchpad, disrupting Canonical infrastructure; extortion/ceasefire demand posted via Telegram.
- Canonical confirms the DDoS disruption; the incident coincides with disclosure of the high-severity 'Copyfail' Linux vulnerability; X/Twitter later suspends 313 Team's account.
- DomainTools Investigations publishes analysis characterizing Handala, Homeland Justice, and Karma/KarmaBelow80 as interchangeable MOIS-operated 'skins' over shared infrastructure and tooling.
- Cyber Security News reports on the broader pro-Iran hacktivist ecosystem's continued use of Telegram, shared target lists, DDoS-for-hire tooling, and leak-amplification campaigns against government, infrastructure, finance, and media targets.
Sources cited for Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate
- Pro-Iran Hacktivists Use Telegram Coordinated DDoS
- Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026 (DomainTools Investigations summary)
- Iran's Digital Proxy Army Turns DDoS Attacks and Data Leaks Into Wartime Psychological Weapons
- Government of Iran Cyber Actors Deploy Telegram C2 to Target Dissidents, Journalists (IC3 Advisory 260320)
- FBI says Iranian hackers are using Telegram to steal data in malware attacks
- 149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
- Pro-Iran Hackers Hit Ubuntu's Canonical With DDoS, Float Extortion Demand
- Ubuntu Hit by DDoS Attack: Pro-Iran 313 Team Claims Responsibility
- Handala Hack Team - Wikipedia
- Dark Web Profile: Mr Hamza
- Telegram Hacktivist Activity Timeline of Iran - Israel & US War
- Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)
- Iran's Cyber Playbook in the Escalating Regional Conflict
- How hacktivist cyber operations surged amid Israeli-Iranian conflict
- Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies
Threats related to Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate
Detection coverage for TL-2026-1309
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1309 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.