◇ SIGN IN
← all actors
ransomware

Handala

activemedium confidence
Ransomware
Handala HackHandala Hack TeamVoid Manticore (linked)BANISHED KITTEN (linked)
Attribution
hacktivist (pro-Palestinian / pro-Iran; assessed links to Iran MOIS)
Origin
Iran (assessed)
First seen
2023
Last active
2025
Motivation
Hacktivism (destructive; ideologically driven)
Confidence
medium
MENA targeting
Israel, UAE (secondary)
Sectors
Government/security services, energy, healthcare, technology

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Israel, UAE (secondary) (Government/security services, energy, healthcare sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Handala is a pro-Palestinian, pro-Iran hacktivist group that emerged after October 2023, known for phishing-delivered custom wiper malware, data leaks and DDoS against Israeli targets, with multiple vendors assessing links to Iran's MOIS (overlapping with Void Manticore / BANISHED KITTEN).

History

Handala surfaced in December 2023, shortly after the 7 October 2023 attacks and the ensuing conflict, branding itself as a pro-Palestinian hacktivist collective. Its core tradecraft centers on destructive operations: phishing emails deliver malicious attachments that deploy custom wiper malware which overwrites files with random data and renders systems unbootable, complemented by data-theft-and-leak extortion and DDoS. Trellix and others have documented Handala's wiper targeting Israeli organizations.

Multiple security firms and intelligence assessments associate Handala with Iranian state interests and specifically Iran's Ministry of Intelligence and Security (MOIS), noting operational overlaps with the Void Manticore / BANISHED KITTEN cluster and positioning the group within Iran's asymmetric cyber strategy. These are analytic assessments rather than confirmed admissions.

In 2025 Handala escalated: reporting describes a January 2025 incident abusing public-address systems in Israeli kindergartens to broadcast alerts and propaganda (later acknowledged by Israel's National Cyber Directorate), plus multi-wave DDoS against Israeli telecom and energy providers. Its targeting is overwhelmingly Israel, with additional MENA-relevant claims including the UAE. Individual victim and breach claims are self-reported and should be treated as unverified unless confirmed by a reputable source.

Notable campaigns

2024
Handala wiper campaigns
Phishing-delivered custom wiper attacks against Israeli organizations documented by Trellix.
2025
Kindergarten PA-system intrusion
Claimed January 2025 abuse of Israeli kindergarten public-address systems to broadcast propaganda; acknowledged by Israel's cyber directorate.
2025
Telecom/energy DDoS waves
Multi-wave DDoS against Israeli telecom and energy firms causing observable disruption (claimed).

Claimed victims · 175 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Exposing Israel’s Drone Queen: The Fall of Colonel Haimovich
Raz Zimmt’s Chats Leaked to the World
Handala Hack Strikes 27 Companies for Minab’s Innocents
50 Senior Unit 9900 Officers ExposedGovernment & Defense
Publication of Photos and Personal Details of IranWire’s Traitorous MembersOther
Passover Wiped Clean: 22TB of Data Gone from 14 Companies
PSK WIND’s Defense Networks Fall to Handala HackEnergy & Utilities
St. Joseph CountyUSGovernment & Defense
IranWireIRTechnology
Listen Closely, Gallant: Handala’s Eyes and Ears Are Everywhere
4 Terabytes Wiped—Good Food Store Shut Down After Major CyberattackUSRetail & E-Commerce
North Country Business Products Breached: 2,680 POS Terminals Disabled NationwideUSTechnology