Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Iran🇮🇷 IR30 malware familiesExploits CVEs in the wild

Handala

Also known asBANISHED KITTENDuneHandalaHandala Hack Teamhandala_hackHomeland JusticeRed SandstormStorm-0842Void Manticore

Handala is an Iran-linked threat actor and hacktivist persona assessed with high confidence as a MOIS-affiliated front operating within the Banished Kitten cyber ecosystem. It is also tracked as Void Manticore by Microsoft and Storm-0842 by Check Point Research. Reported aliases in the provided content include Banished Kitten, Dune, Handala Hack, Handala Hack Team, Homeland Justice, Red Sandstorm, Storm-0842, and Void Manticore. The content also states that Handala Hack Team is an Iranian hacktivist persona first observed in 2023 and operated by COBALT MYSTIQUE. The actor is described as conducting hack-and-leak, destructive, and psychological operations, and as routinely overstating its capability and impact while at times carrying out real data theft and wiper attacks. Confirmed or reported targeting in the content includes U.S. critical infrastructure and healthcare-related organizations, notably California Water Service and Stryker. In the Cal Water case, Handala claimed to have breached the utility, leaked 5 GB of alleged data, and asserted it could disrupt water supply operations. Multiple reports cited in the content state that subsequent investigation by Cal Water and Mandiant found no evidence of threat actor activity in Cal Water’s internal IT or OT environments, with activity limited to unauthorized access to a small number of user accounts in two third-party service provider platforms, one customer online account accessed with stolen credentials, and a third-party GPS correction website. Separate reporting in the content, including Dataminr analysis, states that leaked materials indicated compromise of a customer billing database and an internal RTKBase NTRIP caster environment, with plaintext credentials exposed and possible pivoting between those environments; however, OT or ICS disruption was not confirmed. The content also attributes to Handala a March 2026 attack on Stryker that was described as a wiper attack. Handala claimed it exfiltrated 50 TB of critical data and permanently erased 200,000 devices and 12 PB of Stryker data. The content further states that Handala’s toolkit includes custom wipers named win.handala, Handala Wiper, and Hamsa Wiper, as well as MBR-overwriting capabilities. Across reporting cited here, Handala is associated with data exfiltration, public leaking of stolen data, extortion-style pressure, wiper deployment, and influence or intimidation messaging. Tactics and techniques directly mentioned in the content include impersonation of individuals familiar to victims and technical support associated with social messaging services, PowerShell execution, and video capture-related activity annotated to Void Manticore. The broader reporting also describes likely or observed Iran-linked tradecraft around exploitation of internet-exposed systems, credential attacks, phishing, password spraying, ransomware, wiper malware, website defacement, DDoS, and hack-and-leak operations. Handala has been publicly linked in the content to retaliation-themed operations following U.S. and Israeli military actions against Iran, and is repeatedly characterized as Iran-linked, widely believed to be a front for Iranian government hacking operations, and specifically suspected of serving Iran’s Ministry of Intelligence.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Energy
  • Utilities
  • Government & Administration
  • Transportation
  • Public Safety

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇨🇦 Canada
  • 🇲🇽 Mexico
  • 🇮🇱 Israel

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics42 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589×3
Gather Victim Identity Information
T1592
Gather Victim Host Information
TA0042
Resource Development
1 technique
T1586×4
Compromise Accounts
TA0001
Initial Access
5 techniques
T1078×10
Valid Accounts
T1133
External Remote Services
T1190×4
Exploit Public-Facing Application
T1195
Supply Chain Compromise
T1566×2
Phishing
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1574
Hijack Execution Flow
T1574.001
DLL
TA0003
Persistence
3 techniques
T1078×10
Valid Accounts
T1133
External Remote Services
T1136
Create Account
TA0004
Privilege Escalation
1 technique
T1078×10
Valid Accounts
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1078×10
Valid Accounts
T1574
Hijack Execution Flow
T1574.001
DLL
TA0007
Discovery
2 techniques
T1046×2
Network Service Discovery
T1482
Domain Trust Discovery
TA0008
Lateral Movement
2 techniques
T1021×2
Remote Services
T1210
Exploitation of Remote Services
TA0009
Collection
4 techniques
T1005×2
Data from Local System
T1074
Data Staged
T1125×3
Video Capture
T1213×4
Data from Information Repositories
TA0011
Command and Control
2 techniques
T1102
Web Service
T1219×2
Remote Access Tools
TA0010
Exfiltration
4 techniques
T1020
Automated Exfiltration
T1041×2
Exfiltration Over C2 Channel
T1537×7
Transfer Data to Cloud Account
T1567×5
Exfiltration Over Web Service
TA0040
Impact
7 techniques
T1485×18
Data Destruction
T1486×4
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1491×3
Defacement
T1498×2
Network Denial of Service
T1499
Endpoint Denial of Service
T1561×4
Disk Wipe
IOCS

Observables

136 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping35

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal30

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs3

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables136

Domains, IPs, and hashes tied to this actor, refreshed continuously.