Handala
Handala is an Iran-linked threat actor and hacktivist persona assessed with high confidence as a MOIS-affiliated front operating within the Banished Kitten cyber ecosystem. It is also tracked as Void Manticore by Microsoft and Storm-0842 by Check Point Research. Reported aliases in the provided content include Banished Kitten, Dune, Handala Hack, Handala Hack Team, Homeland Justice, Red Sandstorm, Storm-0842, and Void Manticore. The content also states that Handala Hack Team is an Iranian hacktivist persona first observed in 2023 and operated by COBALT MYSTIQUE. The actor is described as conducting hack-and-leak, destructive, and psychological operations, and as routinely overstating its capability and impact while at times carrying out real data theft and wiper attacks. Confirmed or reported targeting in the content includes U.S. critical infrastructure and healthcare-related organizations, notably California Water Service and Stryker. In the Cal Water case, Handala claimed to have breached the utility, leaked 5 GB of alleged data, and asserted it could disrupt water supply operations. Multiple reports cited in the content state that subsequent investigation by Cal Water and Mandiant found no evidence of threat actor activity in Cal Water’s internal IT or OT environments, with activity limited to unauthorized access to a small number of user accounts in two third-party service provider platforms, one customer online account accessed with stolen credentials, and a third-party GPS correction website. Separate reporting in the content, including Dataminr analysis, states that leaked materials indicated compromise of a customer billing database and an internal RTKBase NTRIP caster environment, with plaintext credentials exposed and possible pivoting between those environments; however, OT or ICS disruption was not confirmed. The content also attributes to Handala a March 2026 attack on Stryker that was described as a wiper attack. Handala claimed it exfiltrated 50 TB of critical data and permanently erased 200,000 devices and 12 PB of Stryker data. The content further states that Handala’s toolkit includes custom wipers named win.handala, Handala Wiper, and Hamsa Wiper, as well as MBR-overwriting capabilities. Across reporting cited here, Handala is associated with data exfiltration, public leaking of stolen data, extortion-style pressure, wiper deployment, and influence or intimidation messaging. Tactics and techniques directly mentioned in the content include impersonation of individuals familiar to victims and technical support associated with social messaging services, PowerShell execution, and video capture-related activity annotated to Void Manticore. The broader reporting also describes likely or observed Iran-linked tradecraft around exploitation of internet-exposed systems, credential attacks, phishing, password spraying, ransomware, wiper malware, website defacement, DDoS, and hack-and-leak operations. Handala has been publicly linked in the content to retaliation-themed operations following U.S. and Israeli military actions against Iran, and is repeatedly characterized as Iran-linked, widely believed to be a front for Iranian government hacking operations, and specifically suspected of serving Iran’s Ministry of Intelligence.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Energy
- Utilities
- Government & Administration
- Transportation
- Public Safety
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇨🇦 Canada
- 🇲🇽 Mexico
- 🇮🇱 Israel
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604. For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.
One of the Hikvision vulnerabilities (CVE-2021-3626; command injection) grants an attacker full root access to control the device.
This analytic detects Windchill MethodServer log4j events that contain the CVE-2026-4681 exploitation probe run?c=echo%20GW_READY_OK . PTC identifies GW_READY_OK and related run?c= activity as log indicators associated with Windchill and FlexPLM exploitation.
Observables
136 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed a cyberattack against Cal Water, leaked 5 GB of allegedly stolen data, and asserted it could have disrupted the water supply after gaining access to Cal Water systems; investigation found activity limited to unauthorized access to a small number of user accounts on third-party platforms.
Claimed responsibility for hacking California Water Service; activity was assessed as unauthorized access to a small number of user accounts in two third-party service provider platforms, including access to one customer online account using stolen credentials.
Conducted a destructive cyberattack against Stryker, claiming theft of 50 TB of data and permanent erasure of 200,000 devices and 12 PB of company data.
Iran-aligned actor highlighted as a representative threat to World Cup-supporting infrastructure, with concern around targeting municipal and critical infrastructure services.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.