Handala is an Iran-linked threat actor and hacktivist persona widely associated with the Iranian cyber-influence ecosystem and assessed by multiple defenders and government reporting to be linked to the Ministry of Intelligence and Security (MOIS). The actor operates as a deniable front that blends intrusion activity, destructive operations, hack-and-leak messaging, intimidation, and propaganda amplification. Known aliases include Banished Kitten, Dune, Handala Hack, Handala Hack Team, Homeland Justice, Red Sandstorm, Storm-0842, and Void Manticore, although some of these names may reflect overlapping tracking by different vendors rather than perfectly bounded one-to-one identity mapping. Handala has targeted organizations of strategic, symbolic, and psychological value, with a strong focus on Israeli entities and additional activity affecting the United States and other regional targets. Reported victim sectors include healthcare and medical technology, water utilities, government-linked organizations, and other civilian or dual-use enterprises whose disruption can generate political pressure, reputational harm, or downstream operational effects. The actor has been described as part of a broader Iran-aligned ecosystem in which nominal hacktivist branding masks state-linked objectives. The group is notable for combining information operations with real intrusion capability. Public-facing behavior includes breach claims, coercive messaging, leak threats, publication of allegedly stolen data, and narrative amplification through social channels. Operationally, Handala has been associated with credential theft, use of valid accounts, social engineering, impersonation of trusted individuals or technical support, password spraying and brute force against externally exposed services, and abuse of legitimate administrative platforms once privileged access is obtained. A defining characteristic of Handala’s tradecraft is the use of legitimate enterprise control planes for destructive effect rather than reliance solely on conventional malware deployment. In the March 2026 attack on Stryker, Handala was reported to have abused Microsoft Intune administrative capabilities to conduct bulk remote wipe actions at large scale after obtaining privileged cloud access. That operation has been cited as a prominent example of identity- and management-plane compromise leading directly to destructive business impact. Reporting around the same campaign also describes pre-attack reconnaissance and credential access activity including LSASS dumping, registry hive export, and Active Directory reconnaissance. Handala has also been linked in reporting to destructive and dual-use malware ecosystems, including activity overlapping with wiper operations and with tooling associated with broader Iranian clusters. Related reporting has connected parts of the surrounding campaign space to malware and backdoors such as Dindoor and Fakeset in pre-positioning phases, and to destructive tooling lineages including Crucio and FlockWiper in adjacent Iran-linked operations. Some reporting characterizes Handala as the destructive or propaganda-facing component of a larger operational chain in which other Iranian actors conduct initial access, persistence, or staging before handoff. The actor’s targeting and behavior fit a broader Iranian model of hybrid cyber and influence operations: opportunistic exploitation of exposed systems, credential abuse, selective data theft, disruptive or destructive action, and rapid public exploitation of the incident for psychological and political effect. Handala should be understood less as a purely grassroots hacktivist collective than as a state-aligned persona used to provide deniability while advancing Iranian strategic objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604. For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.
CVEs Weaponized by This Cluster CVE-2017-7921 — Hikvision auth bypass (historical reuse)
One of the Hikvision vulnerabilities (CVE-2021-3626; command injection) grants an attacker full root access to control the device.
CVEs Weaponized by This Cluster CVE-2023-6895 — IP camera RCE
CVEs Weaponized by This Cluster CVE-2024-55591 — FortiOS authentication bypass (modified exploit creates super_admin accounts)
4 more CVEs tied to this actor tracked in Mallory.
142 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in passing as the Iran-linked hacktivist group behind a separate wiper attack on Stryker; not connected to the AdaptHealth breach.
Separate Iran-linked group mentioned as part of a broader wave of wiper activity against Israeli organizations.
Targeted a medical equipment firm that supplies U.S. military branches, illustrating how private-sector organizations can become wartime cyber targets due to military-adjacent business relationships.
Iran-linked hacktivist actor conducting opportunistic attacks against exposed internet-facing systems; attributed in the article to Iran's Ministry of Intelligence and Security and described as having remotely wiped over 200,000 hosts in an attack on Stryker.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.