Handala is an Iran-aligned cyber persona and hacktivist-fronted threat actor active since at least late 2023, primarily known for targeting Israeli organizations and, more recently, entities in adjacent regional and Western sectors. The actor is widely tracked under aliases including Void Manticore, Banished Kitten, Red Sandstorm, Storm-0842, Dune, Homeland Justice, and Handala Hacking Team, although some of these names may reflect overlapping clustering by different vendors rather than perfectly bounded organizational identities. Handala is commonly assessed as part of Iran’s broader cyber-influence ecosystem and has been linked in public reporting to the Ministry of Intelligence and Security (MOIS). It operates as a deniable hybrid of intrusion activity, coercive messaging, leak operations, and psychological pressure rather than as a purely technical espionage group. Handala’s targeting has centered on Israel, including government, transportation, technology, business services, construction, healthcare, and industrial or critical-infrastructure-adjacent organizations. Reporting also associates the actor with activity affecting Jordanian infrastructure and attempted or claimed operations involving water and industrial environments. The group’s victimology indicates a preference for politically salient targets that offer propaganda value, reputational damage, or disruptive impact during periods of regional escalation. Handala’s operational tempo has been observed to rise and fall in line with geopolitical conflict, especially during heightened tensions involving Israel and Iran-aligned actors. The actor combines opportunistic intrusion methods with destructive and influence-oriented outcomes. Reported tradecraft includes scanning for exposed internet-facing services, exploiting known vulnerabilities in perimeter systems and externally accessible applications, password spraying and credential abuse, phishing and social engineering, use of valid accounts, webshell deployment, Active Directory reconnaissance, credential dumping, registry hive collection, and data exfiltration. Handala has also been associated with pre-attack reconnaissance and post-compromise administrative abuse in enterprise environments, including cloud and identity infrastructure. In some reporting, pre-positioning activity linked to the broader campaign included use of tools and malware associated with MuddyWater, suggesting either operational collaboration, handoff, or ecosystem overlap between Iranian state-linked operators and the Handala persona. A defining characteristic of Handala is its use of hack-and-leak and intimidation tactics. The group operates leak infrastructure, publishes stolen or purportedly stolen data, issues public claims timed for maximum psychological effect, and uses propaganda branding to amplify coercive impact. It has exposed personal and professional information, threatened additional disclosures, and framed intrusions as retaliation or resistance activity. This places Handala within a broader Iranian pattern of cyber-enabled influence operations in which technical compromise is paired with narrative shaping, public humiliation of victims, and deterrent signaling. Handala has also been tied to destructive operations. Public reporting in 2026 associated the actor with a major attack on Stryker in which Microsoft Intune administrative functionality was allegedly abused to issue bulk wipe actions at enterprise scale, causing widespread device destruction and operational disruption without deploying a traditional endpoint wiper. Other reporting links Handala to destructive or pseudo-ransomware-style tooling and to campaigns involving wiper-related tradecraft, though attribution of specific malware families varies across vendors. The actor has additionally been discussed in connection with Iranian destructive ecosystems that blend espionage, access operations, and sabotage. Overall, Handala should be understood as a state-linked Iranian cyber persona that sits at the intersection of hacktivism, information operations, and disruptive intrusion activity. Its most consistent hallmarks are politically aligned targeting, opportunistic access methods, credential and identity abuse, leak-and-shame operations, and the use of cyber incidents as instruments of coercion, propaganda, and strategic signaling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604. For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.
CVEs Weaponized by This Cluster CVE-2017-7921 — Hikvision auth bypass (historical reuse)
One of the Hikvision vulnerabilities (CVE-2021-3626; command injection) grants an attacker full root access to control the device.
CVEs Weaponized by This Cluster CVE-2023-6895 — IP camera RCE
CVEs Weaponized by This Cluster CVE-2024-55591 — FortiOS authentication bypass (modified exploit creates super_admin accounts)
4 more CVEs tied to this actor tracked in Mallory.
143 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned actor described as synchronizing cyber/influence activity with regional kinetic events and blending extortion with influence operations.
Mentioned only in passing as the Iran-linked hacktivist group behind a separate wiper attack on Stryker; not connected to the AdaptHealth breach.
Separate Iran-linked group mentioned as part of a broader wave of wiper activity against Israeli organizations.
Targeted a medical equipment firm that supplies U.S. military branches, illustrating how private-sector organizations can become wartime cyber targets due to military-adjacent business relationships.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.