Handala is an Iranian state-linked threat actor and public-facing hacktivist persona associated with Iran’s Ministry of Intelligence and Security (MOIS). It is also tracked as VOID MANTICORE, Storm-0842, Banished Kitten, Dune, Red Sandstorm, and Homeland Justice; Handala Hack and Handala Popular Resistance Front are related public-facing names. The actor has conducted politically motivated and destructive operations against perceived Iranian adversaries, particularly in Albania, Israel, and the United States. Homeland Justice was publicly attributed by U.S. authorities to Iranian state activity following attacks on Albanian government systems. The group has targeted Albanian government and infrastructure organizations in campaigns connected to Iranian opposition-group activity in Albania. Its operations have included destructive malware, including the No-Justice Wiper, which damages boot-record data and renders affected Windows systems unable to restart. Observed supporting tradecraft includes PowerShell-based remote propagation via WinRM, likely use of administrative access for deployment, credential collection from Windows registry hives, and hidden PowerShell execution for defense evasion. It has also used or obtained trojanized applications for persistent surveillance of selected individuals. Handala has claimed disruptive intrusions against U.S. medical-technology and payment-processing companies in the context of Iran-related geopolitical escalation. A claimed attack against Stryker disrupted business operations including order processing, manufacturing, and shipping. The actor’s operations combine destructive effects, public claims, propaganda-oriented messaging, and cyber-enabled surveillance, consistent with Iranian proxy and state-aligned influence activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
32 malware families attributed to this actor across reporting.
27 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604. For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.
CVEs Weaponized by This Cluster CVE-2017-7921 — Hikvision auth bypass (historical reuse)
One of the Hikvision vulnerabilities (CVE-2021-3626; command injection) grants an attacker full root access to control the device.
CVEs Weaponized by This Cluster CVE-2023-6895 — IP camera RCE
CVEs Weaponized by This Cluster CVE-2024-55591 — FortiOS authentication bypass (modified exploit creates super_admin accounts)
4 more CVEs tied to this actor tracked in Mallory.
153 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed an attack against medical-device manufacturer Stryker involving widespread system wiping and theft of approximately 50 TB of data.
A pro-Iranian hacktivist/proxy collective discussed in the context of cyber operations aligned with military objectives in the Middle East, including disruptive attacks, data-wiper claims, extortion, and critical-infrastructure targeting.
VOID MANTICORE appears only in the detection's annotations list.
Listed in the detection's Annotations section.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.