Handala Hack is an Iranian-affiliated threat actor associated with cyber operations aligned with Iran’s Ministry of Intelligence and Security (MOIS). The group has been observed using Telegram both as an operational communications platform and as command-and-control infrastructure, reflecting a preference for blending malicious traffic with legitimate services. Public reporting also places the actor on Telegram channels where it publicizes operations. Observed intrusion activity attributed to this actor begins with social engineering conducted through social media applications. Operators impersonate technical support personnel or well-known personas to persuade targets to install malware disguised as legitimate software, including communication applications. The malware delivery chain has used PowerShell and VBScript loaders to retrieve additional payloads from remote object storage, unpack archives, and execute follow-on components. The tooling associated with Handala Hack supports persistence, defense evasion, collection, and exfiltration. Reported behaviors include modifying registry settings for persistence, using PowerShell extensively for execution, adding Microsoft Defender exclusions, and deploying payloads that collect screen activity, audio activity, and cached data. The malware can compress collected material into archives and exfiltrate sensitive information through Telegram bots. Additional analyzed payloads included executable and Python-based components used after initial loader execution. The actor’s tradecraft emphasizes user execution, masquerading, obfuscation, staged payload delivery, and abuse of trusted cloud and messaging services. Based on the reported MOIS alignment, Handala Hack is best characterized as an Iranian state-linked espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.