Handala is a destructive malware designation associated with Iran-aligned disruptive operations and with a campaign that used politically themed social engineering against Israeli targets. The malware has been described primarily as a wiper capable of irreversibly destroying data and rendering infected systems inoperable. Reporting also links the name to a second-stage Delphi loader used in a multi-stage intrusion chain, indicating that Handala may refer both to a broader operation and to a specific loader component within that operation.
Observed delivery in the documented campaign relied on phishing themed around urgent security updates for F5 BIG-IP systems. On Windows, victims were induced to execute a disguised .NET updater from an archive, which extracted and launched additional payloads. On Linux, victims were instructed to run a shell command that fetched and executed a heavily obfuscated script. The Windows path could culminate in a wiper payload that overwrote files with random data and deleted them across major system and user directories on connected drives. The Linux path used a destructive script that delayed execution, profiled the host environment, removed user accounts, wiped home directories, destroyed partition structures, reformatted storage, deleted core system binaries, and rebooted the host to leave it unusable.
The intrusion chain also included a Delphi-coded second-stage loader referred to as Handala, which launched an AutoIt-based injector. That injector decrypted and decompressed shellcode and communicated with remote infrastructure, demonstrating a modular architecture beyond simple file destruction. Defensive reporting further notes suspicious AutoIt execution, malicious driver drops, unexpected regasm activity, abrupt system slowdowns, and creation of unknown files or processes as behaviors associated with Handala activity. The malware has also been characterized as capable of rapid spread across networks and of using evasion techniques.
Handala has been associated with disruptive and destructive incidents affecting organizations, including critical infrastructure and healthcare-adjacent entities. Public reporting tied the name to an attack on a medical technology organization involving both data exfiltration and destructive actions, and to a major claimed wiper incident affecting a multinational healthcare technology company. Because attribution around some Handala-branded operations remains contested, high-confidence characterization is strongest on its destructive wiping role, phishing-led delivery in at least one campaign, and use in politically motivated disruptive activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stryker has suffered a major cyberattack involving wiper malware claimed by Handala, a pro-Palestinian hacktivist group linked to Iran.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
“obfuscated payload… concealed within… five Base64 encoding steps… executed using the ‘eval’ command.” / “loader conceals its strings with… ADD… AutoIt script… strings… SUB… shellcode… implements the RC4 stream cipher… decrypt another payload… decompressed… LZNT1.”
Sandworm directly deployed the OLYMPICDESTROYER wiper at the 2018 Pyeongchang Winter Olympics, disabling Wi-Fi at the opening ceremony, taking down the official ticketing system, disrupting broadcast drone operations, and compromising over 300 systems, requiring 12 hours to restore.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive wiper malware with a reported multi-year operational lifespan; the report describes it as MOIS-linked and associated with targeting US and Israeli organizations.
Associated Analytic Story ... BlackByte Ransomware IcedID Handala Wiper Meduza Stealer ...
Iran-aligned disruptive tooling and operations involving data exfiltration and destructive actions against healthcare-related infrastructure.
Destructive malware used in attacks attributed to Handala to wipe Windows and Linux systems and disrupt operations; the group also claims data theft and public leaking of sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.