Skip to content

Handala

Handala is a destructive malware designation associated with Iran-aligned disruptive operations and with a campaign that used politically themed social engineering against Israeli targets.

Profile source: Mallory opens in a new tab

Handala

Family profile

Handala is a destructive malware designation associated with Iran-aligned disruptive operations and with a campaign that used politically themed social engineering against Israeli targets. The malware has been described primarily as a wiper capable of irreversibly destroying data and rendering infected systems inoperable. Reporting also links the name to a second-stage Delphi loader used in a multi-stage intrusion chain, indicating that Handala may refer both to a broader operation and to a specific loader component within that operation.

Observed delivery in the documented campaign relied on phishing themed around urgent security updates for F5 BIG-IP systems. On Windows, victims were induced to execute a disguised .NET updater from an archive, which extracted and launched additional payloads. On Linux, victims were instructed to run a shell command that fetched and executed a heavily obfuscated script. The Windows path could culminate in a wiper payload that overwrote files with random data and deleted them across major system and user directories on connected drives. The Linux path used a destructive script that delayed execution, profiled the host environment, removed user accounts, wiped home directories, destroyed partition structures, reformatted storage, deleted core system binaries, and rebooted the host to leave it unusable.

The intrusion chain also included a Delphi-coded second-stage loader referred to as Handala, which launched an AutoIt-based injector. That injector decrypted and decompressed shellcode and communicated with remote infrastructure, demonstrating a modular architecture beyond simple file destruction. Defensive reporting further notes suspicious AutoIt execution, malicious driver drops, unexpected regasm activity, abrupt system slowdowns, and creation of unknown files or processes as behaviors associated with Handala activity. The malware has also been characterized as capable of rapid spread across networks and of using evasion techniques.

Handala has been associated with disruptive and destructive incidents affecting organizations, including critical infrastructure and healthcare-adjacent entities. Public reporting tied the name to an attack on a medical technology organization involving both data exfiltration and destructive actions, and to a major claimed wiper incident affecting a multinational healthcare technology company. Because attribution around some Handala-branded operations remains contested, high-confidence characterization is strongest on its destructive wiping role, phishing-led delivery in at least one campaign, and use in politically motivated disruptive activity.

Capabilities

  • Defense Evasion
  • Exfiltration

Operational record

1
YARA rules
5
Leak sites
3 available

Reported operators

Threat actors

1 named in public reporting
Handala

Stryker has suffered a major cyberattack involving wiper malware claimed by Handala, a pro-Palestinian hacktivist group linked to Iran.

MITRE ATT&CK

Handala in ATT&CK

70 distinct techniques

Techniques

70 techniques
T1485 Data Destruction T1027 Obfuscated Files or Information T1562.001 Disable or Modify Tools T1057 Process Discovery T1036 Masquerading T1059.003 Windows Command Shell T1105 Ingress Tool Transfer T1055 Process Injection T1204 User Execution T1078 Valid Accounts T1078.002 Valid Accounts: Domain Accounts T1078.004 Valid Accounts: Cloud Accounts T1133 External Remote Services T1190 Exploit Public-Facing Application T1199 Trusted Relationship T1566 Phishing T1047 Windows Management Instrumentation T1059.001 Command and Scripting Interpreter: PowerShell T1059.006 Command and Scripting Interpreter: Python T1072 Software Deployment Tools T1204.002 User Execution: Malicious File T1651 Cloud Administration Command T1098 Account Manipulation T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1484.001 Domain or Tenant Policy Modification: Group Policy Modification T1027.015 Obfuscated Files or Information: Compression T1036.004 Masquerading: Masquerade Task or Service T1036.005 Masquerading: Match Legitimate Resource Name or Location T1564.003 Hide Artifacts: Hidden Window T1679 Selective Exclusion T1684.001 Social Engineering: Impersonation T1003.001 OS Credential Dumping: LSASS Memory T1110 Brute Force T1110.001 Brute Force: Password Guessing T1110.004 Brute Force: Credential Stuffing T1552.002 Unsecured Credentials: Credentials in Registry T1082 System Information Discovery T1087.002 Account Discovery: Domain Account T1021.001 Remote Services: Remote Desktop Protocol T1005 Data from Local System T1074 Data Staged T1113 Screen Capture T1114.002 Email Collection: Remote Email Collection T1119 Automated Collection T1123 Audio Capture T1125 Video Capture T1213.002 Data from Information Repositories: Sharepoint T1560.001 Archive Collected Data: Archive via Utility T1041 Exfiltration Over C2 Channel T1071.001 Application Layer Protocol: Web Protocols T1102 Web Service T1219.002 Remote Access Tools: Remote Desktop Software T1572 Protocol Tunneling T1486 Data Encrypted for Impact T1490 Inhibit System Recovery T1561.001 Disk Wipe: Disk Content Wipe T1561.002 Disk Wipe: Disk Structure Wipe T1657 Financial Theft T1583.001 Acquire Infrastructure: Domains T1583.003 Acquire Infrastructure: Virtual Private Server T1583.004 Acquire Infrastructure: Server T1583.006 Acquire Infrastructure: Web Services T1585.001 Establish Accounts: Social Media Accounts T1585.002 Establish Accounts: Email Accounts T1587.001 Develop Capabilities: Malware T1588.001 Obtain Capabilities: Malware T1588.002 Obtain Capabilities: Tool T1589 Gather Victim Identity Information T1595.002 Active Scanning: Vulnerability Scanning T1686.003 Disable or Modify System Firewall: Windows Host Firewall

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.