Skip to content

Handala

Handala is described in the provided content both as an Iran-aligned cyber group/pro-Palestinian hacktivist persona linked to Iran and as a destructive malware/wiper family used in disruptive operations.

Profile source: Mallory opens in a new tab

Handala

Family profile

Handala is described in the provided content both as an Iran-aligned cyber group/pro-Palestinian hacktivist persona linked to Iran and as a destructive malware/wiper family used in disruptive operations. The malware is characterized as a destructive wiper capable of irreversibly wiping data from infected systems, rendering systems inoperable, spreading rapidly across networks, and using evasion techniques. Splunk’s 2024 analytics story on the Handala wiper states defenders should monitor for unexpected regasm processes, unauthorized AutoIt script execution, malicious driver drops, abrupt system slowdowns, and creation of unknown files or processes. The content says Handala has been used against critical infrastructure and organizations and can cause major disruption, downtime, financial loss, data loss, and compromise of sensitive information.

The content also links Handala to healthcare-sector targeting. It states that Handala, described there as an Iran-aligned cyber group, targeted a medical technology organization in 2026 with data exfiltration and destructive actions. A separate report says Stryker suffered a major cyberattack involving wiper malware claimed by Handala; Handala allegedly claimed theft of 50 TB of data and wiping of more than 200,000 systems, servers, and mobile devices, while Stryker confirmed a global disruption affecting its Microsoft environment.

A more detailed intrusion chain in the content associates the name Handala with a Delphi-coded second-stage loader observed in Operation HamsaUpdate, a phishing campaign targeting Israeli customers using F5-themed lures. In that campaign, Windows victims were instructed to execute a ZIP-delivered .NET loader masquerading as an F5 update tool. One variant extracted Handala.exe, a Delphi second-stage loader, which launched an AutoIt-based injector chain. The chain used a renamed AutoIt interpreter (Naples.pif) and an obfuscated script to inject RC4-decrypting shellcode, decompress payloads with LZNT1, and communicate over HTTPS with 31.192.237[.]207:2515. In the same campaign, the Windows wiper payload Hatef overwrote files with random data and deleted them across key directories and drives, while the Linux payload Hamsa used a heavily obfuscated bash script to delete user accounts, wipe home directories, destroy partitions, delete system binaries, and reboot the host. Both variants reported execution details to a Telegram bot/channel identified in the content. The report notes that a group calling itself "Handala Hack Team" claimed responsibility, but also states there was insufficient basis for attribution and that a false hacktivist persona was possible.

PolySwarm telemetry cited in the content observed continued circulation of HANDALA alongside other destructive and criminal malware families during the period leading up to and coinciding with the 2026 FIFA World Cup.

Operational record

1
YARA rules
5
Leak sites
3 available

Reported operators

Threat actors

1 named in public reporting
Handala

Stryker has suffered a major cyberattack involving wiper malware claimed by Handala, a pro-Palestinian hacktivist group linked to Iran.

MITRE ATT&CK

Handala in ATT&CK

70 distinct techniques

Techniques

70 techniques
T1485 Data Destruction T1027 Obfuscated Files or Information T1562.001 Disable or Modify Tools T1057 Process Discovery T1036 Masquerading T1059.003 Windows Command Shell T1105 Ingress Tool Transfer T1055 Process Injection T1204 User Execution T1078 Valid Accounts T1078.002 Valid Accounts: Domain Accounts T1078.004 Valid Accounts: Cloud Accounts T1133 External Remote Services T1190 Exploit Public-Facing Application T1199 Trusted Relationship T1566 Phishing T1047 Windows Management Instrumentation T1059.001 Command and Scripting Interpreter: PowerShell T1059.006 Command and Scripting Interpreter: Python T1072 Software Deployment Tools T1204.002 User Execution: Malicious File T1651 Cloud Administration Command T1098 Account Manipulation T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1484.001 Domain or Tenant Policy Modification: Group Policy Modification T1027.015 Obfuscated Files or Information: Compression T1036.004 Masquerading: Masquerade Task or Service T1036.005 Masquerading: Match Legitimate Resource Name or Location T1564.003 Hide Artifacts: Hidden Window T1679 Selective Exclusion T1684.001 Social Engineering: Impersonation T1003.001 OS Credential Dumping: LSASS Memory T1110 Brute Force T1110.001 Brute Force: Password Guessing T1110.004 Brute Force: Credential Stuffing T1552.002 Unsecured Credentials: Credentials in Registry T1082 System Information Discovery T1087.002 Account Discovery: Domain Account T1021.001 Remote Services: Remote Desktop Protocol T1005 Data from Local System T1074 Data Staged T1113 Screen Capture T1114.002 Email Collection: Remote Email Collection T1119 Automated Collection T1123 Audio Capture T1125 Video Capture T1213.002 Data from Information Repositories: Sharepoint T1560.001 Archive Collected Data: Archive via Utility T1041 Exfiltration Over C2 Channel T1071.001 Application Layer Protocol: Web Protocols T1102 Web Service T1219.002 Remote Access Tools: Remote Desktop Software T1572 Protocol Tunneling T1486 Data Encrypted for Impact T1490 Inhibit System Recovery T1561.001 Disk Wipe: Disk Content Wipe T1561.002 Disk Wipe: Disk Structure Wipe T1657 Financial Theft T1583.001 Acquire Infrastructure: Domains T1583.003 Acquire Infrastructure: Virtual Private Server T1583.004 Acquire Infrastructure: Server T1583.006 Acquire Infrastructure: Web Services T1585.001 Establish Accounts: Social Media Accounts T1585.002 Establish Accounts: Email Accounts T1587.001 Develop Capabilities: Malware T1588.001 Obtain Capabilities: Malware T1588.002 Obtain Capabilities: Tool T1589 Gather Victim Identity Information T1595.002 Active Scanning: Vulnerability Scanning T1686.003 Disable or Modify System Firewall: Windows Host Firewall

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.