Handala
Iranian state-sponsored (MOIS — Ministry of Intelligence and Security) · Politically motivated disruption / hack-and-leak / psychological operations against Israel and Western interests
Tactics, Techniques & Procedures (TTPs)
- Hack-and-leak operations against Israeli government, military, and private sector organisations
- Wiper malware deployment for destructive impact against Israeli targets
- Third-party SaaS platform exploitation for lateral access to adjacent operational or billing systems
- Exaggerated OT compromise claims for influence operations (capability systematically overstated in public statements)
- Data publication via Telegram and dedicated leak sites
- US and Western critical infrastructure targeting as retaliation for US-Iran military engagement
- Internet-facing industrial and positioning platform exploitation as entry to utility-adjacent systems
Known Targets
Analyst Notes
See also: Handala (MOIS / Banished Kitten). Handala has been active since December 2023, escalating operations following the October 2023 conflict in Gaza and again following US military action against Iranian targets from February 2026. Named after a Palestinian cartoon character; explicitly frames operations as political retaliation. The June 2026 Cal Water breach demonstrated the third-party SaaS-to-billing-system access pattern but Mandiant confirmed no OT access. Distinguishing actual operational impact from influence exaggeration is essential in Handala incident assessment.
Also Known As