What began in December 2023 as an apparently grassroots pro-Palestinian hacktivist operation has evolved into one of Iran's most visible and active cyber warfare instruments. Handala Hack Team, named after the iconic Palestinian cartoon character created by Naji al-Ali in 1969, has been independently attributed by Microsoft, Check Point, and multiple intelligence agencies to Iranian state-sponsored cyber operations under the Ministry of Intelligence and Security (MOIS).
Attribution Chain
In 2024, Microsoft published reports attributing Handala to the Iranian attack group Storm-0842, also tracked as Banished Kitten or Dune. Storm-0842 is connected to the MOIS and is also responsible for operations under the identities DarkBit and Homeland Justice. Check Point Research independently assesses Handala as one of several online personas maintained by Void Manticore, a confirmed MOIS-affiliated destructive actor. In August 2025, Iran International TV exposed the identities of several Handala members, reporting the cyber unit is led by Yahya Hosseini Panjkhi. In January 2026, Check Point observed Handala routing operations through Starlink IP ranges during Iran's nationwide internet shutdown, probing externally facing applications for misconfigurations and weak credentials.
Evolution of Capabilities
Handala's operational trajectory demonstrates a clear escalation from basic hacktivism to structured cyber operations. In its first phase from December 2023 through early 2024, the group conducted website defacements, DDoS attacks, and data leaks on BreachForums with approximately 140 posts across cybercrime forums. The second phase spanning mid-2024 saw a transition to wiper malware deployment, sophisticated phishing impersonating CrowdStrike and F5, and ransomware against Israeli critical infrastructure. Phase three from late 2024 through early 2025 brought targeted espionage against senior Israeli officials through the Bibi Gate Telegram breaches and mass data exfiltration from law enforcement. The current fourth phase beginning in 2025 has seen geographic expansion beyond Israel to Gulf energy infrastructure, collaboration with Iran's Electronic Operations Room, and integration into state-level escalation campaigns.
Operational Playbook
Handala's core tactics rely on phishing and social engineering rather than advanced exploit development. The group impersonates trusted vendors including CrowdStrike, F5, and government agencies to deliver payloads. Hebrew-language lures are well-crafted, suggesting at least one fluent Hebrew speaker. The group uses Telegram for command and control, AutoIT for process injection, and maintains presence across BreachForums, Ramp, Exploit, and its own leak site. Data exfiltration uses cloud storage services, and the group has demonstrated ability to pivot from IT service providers to downstream victims through supply-chain access. Leaked materials are released on a calculated schedule to maximize media coverage.
By the Numbers
Between December 2023 and March 2026, Handala's documented activity includes at least 85 attacks in its first year alone according to the International Institute for Counter-Terrorism, with 58 confirmed Israeli victims tracked by Ransomware.live across technology, government, energy, healthcare, and manufacturing sectors. Notable operations include the 2.1 terabyte Israeli Police breach, Soreq Nuclear Research Center intrusion claims, kindergarten emergency alert hijacking, diplomatic email compromises of multiple former prime ministers, the Clalit healthcare breach, and the 2026 Gulf energy campaign targeting Saudi Aramco and Sharjah National Oil Corporation.
Assessment
Handala represents a model increasingly favored by Iranian intelligence: deniable hacktivist personas that provide operational flexibility and media impact while maintaining plausible distance from state direction. The group's strength lies not in technical sophistication but in operational tempo, psychological targeting, and the ability to convert modest technical compromises into outsized media and political impact. As Unit 42 noted in its March 2026 threat brief, Handala is optimized for psychological and reputational disruption rather than sustained network penetration.