Description Summary
Handala is a hacktivist-aligned operation that emerged in late 2023 and surged in 2024, targeting Israeli organizations with ransomware and data leaks. Branded with imagery referencing Palestinian iconography, the group is assessed to be politically motivated and possibly state-aligned with Iran.
Threat Actor
Hacktivist/political alignment; assessed Iranian-aligned actor.
Technical Indicators
Encryption Extension
Varies
Encryption Algorithm
AES + RSA
Ransom Note Name
README.txt
Targeted Industries
Israeli technology, defense, healthcare, government
First Seen
December 2023
Last Seen
Active
Geographical Location
Israel (primary)
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |