ShellCodeX
Tools • Events • News • Insights
SEO Checker
Threat Group Profile

handala

Dormant / historical
Victim claims 8
First seen Apr 2026
Last activity 07 Apr 2026
Tracked since May 2024

Group overview

Not a Ransomware Group

Preferred targets

Public Sector · 2 Energy · 1

Most targeted countries

US · 1

Tactics & techniques (MITRE ATT&CK)

Initial Access

Valid Accounts Valid Accounts: Domain Accounts Valid Accounts: Cloud Accounts External Remote Services Exploit Public-Facing Application Trusted Relationship Phishing

Execution

Windows Management Instrumentation Command and Scripting Interpreter: PowerShell Command and Scripting Interpreter: Python Software Deployment Tools User Execution: Malicious File Cloud Administration Command

Persistence

Valid Accounts Valid Accounts: Domain Accounts Valid Accounts: Cloud Accounts Account Manipulation External Remote Services Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Privilege Escalation

Valid Accounts Valid Accounts: Domain Accounts Valid Accounts: Cloud Accounts Account Manipulation Domain or Tenant Policy Modification: Group Policy Modification Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Stealth

Obfuscated Files or Information: Compression Masquerading: Masquerade Task or Service Masquerading: Match Legitimate Resource Name or Location Valid Accounts Valid Accounts: Domain Accounts Valid Accounts: Cloud Accounts Hide Artifacts: Hidden Window Selective Exclusion

Credential Access

OS Credential Dumping: LSASS Memory Brute Force Brute Force: Password Guessing Brute Force: Credential Stuffing Unsecured Credentials: Credentials in Registry

Discovery

System Information Discovery Account Discovery: Domain Account

Lateral Movement

Remote Services: Remote Desktop Protocol Software Deployment Tools

Victim Claims Timeline

Back to radar
🇺🇸 United States

St. Joseph County

We, the members of Handala Hack, proudly announce that through a targeted and intelligent operation, we have completely taken control of the centralized IT infrastructure...

Public Sector
Unknown

PSK WIND’s Defense Networks Fall to Handala Hack

In continuation of our series of cyber operations against the military infrastructure of the Zionist regime, Handala Hack Group has once again struck a decisive blow. Thr...

Energy
Unknown

50 Senior Unit 9900 Officers Exposed

Today, for the first time, the complete details of 50 senior officers from Unit 9900 of the Israeli military intelligence (Aman) have been made public. This historic expo...

Public Sector
Unknown

Raz Zimmt’s Chats Leaked to the World

Raz Zimmt, Head of the Iran Desk  at the Israeli National Security Institute, Once again, you ignored our warnings, and now you’re facing the consequences. We repeatedly...