Handala is an Iranian state-controlled destructive cyber and information-operations persona that appeared publicly in late 2023. The U.S. Department of Justice said in March 2026 that Handala-hack.to and related seized domains were controlled by Iran’s Ministry of Intelligence and Security and used for hacking, stolen-data publication, threats and psychological operations. This evidence supports a state-actor classification even though Handala’s public messaging presents the persona as a hacktivist collective.
Activity and targeting
Handala has focused heavily on Israeli organizations, officials, military personnel, Iranian dissidents and people or companies it portrays as aligned with Israel or the United States. Its public posts combine ideological retaliation narratives with claims of destructive attacks, data theft, doxxing and threats. The Justice Department said the Handala domain was used March 11, 2026, to claim a destructive attack against a U.S.-based multinational medical technology company, matching the Stryker incident.
Victim posts remain actor assertions unless the affected organization, technical evidence or another authoritative source corroborates them. In the Stryker case, the confirmed global disruption and device wiping support the underlying destructive attack, while Handala’s claims of more than 200,000 affected devices and 50 TB of theft remain unverified.
Methods and operational characteristics
Palo Alto Networks Unit 42 tracks Handala as Void Manticore, COBALT MYSTIQUE and Storm-1084 or Storm-0842. It reported that recent destructive operations associated with the cluster relied on identity compromise through phishing and administrative access to Microsoft Intune. The group targets highly privileged accounts and uses legitimate enterprise administration capabilities for remote wiping, allowing destructive effects without relying only on a conventional encryptor or novel wiper binary.
Handala also uses public claim sites and social channels as part of its operations. Its messaging amplifies destructive effects, alleges data theft and publishes or threatens sensitive information to create psychological and reputational impact. Those information operations can accompany genuine compromise while still exaggerating scope or mixing verified and unverified assertions.
What type of group is it?
Handala is best characterized as an Iranian state actor operating through a hacktivist-style persona. The Justice Department directly tied its controlled domains to Iran’s Ministry of Intelligence and Security, while Unit 42 described it as a state-directed front. Its activity emphasizes destructive disruption, hack-and-leak operations and psychological pressure rather than a conventional financially motivated ransomware service. Public evidence does not identify every operator or establish that every Handala claim represents a successful intrusion.