Skip to content

Handala

State Actor1 claimLast activity:
Also known as:
  • COBALT MYSTIQUE · Alias
  • Handala Hack · Alias
  • Storm-0842 · Alias
  • Storm-1084 · Alias
  • Void Manticore · Alias

Overview

Handala is an Iranian state-controlled destructive cyber and information-operations persona that appeared publicly in late 2023. The U.S. Department of Justice said in March 2026 that Handala-hack.to and related seized domains were controlled by Iran’s Ministry of Intelligence and Security and used for hacking, stolen-data publication, threats and psychological operations. This evidence supports a state-actor classification even though Handala’s public messaging presents the persona as a hacktivist collective.

Activity and targeting

Handala has focused heavily on Israeli organizations, officials, military personnel, Iranian dissidents and people or companies it portrays as aligned with Israel or the United States. Its public posts combine ideological retaliation narratives with claims of destructive attacks, data theft, doxxing and threats. The Justice Department said the Handala domain was used March 11, 2026, to claim a destructive attack against a U.S.-based multinational medical technology company, matching the Stryker incident.

Victim posts remain actor assertions unless the affected organization, technical evidence or another authoritative source corroborates them. In the Stryker case, the confirmed global disruption and device wiping support the underlying destructive attack, while Handala’s claims of more than 200,000 affected devices and 50 TB of theft remain unverified.

Methods and operational characteristics

Palo Alto Networks Unit 42 tracks Handala as Void Manticore, COBALT MYSTIQUE and Storm-1084 or Storm-0842. It reported that recent destructive operations associated with the cluster relied on identity compromise through phishing and administrative access to Microsoft Intune. The group targets highly privileged accounts and uses legitimate enterprise administration capabilities for remote wiping, allowing destructive effects without relying only on a conventional encryptor or novel wiper binary.

Handala also uses public claim sites and social channels as part of its operations. Its messaging amplifies destructive effects, alleges data theft and publishes or threatens sensitive information to create psychological and reputational impact. Those information operations can accompany genuine compromise while still exaggerating scope or mixing verified and unverified assertions.

What type of group is it?

Handala is best characterized as an Iranian state actor operating through a hacktivist-style persona. The Justice Department directly tied its controlled domains to Iran’s Ministry of Intelligence and Security, while Unit 42 described it as a state-directed front. Its activity emphasizes destructive disruption, hack-and-leak operations and psychological pressure rather than a conventional financially motivated ransomware service. Public evidence does not identify every operator or establish that every Handala claim represents a successful intrusion.

Incident claim

Stryker global destructive cyberattack

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Handala listed Stryker Corporation March 11 and claimed it wiped more than 200,000 systems, servers and mobile devices and stole 50 TB of data, framing the operation as retaliation. Stryker later confirmed unauthorized access and global destructive effects, and its CEO said about 40,000 laptops were wiped, but the company did not validate Handala’s device count, alleged theft or attribution. The Justice Department later said an Iran Ministry of Intelligence and Security-controlled Handala domain was used to claim the destructive attack. The evidence supports a high-confidence connection to the intrusion, not every claim assertion.

Impacted organizations

Impacted locations

Sources