🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS    ◆    🔴 [LATEST] BREACHFORUMS ADMIN: HASANBROKER WAS A PREDATOR? DARK WEB FORUM WARS EXPLODE

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
HANDALA

/actor/handala/  ·  3 intel reports

Year Established
2023
Attribution
Iran (Suspected)
Motivation
Hacktivism, Pro-Palestinian, Anti-Israel
Modus Operandi (MO)
Destructive wiper attacks, data leaks, psychological operations against Israeli targets
Primary Aliases
Handala Hack, Handala Team

HANDALA is a pro-Palestinian hacktivist group that emerged in late 2023, taking its name from the iconic Palestinian cartoon character Handala created by Naji al-Ali , a symbol of Palestinian resistance and resilience. The group is suspected to have ties to Iranian state intelligence services based on the sophistication of some operations and alignment with known Iranian geopolitical objectives, though this attribution remains contested.

HANDALA gained significant attention for conducting destructive cyber operations against Israeli organisations, including the deployment of wiper malware designed to permanently destroy data on compromised systems rather than encrypting it for ransom. This destructive approach, combined with psychological pressure campaigns, signals a higher operational mandate beyond typical hacktivist financial or notoriety motivations.

The group has claimed responsibility for compromising Israeli water infrastructure systems, radar networks, and government databases , publishing stolen documents and internal communications as evidence. HANDALA has also conducted targeted SMS phishing campaigns against Israeli citizens, sending mass text messages with disturbing content designed to sow panic and undermine public confidence in Israeli security institutions.

HANDALA operates an active Telegram channel with hundreds of thousands of followers, which they use to publish stolen Israeli data, announce operations, and conduct information operations amplifying anti-Israel narratives. Their combination of technical attacks and sophisticated information operations makes them one of the more impactful pro-Palestinian threat actors in the current threat landscape.

Handala operates as a hacktivist leak and disruption brand aligned with Palestinian political messaging. Public cards mix claimed database leaks and website defacements. CyberAsia requires a sample or a unique admin screenshot before upgrading a Handala post from claim to confirmed breach. Do not republish raw PII they dump.

Targets are often poorly patched public sites, not hardened defence networks. WAF, credential hygiene, and a decision not to host donor or member databases on the same CMS as the brochure page will stop most of this class.

STATUS: ACTIVE CLASSIFICATION: HACKTIVIST COLLECTIVE LAST SEEN: Aug 2026

> LINKED_INTEL_REPORTS (3)

Who is HANDALA?
Threat Intelligence Aug 04, 2026

Who is HANDALA?

⚠️ THREAT INTELLIGENCE ADVISORY: In the volatile landscape of Middle Eastern cyber warfare, few names have risen to…

> cd ../articles