Handala is a pro-Palestinian hacktivist group conducting wiper attacks on Israeli organizations.
Analyst brief
Handala is a pro-Palestinian hacktivist group that primarily targets Israeli organizations. Their TTPs include phishing, data theft, extortion, and destructive attacks using custom wiper malware. The group gains initial access by exploiting critical vulnerabilities and conducting phishing campaigns that leverage major events, then delivers wiper payloads to both Windows and Linux environments via a multi-stage loading process involving a Delphi-based second-stage loader and an AutoIT injector. Defenders should heighten vigilance against phishing emails during significant events, patch critical vulnerabilities promptly, and focus on detecting the multi-stage loading chain to block the transition to wiper operations.
Handala
unknown
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive attacks using custom wiper malware. The group utilizes a multi-stage loading process, including a Delphi-coded second-stage loader and an AutoIT injector, to deliver wiper malware that specifically targets Windows and Linux environments. Their phishing campaigns often exploit major events and critical vulnerabilities, masquerading as legitimate organizations to gain initial access. Handala operates a data leak site to publicize stolen data, although claims of successful attacks are sometimes disputed by targeted organizations.