INTEL_REPORT
Check Point Research · published 3/12/2026, 5:21:23 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
“Handala Hack” – Unveiling Group’s Modus Operandi Key Findings Introduction Handala Hack, also tracked by Check Point Research as Void Manticore, is an Iranian threat actor that is known for multiple destructive wiping attacks combined with “hack and leak” operations. The threat actor operates several online personas, with the most prominent among them being Homeland Justice, maintained from mid-2022 specifically for multiple attacks […] The post “Handala Hack” &#…
https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi
sha256:88b57683f4c242a1b83dc6a154ab554273a10748927507146cd54a17b8691054
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| domain | wmic.exe | Open → |
| domain | handala.exe | Open → |
| domain | handala.bat | Open → |
| domain | item.fullname | Open → |
| domain | handala.rar | Open → |
| md5 | 5986ab04dd6b3d259935249741d3eff2 | Open → |
| md5 | 3cb9dea916432ffb8784ac36d1f2d3cd | Open → |
| md5 | 3236facc7a30df4ba4e57fddfba41ec5 | Open → |
| md5 | 3dfb151d082df7937b01e2bb6030fe4a | Open → |
| md5 | e035c858c1969cffc1a4978b86e90a30 | Open → |