Handala Hack Team
MITRE G1016Also known as Handala, Void Manticore, Handala Popular Resistance Front, Handala Hack Team, Red Sandstorm, Storm-0842, Banished Kitten, TAG-145, HPRF, Cobalt Mystique
Reports
10
First seen
Mar 31, 2026
Last seen
Jul 21, 2026
Motivation
Hacktivism, Sabotage, Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×1×2
United States×2
Israel×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×8T1005 Data from Local System ×6T1486 Data Encrypted for Impact ×5T1078 Valid Accounts ×4T1041 Exfiltration Over C2 Channel ×4T1110 Brute Force ×4T1190 Exploit Public-Facing Application ×4T1195 Supply Chain Compromise ×3T1003 OS Credential Dumping ×3T1561 Disk Wipe ×3T1567 Exfiltration Over Web Service ×2T1589 Gather Victim Identity Information ×2
Indicators
cve ×53domain ×13email ×1filename ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High