Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Scheduled Pinned Locked Moved Uncategorized
threatintelhandala
44 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Handala continues to be crazy town, with data dumps of what is allegedly to be SSV Network, a blockchain company.

    Handala claim they can link it (SSV Network) to Unit 8200, the Israeli intelligence agency. So far this appears to be without proof.

    I’m going to guess, based on this post, they plan to post more tomorrow about Unit 8200.

    #Handala #threatintel

    Link Preview Image
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.social
    wrote on last edited by
    #17

    So with the Unit 8200 stuff and Handala, their latest claim is they gained access to Silicom Limited (an IT services and networking company) and exfiltrated data, and that Silicom is a front company for Unit 8200.

    Presented evidence includes a video accessing an internal VMware vCentre cluster with about 50tb of storage.

    #Handala #threatintel

    Link Preview Image
    gossithedog@cyberplace.socialG 1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      So with the Unit 8200 stuff and Handala, their latest claim is they gained access to Silicom Limited (an IT services and networking company) and exfiltrated data, and that Silicom is a front company for Unit 8200.

      Presented evidence includes a video accessing an internal VMware vCentre cluster with about 50tb of storage.

      #Handala #threatintel

      Link Preview Image
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.social
      wrote on last edited by
      #18

      Handala claim to be inside the Silicom incident response process, and that they’ve wiped 300 systems. #Handala #threatintel

      Link Preview Image
      gossithedog@cyberplace.socialG 1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        Handala claim to be inside the Silicom incident response process, and that they’ve wiped 300 systems. #Handala #threatintel

        Link Preview Image
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.social
        wrote on last edited by
        #19

        Btw the Silicom thing is interesting - Silicom sell OEMs networking kit and cards inside server which is rebranded on sale, ie people see their products as other company. The Handala claim is that Silicom is a Unit 8200 (Israeli signals intelligence) front company, for onward access. #Handala #threatintel

        gossithedog@cyberplace.socialG 1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Btw the Silicom thing is interesting - Silicom sell OEMs networking kit and cards inside server which is rebranded on sale, ie people see their products as other company. The Handala claim is that Silicom is a Unit 8200 (Israeli signals intelligence) front company, for onward access. #Handala #threatintel

          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.social
          wrote on last edited by
          #20

          Handala are one year old today. They are billing next week “destructive week”. #Handala #threatintel

          gossithedog@cyberplace.socialG 1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            Handala are one year old today. They are billing next week “destructive week”. #Handala #threatintel

            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            wrote on last edited by
            #21

            Masoumeh Karbasi & Reza Avazeh were killed in a drone strike in Lebanon in October. As far as I can see nobody knew why publicly, Handala’s linking Reza to Hezbollah and their cybersecurity appears to be a first.

            His children were invited to meet ‘Supreme Leader of the Islamic Revolution’ that week. https://farsi.khamenei.ir/news-content?id=58050

            #Handala #threatintel

            gossithedog@cyberplace.socialG 1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Masoumeh Karbasi & Reza Avazeh were killed in a drone strike in Lebanon in October. As far as I can see nobody knew why publicly, Handala’s linking Reza to Hezbollah and their cybersecurity appears to be a first.

              His children were invited to meet ‘Supreme Leader of the Islamic Revolution’ that week. https://farsi.khamenei.ir/news-content?id=58050

              #Handala #threatintel

              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.social
              wrote on last edited by
              #22

              Handala say they plan their most destructive hack so far this weekend, over the fate of Reza Avazeh

              There’s even a video, but sadly no hoodie wearing hackers

              #Handala #threatintel

              gossithedog@cyberplace.socialG 1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                Handala say they plan their most destructive hack so far this weekend, over the fate of Reza Avazeh

                There’s even a video, but sadly no hoodie wearing hackers

                #Handala #threatintel

                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.social
                wrote on last edited by
                #23

                Handala claim to have gained access to
                CaaB Cloud (https://caab.cloud), aka Cloud as a Business, posting a video of administrator access. CAAB Cloud describe themselves as “The MSP’s Cloud” in marketing.

                CAAB Cloud is owned and operated by GNS in Israel, aka https://gns.cloud

                It is unclear if the claims are credible. CaaB’s status page suggest a ~10% availability impact in one of their Israeli datacenters three days ago on cloud VM. https://status.caab.cloud

                #Handala #threatintel

                gossithedog@cyberplace.socialG 1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Handala claim to have gained access to
                  CaaB Cloud (https://caab.cloud), aka Cloud as a Business, posting a video of administrator access. CAAB Cloud describe themselves as “The MSP’s Cloud” in marketing.

                  CAAB Cloud is owned and operated by GNS in Israel, aka https://gns.cloud

                  It is unclear if the claims are credible. CaaB’s status page suggest a ~10% availability impact in one of their Israeli datacenters three days ago on cloud VM. https://status.caab.cloud

                  #Handala #threatintel

                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.social
                  wrote on last edited by
                  #24

                  Handala suggests they got access to Ehud Barak’s iPad using a BYOD management profile. #Handala #threatintel

                  Link Preview Image
                  gossithedog@cyberplace.socialG 1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    Handala suggests they got access to Ehud Barak’s iPad using a BYOD management profile. #Handala #threatintel

                    Link Preview Image
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.social
                    wrote on last edited by
                    #25

                    A bit on the nose writing 🤣 #Handala #threatintel

                    Link Preview Image
                    gossithedog@cyberplace.socialG 1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      A bit on the nose writing 🤣 #Handala #threatintel

                      Link Preview Image
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.social
                      wrote on last edited by
                      #26

                      Handala have gained access to Reutone, a SaaS CRM supplier, and forward phished customers with a Trojan. Write up later. #Handala #threatintel

                      Link Preview Image
                      gossithedog@cyberplace.socialG 1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Handala have gained access to Reutone, a SaaS CRM supplier, and forward phished customers with a Trojan. Write up later. #Handala #threatintel

                        Link Preview Image
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.social
                        wrote on last edited by
                        #27

                        I wrote up the Handala attack on ReutOne, includes the first IoCs on Handala's python trojan

                        Just a moment...

                        favicon

                        (doublepulsar.com)

                        gossithedog@cyberplace.socialG 1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          I wrote up the Handala attack on ReutOne, includes the first IoCs on Handala's python trojan

                          Just a moment...

                          favicon

                          (doublepulsar.com)

                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.social
                          wrote on last edited by
                          #28

                          Handala has also defaced ReutOne’s website, and published videos of RDP access to ReutOne’s internal network, eg Active Directory Certificate Authority etc. https://web.archive.org/web/20241226141650/https://www.reutone.com/

                          #threatintel #Handala

                          Link Preview Image
                          gossithedog@cyberplace.socialG 1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Handala has also defaced ReutOne’s website, and published videos of RDP access to ReutOne’s internal network, eg Active Directory Certificate Authority etc. https://web.archive.org/web/20241226141650/https://www.reutone.com/

                            #threatintel #Handala

                            Link Preview Image
                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.social
                            wrote on last edited by
                            #29

                            Handala claim they hacked Allen Carr's Easyway via ReutOne.

                            Two points:

                            a) I legit thought they had hacked UK national treasure Alan Carr for a moment

                            2) "reportedly", lol. ChatGPT doing overtime for Handala.

                            Link Preview Image
                            gossithedog@cyberplace.socialG 1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              Handala claim they hacked Allen Carr's Easyway via ReutOne.

                              Two points:

                              a) I legit thought they had hacked UK national treasure Alan Carr for a moment

                              2) "reportedly", lol. ChatGPT doing overtime for Handala.

                              Link Preview Image
                              gossithedog@cyberplace.socialG This user is from outside of this forum
                              gossithedog@cyberplace.socialG This user is from outside of this forum
                              gossithedog@cyberplace.social
                              wrote on last edited by
                              #30

                              The '100K messages sent' thing is a reference to Handala abusing WhatsApp Business accounts, my English translation of message they've been sending.

                              #handala #threatintel

                              Link Preview Image
                              gossithedog@cyberplace.socialG 1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                The '100K messages sent' thing is a reference to Handala abusing WhatsApp Business accounts, my English translation of message they've been sending.

                                #handala #threatintel

                                Link Preview Image
                                gossithedog@cyberplace.socialG This user is from outside of this forum
                                gossithedog@cyberplace.socialG This user is from outside of this forum
                                gossithedog@cyberplace.social
                                wrote on last edited by
                                #31

                                Handala claim they will be wiping Mossad’s financial network today. Also, they appear to have purchased ChatGPT premium.

                                #handala #threatintel

                                gossithedog@cyberplace.socialG 1 Reply Last reply
                                0
                                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                  Handala claim they will be wiping Mossad’s financial network today. Also, they appear to have purchased ChatGPT premium.

                                  #handala #threatintel

                                  gossithedog@cyberplace.socialG This user is from outside of this forum
                                  gossithedog@cyberplace.socialG This user is from outside of this forum
                                  gossithedog@cyberplace.social
                                  wrote on last edited by
                                  #32

                                  One note, they fully respected the dates of the ceasefire last time but apparently aren’t bothered this time? #handala #threatintel

                                  Edit: derp, it was Cyber Toufan who respected the ceasefire, not Handala.

                                  gossithedog@cyberplace.socialG 1 Reply Last reply
                                  0
                                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                    One note, they fully respected the dates of the ceasefire last time but apparently aren’t bothered this time? #handala #threatintel

                                    Edit: derp, it was Cyber Toufan who respected the ceasefire, not Handala.

                                    gossithedog@cyberplace.socialG This user is from outside of this forum
                                    gossithedog@cyberplace.socialG This user is from outside of this forum
                                    gossithedog@cyberplace.social
                                    wrote on last edited by
                                    #33

                                    Handala claim to have done a hack and wipe of Zuk Group, an Israel group of financial companies. Their website has been defaced as of writing.

                                    Handala posted a series of videos appearing to show access to their internal network.

                                    Handala also claim the company is a front for Mossad. They offer no evidence of that bit.

                                    #handala #threatintel

                                    Link Preview Image
                                    gossithedog@cyberplace.socialG 1 Reply Last reply
                                    0
                                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                      Handala claim to have done a hack and wipe of Zuk Group, an Israel group of financial companies. Their website has been defaced as of writing.

                                      Handala posted a series of videos appearing to show access to their internal network.

                                      Handala also claim the company is a front for Mossad. They offer no evidence of that bit.

                                      #handala #threatintel

                                      Link Preview Image
                                      gossithedog@cyberplace.socialG This user is from outside of this forum
                                      gossithedog@cyberplace.socialG This user is from outside of this forum
                                      gossithedog@cyberplace.social
                                      wrote on last edited by
                                      #34

                                      Handala got booted off Telegram after the Zuk Group hack.

                                      They’re back on another channel and posted:

                                      “وَ كَمْ قَصَمْنا مِنْ قَرْيَةٍ كانَتْ ظالِمَةً ... بَلْ نَقْذِفُ بِالْحَقِّ عَلَى الْباطِلِ فَيَدْمَغُهُ فَإِذا هُوَ زاهِقٌ‌ ...”

                                      Which translates to

                                      “How many a city have We destroyed which was unjust... Rather, We cast the truth upon falsehood, and it destroys it, and at once it departs...”

                                      #handala #threatintel

                                      gossithedog@cyberplace.socialG 1 Reply Last reply
                                      0
                                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                        Handala got booted off Telegram after the Zuk Group hack.

                                        They’re back on another channel and posted:

                                        “وَ كَمْ قَصَمْنا مِنْ قَرْيَةٍ كانَتْ ظالِمَةً ... بَلْ نَقْذِفُ بِالْحَقِّ عَلَى الْباطِلِ فَيَدْمَغُهُ فَإِذا هُوَ زاهِقٌ‌ ...”

                                        Which translates to

                                        “How many a city have We destroyed which was unjust... Rather, We cast the truth upon falsehood, and it destroys it, and at once it departs...”

                                        #handala #threatintel

                                        gossithedog@cyberplace.socialG This user is from outside of this forum
                                        gossithedog@cyberplace.socialG This user is from outside of this forum
                                        gossithedog@cyberplace.social
                                        wrote on last edited by
                                        #35

                                        Handala claim to have hacked the Ministry of National Security in Israel, activated red alert to get people into shelters, closed the doors, then played a song and wiped the system.

                                        Very unclear how widespread or credible this is, although some Israeli social media posts show devices going off and playing songs.

                                        #handala #threatintel

                                        gossithedog@cyberplace.socialG 1 Reply Last reply
                                        0
                                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                          Handala claim to have hacked the Ministry of National Security in Israel, activated red alert to get people into shelters, closed the doors, then played a song and wiped the system.

                                          Very unclear how widespread or credible this is, although some Israeli social media posts show devices going off and playing songs.

                                          #handala #threatintel

                                          gossithedog@cyberplace.socialG This user is from outside of this forum
                                          gossithedog@cyberplace.socialG This user is from outside of this forum
                                          gossithedog@cyberplace.social
                                          wrote on last edited by
                                          #36

                                          They also claim they have hacked Israeli police pagers and are broadcasting song on them, claim to have taken security ID information and delivery certificates for weapons. #handala #threatintel

                                          gossithedog@cyberplace.socialG 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups