Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Scheduled Pinned Locked Moved Uncategorized
threatintelhandala
51 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Handala claim to have done a hack and wipe of Tosaf, a plastics manufacturer.

    Screenshots show apparent Windows domain admin access, and they attach CCTV videos of themselves playing songs into a factory and an office, with workers looking confused.

    #handala #threatintel

    Link Preview Image
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.social
    wrote on last edited by
    #39

    Handala have been fully kicked off Telegram, including their backup channel.

    Achievement unlocked as I can't remember a group ever getting fully booted.

    #threatintel #handala

    gossithedog@cyberplace.socialG 1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Handala have been fully kicked off Telegram, including their backup channel.

      Achievement unlocked as I can't remember a group ever getting fully booted.

      #threatintel #handala

      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.social
      wrote last edited by
      #40

      Handala appear to have fully wiped a company called Stryker, a global healthcare company.

      Not in the link but they've got into AD, and wiped all the devices with Intune etc etc.

      Link Preview Image
      Stryker cyber attack - Irish unable to work as hackers cripple global systems

      All IT systems at Stryker, which employs 4,000 people in its Cork base, remain down.

      favicon

      Irish Mirror (www.irishmirror.ie)

      gossithedog@cyberplace.socialG 1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        Handala appear to have fully wiped a company called Stryker, a global healthcare company.

        Not in the link but they've got into AD, and wiped all the devices with Intune etc etc.

        Link Preview Image
        Stryker cyber attack - Irish unable to work as hackers cripple global systems

        All IT systems at Stryker, which employs 4,000 people in its Cork base, remain down.

        favicon

        Irish Mirror (www.irishmirror.ie)

        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.social
        wrote last edited by
        #41

        Some more on Stryker situation.

        Link Preview Image
        gossithedog@cyberplace.socialG 1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Some more on Stryker situation.

          Link Preview Image
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.social
          wrote last edited by
          #42

          Handala have claimed responsibility to me, saying they wiped about a quarter of a mil endpoints. They say it’s because of the strike on a girls’ primary school in Minab, in Iran’s Hormozgan province, which killed close to 200 people.

          gossithedog@cyberplace.socialG simonzerafa@infosec.exchangeS 2 Replies Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            Handala have claimed responsibility to me, saying they wiped about a quarter of a mil endpoints. They say it’s because of the strike on a girls’ primary school in Minab, in Iran’s Hormozgan province, which killed close to 200 people.

            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            wrote last edited by
            #43

            There’s an entire thread tracking Handala above btw, goes back multiple years. Some bits need follow links to the thread as I broke it.

            Their MO is break in, lay low for months, when target interesting exfiltrate data and then delete everything including org backups. They pivot to domain admin early and then sit on access for later. They live off land and live off org IT documentation.

            gossithedog@cyberplace.socialG 1 Reply Last reply
            1
            0
            • R relay@relay.infosec.exchange shared this topic
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Handala have claimed responsibility to me, saying they wiped about a quarter of a mil endpoints. They say it’s because of the strike on a girls’ primary school in Minab, in Iran’s Hormozgan province, which killed close to 200 people.

              simonzerafa@infosec.exchangeS This user is from outside of this forum
              simonzerafa@infosec.exchangeS This user is from outside of this forum
              simonzerafa@infosec.exchange
              wrote last edited by
              #44

              @GossiTheDog

              Yikes! That's a lot of endpoints and associated servers and other infrastructure.

              I wonder if they will be able to recover? Particularly if the backups are gone and there are no others in cold storage somewhere.

              As they have discovered, blowback can be painful and expensive or even unrecoverable.

              1 Reply Last reply
              1
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                There’s an entire thread tracking Handala above btw, goes back multiple years. Some bits need follow links to the thread as I broke it.

                Their MO is break in, lay low for months, when target interesting exfiltrate data and then delete everything including org backups. They pivot to domain admin early and then sit on access for later. They live off land and live off org IT documentation.

                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.social
                wrote last edited by
                #45

                Stryker have filed an 8-K with the SEC for their wiper incident.

                "The Company has no indication of ransomware or malware and believes the incident is contained."

                Almost like Handala lived off the land..

                SEC.gov | Your Request Originates from an Undeclared Automated Tool

                favicon

                (www.sec.gov)

                Link Preview Image
                gossithedog@cyberplace.socialG 1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Stryker have filed an 8-K with the SEC for their wiper incident.

                  "The Company has no indication of ransomware or malware and believes the incident is contained."

                  Almost like Handala lived off the land..

                  SEC.gov | Your Request Originates from an Undeclared Automated Tool

                  favicon

                  (www.sec.gov)

                  Link Preview Image
                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.social
                  wrote last edited by
                  #46

                  Handala statement on their hack of Stryker

                  Link Preview Image
                  gossithedog@cyberplace.socialG 1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    Handala statement on their hack of Stryker

                    Link Preview Image
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.social
                    wrote last edited by
                    #47

                    Stryker have a liveblog of their security incident, linked from the front page of their website:

                    Link Preview Image
                    Customer Updates: Stryker Network Disruption

                    favicon

                    (www.stryker.com)

                    tl;dr is most customer systems aren't impacted as they run on Linux, but their corporate Windows systems are toast so please hold the line.

                    gossithedog@cyberplace.socialG 1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      Stryker have a liveblog of their security incident, linked from the front page of their website:

                      Link Preview Image
                      Customer Updates: Stryker Network Disruption

                      favicon

                      (www.stryker.com)

                      tl;dr is most customer systems aren't impacted as they run on Linux, but their corporate Windows systems are toast so please hold the line.

                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.social
                      wrote last edited by
                      #48

                      Stryker filed an 8-K with the SEC saying no indication of malware on their environment - yet Palo-Alto's DFIR statement says they have removed malware from Stryker's environment.

                      Link Preview ImageLink Preview Image
                      gossithedog@cyberplace.socialG 1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Stryker filed an 8-K with the SEC saying no indication of malware on their environment - yet Palo-Alto's DFIR statement says they have removed malware from Stryker's environment.

                        Link Preview ImageLink Preview Image
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.social
                        wrote last edited by
                        #49

                        Handala have phished Kash Patel, the director of the FBI, and released his emails.

                        See the prior rest of thread on this, they've been doing it for years with Israeli politicians - they just phish Gmail and iCloud logins, then sync devices.

                        The FBI have confirmed the emails are authentic. It looks like they are releasing them in batches.

                        Link Preview Image
                        rtificial@infosec.exchangeR kluthulhu@infosec.exchangeK 2 Replies Last reply
                        1
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          Handala have phished Kash Patel, the director of the FBI, and released his emails.

                          See the prior rest of thread on this, they've been doing it for years with Israeli politicians - they just phish Gmail and iCloud logins, then sync devices.

                          The FBI have confirmed the emails are authentic. It looks like they are releasing them in batches.

                          Link Preview Image
                          rtificial@infosec.exchangeR This user is from outside of this forum
                          rtificial@infosec.exchangeR This user is from outside of this forum
                          rtificial@infosec.exchange
                          wrote last edited by
                          #50

                          @GossiTheDog lawl you can already download them. It’s 1.1 gigs.

                          1 Reply Last reply
                          1
                          0
                          • R relay@relay.infosec.exchange shared this topic
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Handala have phished Kash Patel, the director of the FBI, and released his emails.

                            See the prior rest of thread on this, they've been doing it for years with Israeli politicians - they just phish Gmail and iCloud logins, then sync devices.

                            The FBI have confirmed the emails are authentic. It looks like they are releasing them in batches.

                            Link Preview Image
                            kluthulhu@infosec.exchangeK This user is from outside of this forum
                            kluthulhu@infosec.exchangeK This user is from outside of this forum
                            kluthulhu@infosec.exchange
                            wrote last edited by
                            #51

                            @GossiTheDog something something "but her emails!"

                            1 Reply Last reply
                            1
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups