Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Scheduled Pinned Locked Moved Uncategorized
threatintelhandala
44 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Handala has also defaced ReutOne’s website, and published videos of RDP access to ReutOne’s internal network, eg Active Directory Certificate Authority etc. https://web.archive.org/web/20241226141650/https://www.reutone.com/

    #threatintel #Handala

    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.social
    wrote on last edited by
    #29

    Handala claim they hacked Allen Carr's Easyway via ReutOne.

    Two points:

    a) I legit thought they had hacked UK national treasure Alan Carr for a moment

    2) "reportedly", lol. ChatGPT doing overtime for Handala.

    Link Preview Image
    gossithedog@cyberplace.socialG 1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Handala claim they hacked Allen Carr's Easyway via ReutOne.

      Two points:

      a) I legit thought they had hacked UK national treasure Alan Carr for a moment

      2) "reportedly", lol. ChatGPT doing overtime for Handala.

      Link Preview Image
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.social
      wrote on last edited by
      #30

      The '100K messages sent' thing is a reference to Handala abusing WhatsApp Business accounts, my English translation of message they've been sending.

      #handala #threatintel

      Link Preview Image
      gossithedog@cyberplace.socialG 1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        The '100K messages sent' thing is a reference to Handala abusing WhatsApp Business accounts, my English translation of message they've been sending.

        #handala #threatintel

        Link Preview Image
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.social
        wrote on last edited by
        #31

        Handala claim they will be wiping Mossad’s financial network today. Also, they appear to have purchased ChatGPT premium.

        #handala #threatintel

        gossithedog@cyberplace.socialG 1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Handala claim they will be wiping Mossad’s financial network today. Also, they appear to have purchased ChatGPT premium.

          #handala #threatintel

          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.social
          wrote on last edited by
          #32

          One note, they fully respected the dates of the ceasefire last time but apparently aren’t bothered this time? #handala #threatintel

          Edit: derp, it was Cyber Toufan who respected the ceasefire, not Handala.

          gossithedog@cyberplace.socialG 1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            One note, they fully respected the dates of the ceasefire last time but apparently aren’t bothered this time? #handala #threatintel

            Edit: derp, it was Cyber Toufan who respected the ceasefire, not Handala.

            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            wrote on last edited by
            #33

            Handala claim to have done a hack and wipe of Zuk Group, an Israel group of financial companies. Their website has been defaced as of writing.

            Handala posted a series of videos appearing to show access to their internal network.

            Handala also claim the company is a front for Mossad. They offer no evidence of that bit.

            #handala #threatintel

            Link Preview Image
            gossithedog@cyberplace.socialG 1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Handala claim to have done a hack and wipe of Zuk Group, an Israel group of financial companies. Their website has been defaced as of writing.

              Handala posted a series of videos appearing to show access to their internal network.

              Handala also claim the company is a front for Mossad. They offer no evidence of that bit.

              #handala #threatintel

              Link Preview Image
              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.social
              wrote on last edited by
              #34

              Handala got booted off Telegram after the Zuk Group hack.

              They’re back on another channel and posted:

              “وَ كَمْ قَصَمْنا مِنْ قَرْيَةٍ كانَتْ ظالِمَةً ... بَلْ نَقْذِفُ بِالْحَقِّ عَلَى الْباطِلِ فَيَدْمَغُهُ فَإِذا هُوَ زاهِقٌ‌ ...”

              Which translates to

              “How many a city have We destroyed which was unjust... Rather, We cast the truth upon falsehood, and it destroys it, and at once it departs...”

              #handala #threatintel

              gossithedog@cyberplace.socialG 1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                Handala got booted off Telegram after the Zuk Group hack.

                They’re back on another channel and posted:

                “وَ كَمْ قَصَمْنا مِنْ قَرْيَةٍ كانَتْ ظالِمَةً ... بَلْ نَقْذِفُ بِالْحَقِّ عَلَى الْباطِلِ فَيَدْمَغُهُ فَإِذا هُوَ زاهِقٌ‌ ...”

                Which translates to

                “How many a city have We destroyed which was unjust... Rather, We cast the truth upon falsehood, and it destroys it, and at once it departs...”

                #handala #threatintel

                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.social
                wrote on last edited by
                #35

                Handala claim to have hacked the Ministry of National Security in Israel, activated red alert to get people into shelters, closed the doors, then played a song and wiped the system.

                Very unclear how widespread or credible this is, although some Israeli social media posts show devices going off and playing songs.

                #handala #threatintel

                gossithedog@cyberplace.socialG 1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Handala claim to have hacked the Ministry of National Security in Israel, activated red alert to get people into shelters, closed the doors, then played a song and wiped the system.

                  Very unclear how widespread or credible this is, although some Israeli social media posts show devices going off and playing songs.

                  #handala #threatintel

                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.social
                  wrote on last edited by
                  #36

                  They also claim they have hacked Israeli police pagers and are broadcasting song on them, claim to have taken security ID information and delivery certificates for weapons. #handala #threatintel

                  gossithedog@cyberplace.socialG 1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    They also claim they have hacked Israeli police pagers and are broadcasting song on them, claim to have taken security ID information and delivery certificates for weapons. #handala #threatintel

                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.social
                    wrote on last edited by
                    #37

                    There’s some coverage in Israeli media suggesting a focus on schools, with Israeli authorities acknowledging the incidents.
                    https://www.mivzaklive.co.il/archives/879473

                    Link Preview Image
                    מתקפת סייבר במוסדות חינוך: הודעות בערבית ואזעקות במערכות הכריזה

                    במערכות הכריזה הופעלו הודעות בערבית וכן התראות צבע אדום. קבוצת התקיפה האיראנית "Handala" קיבלה אחריות לאירוע.

                    favicon

                    ערוץ 7 (www.inn.co.il)

                    For the record Handala claims they sent 5million text messages at 8am this morning, UK time.

                    #handala #threatintel

                    Link Preview ImageLink Preview Image
                    gossithedog@cyberplace.socialG 1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      There’s some coverage in Israeli media suggesting a focus on schools, with Israeli authorities acknowledging the incidents.
                      https://www.mivzaklive.co.il/archives/879473

                      Link Preview Image
                      מתקפת סייבר במוסדות חינוך: הודעות בערבית ואזעקות במערכות הכריזה

                      במערכות הכריזה הופעלו הודעות בערבית וכן התראות צבע אדום. קבוצת התקיפה האיראנית "Handala" קיבלה אחריות לאירוע.

                      favicon

                      ערוץ 7 (www.inn.co.il)

                      For the record Handala claims they sent 5million text messages at 8am this morning, UK time.

                      #handala #threatintel

                      Link Preview ImageLink Preview Image
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.social
                      wrote on last edited by
                      #38

                      Handala claim to have done a hack and wipe of Tosaf, a plastics manufacturer.

                      Screenshots show apparent Windows domain admin access, and they attach CCTV videos of themselves playing songs into a factory and an office, with workers looking confused.

                      #handala #threatintel

                      Link Preview Image
                      gossithedog@cyberplace.socialG 1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Handala claim to have done a hack and wipe of Tosaf, a plastics manufacturer.

                        Screenshots show apparent Windows domain admin access, and they attach CCTV videos of themselves playing songs into a factory and an office, with workers looking confused.

                        #handala #threatintel

                        Link Preview Image
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.social
                        wrote on last edited by
                        #39

                        Handala have been fully kicked off Telegram, including their backup channel.

                        Achievement unlocked as I can't remember a group ever getting fully booted.

                        #threatintel #handala

                        gossithedog@cyberplace.socialG 1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          Handala have been fully kicked off Telegram, including their backup channel.

                          Achievement unlocked as I can't remember a group ever getting fully booted.

                          #threatintel #handala

                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.social
                          wrote last edited by
                          #40

                          Handala appear to have fully wiped a company called Stryker, a global healthcare company.

                          Not in the link but they've got into AD, and wiped all the devices with Intune etc etc.

                          Link Preview Image
                          Stryker cyber attack - Irish unable to work as hackers cripple global systems

                          All IT systems at Stryker, which employs 4,000 people in its Cork base, remain down.

                          favicon

                          Irish Mirror (www.irishmirror.ie)

                          gossithedog@cyberplace.socialG 1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Handala appear to have fully wiped a company called Stryker, a global healthcare company.

                            Not in the link but they've got into AD, and wiped all the devices with Intune etc etc.

                            Link Preview Image
                            Stryker cyber attack - Irish unable to work as hackers cripple global systems

                            All IT systems at Stryker, which employs 4,000 people in its Cork base, remain down.

                            favicon

                            Irish Mirror (www.irishmirror.ie)

                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.social
                            wrote last edited by
                            #41

                            Some more on Stryker situation.

                            Link Preview Image
                            gossithedog@cyberplace.socialG 1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              Some more on Stryker situation.

                              Link Preview Image
                              gossithedog@cyberplace.socialG This user is from outside of this forum
                              gossithedog@cyberplace.socialG This user is from outside of this forum
                              gossithedog@cyberplace.social
                              wrote last edited by
                              #42

                              Handala have claimed responsibility to me, saying they wiped about a quarter of a mil endpoints. They say it’s because of the strike on a girls’ primary school in Minab, in Iran’s Hormozgan province, which killed close to 200 people.

                              gossithedog@cyberplace.socialG simonzerafa@infosec.exchangeS 2 Replies Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                Handala have claimed responsibility to me, saying they wiped about a quarter of a mil endpoints. They say it’s because of the strike on a girls’ primary school in Minab, in Iran’s Hormozgan province, which killed close to 200 people.

                                gossithedog@cyberplace.socialG This user is from outside of this forum
                                gossithedog@cyberplace.socialG This user is from outside of this forum
                                gossithedog@cyberplace.social
                                wrote last edited by
                                #43

                                There’s an entire thread tracking Handala above btw, goes back multiple years. Some bits need follow links to the thread as I broke it.

                                Their MO is break in, lay low for months, when target interesting exfiltrate data and then delete everything including org backups. They pivot to domain admin early and then sit on access for later. They live off land and live off org IT documentation.

                                1 Reply Last reply
                                1
                                0
                                • R relay@relay.infosec.exchange shared this topic
                                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                  Handala have claimed responsibility to me, saying they wiped about a quarter of a mil endpoints. They say it’s because of the strike on a girls’ primary school in Minab, in Iran’s Hormozgan province, which killed close to 200 people.

                                  simonzerafa@infosec.exchangeS This user is from outside of this forum
                                  simonzerafa@infosec.exchangeS This user is from outside of this forum
                                  simonzerafa@infosec.exchange
                                  wrote last edited by
                                  #44

                                  @GossiTheDog

                                  Yikes! That's a lot of endpoints and associated servers and other infrastructure.

                                  I wonder if they will be able to recover? Particularly if the backups are gone and there are no others in cold storage somewhere.

                                  As they have discovered, blowback can be painful and expensive or even unrecoverable.

                                  1 Reply Last reply
                                  1
                                  0
                                  Reply
                                  • Reply as topic
                                  Log in to reply
                                  • Oldest to Newest
                                  • Newest to Oldest
                                  • Most Votes


                                  • Login

                                  • Login or register to search.
                                  • First post
                                    Last post
                                  0
                                  • Categories
                                  • Recent
                                  • Tags
                                  • Popular
                                  • World
                                  • Users
                                  • Groups