Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago.

Scheduled Pinned Locked Moved Uncategorized
threatintelhandala
44 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.social
    wrote on last edited by
    #1

    Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago. Ron is the Ambassador of Israel to Germany. Telegram post includes death threats.

    50k emails, again looks like a personal email account. #threatintel #handala

    Edit: I broke the thread on this, the prior ones are at https://cyberplace.social/@GossiTheDog/113267372575167506

    gossithedog@cyberplace.socialG 1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Handala's latest is a dump allegedly of Ron Prosor's emails, who they originally mentioned 8 days ago. Ron is the Ambassador of Israel to Germany. Telegram post includes death threats.

      50k emails, again looks like a personal email account. #threatintel #handala

      Edit: I broke the thread on this, the prior ones are at https://cyberplace.social/@GossiTheDog/113267372575167506

      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.social
      wrote on last edited by
      #2

      Handala’s latest dump is of a podcasting platform called Doscast. Email addresses and encrypted passwords. #threatintel #handala

      Link Preview Image
      gossithedog@cyberplace.socialG 1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        Handala’s latest dump is of a podcasting platform called Doscast. Email addresses and encrypted passwords. #threatintel #handala

        Link Preview Image
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.social
        wrote on last edited by
        #3

        Handala claim they used a MaxShop SMS account to send 5 million messages. Their screenshot and my translated version below. #threatintel #handala

        Link Preview ImageLink Preview Image
        gossithedog@cyberplace.socialG 1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Handala claim they used a MaxShop SMS account to send 5 million messages. Their screenshot and my translated version below. #threatintel #handala

          Link Preview ImageLink Preview Image
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.social
          wrote on last edited by
          #4

          Obviously, Handala are awake. #threatintel #handala

          Link Preview ImageLink Preview Image
          gossithedog@cyberplace.socialG 1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            Obviously, Handala are awake. #threatintel #handala

            Link Preview ImageLink Preview Image
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            wrote on last edited by
            #5

            Handala have deleted their previous message and replaced it with this. #threatintel #handala

            Link Preview Image
            gossithedog@cyberplace.socialG 1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Handala have deleted their previous message and replaced it with this. #threatintel #handala

              Link Preview Image
              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.social
              wrote on last edited by
              #6

              Handala claim they are doing a “ultra big wipe” #threatintel #handala

              Link Preview Image
              gossithedog@cyberplace.socialG 1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                Handala claim they are doing a “ultra big wipe” #threatintel #handala

                Link Preview Image
                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.social
                wrote on last edited by
                #7

                Handala claim to have hacked and wiped 74 servers at AGAS - https://www.agas.co.il - an Israeli MSP, MSSP and cloud reseller.

                I’m not sure the size of the org stacks up with Handala’s claim. Also, 74 servers is not a lot.

                I’ve reached out to AGAS to see if they want to comment.

                #threatintel #handala

                gossithedog@cyberplace.socialG 1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Handala claim to have hacked and wiped 74 servers at AGAS - https://www.agas.co.il - an Israeli MSP, MSSP and cloud reseller.

                  I’m not sure the size of the org stacks up with Handala’s claim. Also, 74 servers is not a lot.

                  I’ve reached out to AGAS to see if they want to comment.

                  #threatintel #handala

                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.social
                  wrote on last edited by
                  #8

                  Handala claim to have released 10gb of customer data for AGAS.

                  It does appear AGAS has a security incident going on. AGAS declined to comment when asked.

                  #threatintel #handala

                  Link Preview Image
                  gossithedog@cyberplace.socialG 1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    Handala claim to have released 10gb of customer data for AGAS.

                    It does appear AGAS has a security incident going on. AGAS declined to comment when asked.

                    #threatintel #handala

                    Link Preview Image
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.social
                    wrote on last edited by
                    #9

                    AGAS have confirmed to me they are dealing with a cyber incident from Handala. #threatintel #handala

                    Link Preview ImageLink Preview Image
                    gossithedog@cyberplace.socialG 1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      AGAS have confirmed to me they are dealing with a cyber incident from Handala. #threatintel #handala

                      Link Preview ImageLink Preview Image
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.social
                      wrote on last edited by
                      #10

                      Handala have been banned from TikTok, one day after joining. #threatintel #handala

                      Link Preview Image
                      gossithedog@cyberplace.socialG 1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Handala have been banned from TikTok, one day after joining. #threatintel #handala

                        Link Preview Image
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.social
                        wrote on last edited by
                        #11

                        Handala say have hacked and dumped IM Cannabis aka IMC - https://imcannabis.com/ - using their access via AGAS, their MSP.

                        They also implicate another company, NDN Security - https://www.ndn-security.com/

                        #threatintel #handala

                        Link Preview ImageLink Preview Image
                        gossithedog@cyberplace.socialG 1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          Handala say have hacked and dumped IM Cannabis aka IMC - https://imcannabis.com/ - using their access via AGAS, their MSP.

                          They also implicate another company, NDN Security - https://www.ndn-security.com/

                          #threatintel #handala

                          Link Preview ImageLink Preview Image
                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.social
                          wrote on last edited by
                          #12

                          Handala claims to have done a leak and wipe of Elad municipality.

                          Elad's website is offline, and there's an Israeli media report of some kind of cyber incident.

                          Handala typically over exaggerate data volumes exfiltrated.

                          #Handala #threatintel

                          Link Preview Image
                          gossithedog@cyberplace.socialG 1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Handala claims to have done a leak and wipe of Elad municipality.

                            Elad's website is offline, and there's an Israeli media report of some kind of cyber incident.

                            Handala typically over exaggerate data volumes exfiltrated.

                            #Handala #threatintel

                            Link Preview Image
                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.social
                            wrote on last edited by
                            #13

                            Handala are again claiming to have hacked Soreq, the nuclear safety org. I have in the past confirmed Soreq had a cybersecurity incident related to Handala, via the International Atomic Agency. #Handala #threatintel

                            Link Preview Image
                            gossithedog@cyberplace.socialG 1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              Handala are again claiming to have hacked Soreq, the nuclear safety org. I have in the past confirmed Soreq had a cybersecurity incident related to Handala, via the International Atomic Agency. #Handala #threatintel

                              Link Preview Image
                              gossithedog@cyberplace.socialG This user is from outside of this forum
                              gossithedog@cyberplace.socialG This user is from outside of this forum
                              gossithedog@cyberplace.social
                              wrote on last edited by
                              #14

                              Handala have posted photos and internal diagrams of, they claim, Shimon Peres Negev Nuclear Research Center.

                              The data appears to have come from Soreq. I have confirmed Soreq was owned, via the IAEA.

                              #Handala #threatintel

                              Link Preview Image
                              gossithedog@cyberplace.socialG 1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                Handala have posted photos and internal diagrams of, they claim, Shimon Peres Negev Nuclear Research Center.

                                The data appears to have come from Soreq. I have confirmed Soreq was owned, via the IAEA.

                                #Handala #threatintel

                                Link Preview Image
                                gossithedog@cyberplace.socialG This user is from outside of this forum
                                gossithedog@cyberplace.socialG This user is from outside of this forum
                                gossithedog@cyberplace.social
                                wrote on last edited by
                                #15

                                A few things have happened with Handala over the past few days which I haven’t covered - they’ve been dumping cloud backup photos and making threats, including about family members. I didn’t want to cover it.

                                All but one of the Handala Telegram channels has been shut down tonight.

                                #Handala #threatintel

                                gossithedog@cyberplace.socialG 1 Reply Last reply
                                0
                                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                  A few things have happened with Handala over the past few days which I haven’t covered - they’ve been dumping cloud backup photos and making threats, including about family members. I didn’t want to cover it.

                                  All but one of the Handala Telegram channels has been shut down tonight.

                                  #Handala #threatintel

                                  gossithedog@cyberplace.socialG This user is from outside of this forum
                                  gossithedog@cyberplace.socialG This user is from outside of this forum
                                  gossithedog@cyberplace.social
                                  wrote on last edited by
                                  #16

                                  Handala continues to be crazy town, with data dumps of what is allegedly to be SSV Network, a blockchain company.

                                  Handala claim they can link it (SSV Network) to Unit 8200, the Israeli intelligence agency. So far this appears to be without proof.

                                  I’m going to guess, based on this post, they plan to post more tomorrow about Unit 8200.

                                  #Handala #threatintel

                                  Link Preview Image
                                  gossithedog@cyberplace.socialG 1 Reply Last reply
                                  0
                                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                    Handala continues to be crazy town, with data dumps of what is allegedly to be SSV Network, a blockchain company.

                                    Handala claim they can link it (SSV Network) to Unit 8200, the Israeli intelligence agency. So far this appears to be without proof.

                                    I’m going to guess, based on this post, they plan to post more tomorrow about Unit 8200.

                                    #Handala #threatintel

                                    Link Preview Image
                                    gossithedog@cyberplace.socialG This user is from outside of this forum
                                    gossithedog@cyberplace.socialG This user is from outside of this forum
                                    gossithedog@cyberplace.social
                                    wrote on last edited by
                                    #17

                                    So with the Unit 8200 stuff and Handala, their latest claim is they gained access to Silicom Limited (an IT services and networking company) and exfiltrated data, and that Silicom is a front company for Unit 8200.

                                    Presented evidence includes a video accessing an internal VMware vCentre cluster with about 50tb of storage.

                                    #Handala #threatintel

                                    Link Preview Image
                                    gossithedog@cyberplace.socialG 1 Reply Last reply
                                    0
                                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                      So with the Unit 8200 stuff and Handala, their latest claim is they gained access to Silicom Limited (an IT services and networking company) and exfiltrated data, and that Silicom is a front company for Unit 8200.

                                      Presented evidence includes a video accessing an internal VMware vCentre cluster with about 50tb of storage.

                                      #Handala #threatintel

                                      Link Preview Image
                                      gossithedog@cyberplace.socialG This user is from outside of this forum
                                      gossithedog@cyberplace.socialG This user is from outside of this forum
                                      gossithedog@cyberplace.social
                                      wrote on last edited by
                                      #18

                                      Handala claim to be inside the Silicom incident response process, and that they’ve wiped 300 systems. #Handala #threatintel

                                      Link Preview Image
                                      gossithedog@cyberplace.socialG 1 Reply Last reply
                                      0
                                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                        Handala claim to be inside the Silicom incident response process, and that they’ve wiped 300 systems. #Handala #threatintel

                                        Link Preview Image
                                        gossithedog@cyberplace.socialG This user is from outside of this forum
                                        gossithedog@cyberplace.socialG This user is from outside of this forum
                                        gossithedog@cyberplace.social
                                        wrote on last edited by
                                        #19

                                        Btw the Silicom thing is interesting - Silicom sell OEMs networking kit and cards inside server which is rebranded on sale, ie people see their products as other company. The Handala claim is that Silicom is a Unit 8200 (Israeli signals intelligence) front company, for onward access. #Handala #threatintel

                                        gossithedog@cyberplace.socialG 1 Reply Last reply
                                        0
                                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                          Btw the Silicom thing is interesting - Silicom sell OEMs networking kit and cards inside server which is rebranded on sale, ie people see their products as other company. The Handala claim is that Silicom is a Unit 8200 (Israeli signals intelligence) front company, for onward access. #Handala #threatintel

                                          gossithedog@cyberplace.socialG This user is from outside of this forum
                                          gossithedog@cyberplace.socialG This user is from outside of this forum
                                          gossithedog@cyberplace.social
                                          wrote on last edited by
                                          #20

                                          Handala are one year old today. They are billing next week “destructive week”. #Handala #threatintel

                                          gossithedog@cyberplace.socialG 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups