Iran's Ministry of Intelligence (MOIS) has expanded its 'Handala' operational brand to encompass physical threats and influence operations alongside its established cyber hacktivism. By coordinating personas like Handala Hack Team, HPRF, and VIPEmployment, MOIS leverages global brand recognition to solicit proxies via Telegram for espionage, sabotage, and physical attacks against US and Israeli interests. This multidomain approach combines cyber intrusions with real-world intimidation tactics.
Void Manticore
3 posts
Iran Expands Handala Brand to Physical Threats “Handala Hack” – Unveiling Group’s Modus Operandi Handala Hack, an Iranian MOIS-affiliated threat actor also known as Void Manticore, conducts destructive wiping and hack-and-leak operations against US, Israeli, and Albanian targets. The group leverages compromised VPN credentials for initial access, uses NetBird for internal tunneling, and deploys multiple parallel wiping techniques—including custom MBR wipers, PowerShell scripts, and VeraCrypt—distributed via Active Directory Group Policy.
Iranian MOIS Actors & the Cyber Crime Connection Iranian Ministry of Intelligence and Security (MOIS) affiliated threat actors, including Void Manticore and MuddyWater, are increasingly integrating cybercriminal tools, infrastructure, and affiliate models into their operations. This strategic shift, which includes the use of commercial infostealers like Rhadamanthys and RaaS platforms like Qilin, enhances their operational capabilities while complicating attribution efforts.