Handala
The Handala Group is a pro-Palestinian hacktivist group involved in cyber attacks targeting critical infrastructure, governmental entities, and civilian sectors in Israel. Their operations include DDoS attacks, phishing campaigns, and attempts to disrupt public services. This group has been active during heightened conflicts and leverages cyber tactics to advance its objectives in the Israel-Palestine conflict...
Albania
Israel
Target Sectors
Public Administration
Electrical&Electronical Manufacturing
Associated Malware/Software
rhadamanthys
ATT&CK IDs:
T1106 - Native API
T1574 - Hijack Execution Flow
T1566 - Phishing
T1102 - Web Service
T1036 - Masquerading
+3
Tactic | Id | Technique | |||
---|---|---|---|---|---|
Command And Control | T1102 | Web Service |
Sub Techniques |
Detections |
Mitigations |
Defense Evasion | T1027 | Obfuscated Files or Information |
Sub Techniques |
Detections |
Mitigations |
Defense Evasion | T1574 | Hijack Execution Flow |
Sub Techniques |
Detections |
Mitigations |
Defense Evasion | T1134 | Access Token Manipulation |
Sub Techniques |
Detections |
Mitigations |
Defense Evasion | T1036 | Masquerading |
Sub Techniques |
Detections |
Mitigations |
Execution | T1106 | Native API |
Sub Techniques |
Detections |
Mitigations |
Initial Access | T1566 | Phishing |
Sub Techniques |
Detections |
Mitigations |
Persistence | T1574 | Hijack Execution Flow |
Sub Techniques |
Detections |
Mitigations |
Persistence | T1547 | Boot or Logon Autostart Execution |
Sub Techniques |
Detections |
Mitigations |
Privilege Escalation | T1574 | Hijack Execution Flow |
Sub Techniques |
Detections |
Mitigations |
Privilege Escalation | T1134 | Access Token Manipulation |
Sub Techniques |
Detections |
Mitigations |
Privilege Escalation | T1547 | Boot or Logon Autostart Execution |
Sub Techniques |
Detections |
Mitigations |