Skip to main content

Operator dossier

Handala is a ransomware operator currently active on public leak sites. Darkfield has indexed 182 public victims claimed by this operator between May 26, 2024 and April 15, 2026. Handala is a recently emerged ransomware group that first appeared in May 2024, primarily motivated by financial gain with potential geopolitical overtones given their targeting patterns. The group's country of origin remains unclear, though their focus on Israeli targets alongside Western nations suggests possible Middle Eastern connections or sympathies, and it is unknown whether they operate as a standalone group or utilize a Ransomware-as-a-Service model. Limited public information exists regarding their specific attack methodologies, initial access vectors, or technical capabilities, though their rapid accumulation of 164 documented victims suggests they employ effective compromise techniques across multiple sectors including technology, government, energy, and healthcare organizations. The group has demonstrated a clear preference for targeting victims in Israel, the United States, and the United Kingdom, with additional activity observed in Iran and the UAE, indicating either opportunistic targeting or strategic selection based on geopolitical considerations. Given their recent emergence and continued victim acquisitions throughout 2024, Handala appears to remain active, though comprehensive technical analysis and law enforcement reporting on their operations remain limited due to their relatively short operational history.

Most-targeted sectors

Most-affected countries

Recent disclosures by Handala

Most recent 150 of 182 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Handala

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

All groups

Handala

182 victims indexed · first seen 2 years ago · last activity 4 months ago

182
Victims indexed
#49 of 370 tracked operators
1y 11m
Active period
May 2024 → Apr 2026
23
Countries hit
top Israel · 119

At a glance

Status
active
First seen
2 years ago
Last activity
4 months ago
Onion sites
3 known endpoints
Primary sector
Not Found · 96 hits

About

Handala is a recently emerged ransomware group that first appeared in May 2024, primarily motivated by financial gain with potential geopolitical overtones given their targeting patterns. The group's country of origin remains unclear, though their focus on Israeli targets alongside Western nations suggests possible Middle Eastern connections or sympathies, and it is unknown whether they operate as a standalone group or utilize a Ransomware-as-a-Service model. Limited public information exists regarding their specific attack methodologies, initial access vectors, or technical capabilities, though their rapid accumulation of 164 documented victims suggests they employ effective compromise techniques across multiple sectors including technology, government, energy, and healthcare organizations. The group has demonstrated a clear preference for targeting victims in Israel, the United States, and the United Kingdom, with additional activity observed in Iran and the UAE, indicating either opportunistic targeting or strategic selection based on geopolitical considerations. Given their recent emergence and continued victim acquisitions throughout 2024, Handala appears to remain active, though comprehensive technical analysis and law enforcement reporting on their operations remain limited due to their relatively short operational history.

References

6 links

External sources curated by the MISP threat-intel community.

Timeline

20 months
2024-05-01T00:00:00+00:00 · 112024-06-01T00:00:00+00:00 · 72024-07-01T00:00:00+00:00 · 92024-08-01T00:00:00+00:00 · 52024-09-01T00:00:00+00:00 · 62024-10-01T00:00:00+00:00 · 82024-11-01T00:00:00+00:00 · 32024-12-01T00:00:00+00:00 · 42025-01-01T00:00:00+00:00 · 22025-02-01T00:00:00+00:00 · 22025-06-01T00:00:00+00:00 · 232025-07-01T00:00:00+00:00 · 112025-09-01T00:00:00+00:00 · 32025-10-01T00:00:00+00:00 · 72025-11-01T00:00:00+00:00 · 62025-12-01T00:00:00+00:00 · 122026-01-01T00:00:00+00:00 · 82026-02-01T00:00:00+00:00 · 22026-03-01T00:00:00+00:00 · 392026-04-01T00:00:00+00:00 · 14
2024-05-01T00:00:00+00:002026-04-01T00:00:00+00:00

Top countries

🇮🇱 Israel
119
🇺🇸 United States
11
Iran
5
🇬🇧 United Kingdom
4
Iran
4
🇦🇪 UAE
2
Palestinian Territories
2
🇨🇭 Switzerland
1

Top sectors

Technology
25
Public Sector
12
Government
10
Energy
10
Healthcare
8
Manufacturing
7
Telecommunication
3
Business Services
3

MITRE ATT&CK

63 techniques · 15 tactics

Tactics

CollectionCommand And ControlCredential AccessDefense ImpairmentDiscoveryExecutionExfiltrationImpactInitial AccessLateral MovementPersistencePrivilege EscalationReconnaissanceResource DevelopmentStealth

Techniques

Recent victims

Loading…

Onion infrastructure

3 known
  • http://handala-hack.to
  • http://handala.to
  • http://vmjfieomxhnfjba57sd6jjws2ogvowjgxhhfglsikqvvrnrajbmpxqqd.onion

Source

Updated 4 months ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Handala posts a victim.

Add Handala to your watchlist — Pro pings you within 5 minutes of any new Handala leak-site post, Telegram callout, or affiliate-rebrand inference.