<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/unveiling-group-s-modus-operandi-vozeyxrgg" -->

---
title: Unveiling Group&#x27;s Modus Operandi | daily.dev
description: Check Point Research details the tactics, techniques, and procedures (TTPs) of Handala Hack, an Iranian MOIS-affiliated threat actor also tracked as Void...
canonical: https://daily.dev/posts/unveiling-group-s-modus-operandi-vozeyxrgg
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Unveiling Group&#x27;s Modus Operandi | daily.dev
og:description: Check Point Research details the tactics, techniques, and procedures (TTPs) of Handala Hack, an Iranian MOIS-affiliated threat actor also tracked as Void...
og:url: https://daily.dev/posts/unveiling-group-s-modus-operandi-vozeyxrgg
og:image: https://api.daily.dev/og/posts/vOzeyXRGg.png
og:image:alt: Unveiling Group&#x27;s Modus Operandi
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Unveiling Group's Modus Operandi

**[Check Point Research](https://daily.dev/sources/cpresearch)** · 11 min read · 0 upvotes · 0 comments

## Summary

Check Point Research details the tactics, techniques, and procedures (TTPs) of Handala Hack, an Iranian MOIS-affiliated threat actor also tracked as Void Manticore. The group operates multiple personas (Handala, Karma, Homeland Justice) and has expanded targeting from Israel and Albania to US enterprises like Stryker. Their intrusions rely on compromised VPN credentials for initial access, extensive RDP-based lateral movement, and deployment of custom and off-the-shelf wipers. The destructive phase uses four parallel wiping techniques including a custom Handala Wiper with MBR corruption, an AI-assisted PowerShell wiper, VeraCrypt disk encryption, and manual file deletion. NetBird is used to establish internal mesh connectivity. The report includes full MITRE ATT&CK mapping and IOCs including hashes, IPs, and attacker machine hostnames.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/>

## Similar posts on daily.dev

- [CTI Research: Handala Hack Group \(aka Handala Hack Team\)](https://daily.dev/posts/cti-research-handala-hack-group-aka-handala-hack-team--9t0nlqqst) · InfoSec Write-ups · 0 upvotes · 0 comments
- [The thin gray line: Handala, CyberAv3ngers and Iran’s proxy ops](https://daily.dev/posts/the-thin-gray-line-handala-cyberav3ngers-and-iran-s-proxy-ops-pcjlkse4z) · CSO Online · 0 upvotes · 0 comments
- [Insights: Increased Risk of Wiper Attacks](https://daily.dev/posts/insights-increased-risk-of-wiper-attacks-w4bxzr2pf) · Unit 42 · 0 upvotes · 0 comments
- [Iran Expands Handala Brand to Physical Threats](https://daily.dev/posts/iran-expands-handala-brand-to-physical-threats-prlqt3bzf) · Recorded Future Blog · 0 upvotes · 0 comments
- [FBI Seizes Two Websites Linked to Pro-Iranian Group Handala](https://daily.dev/posts/fbi-seizes-two-websites-linked-to-pro-iranian-group-handala-zapvs5ueo) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/unveiling-group-s-modus-operandi-vozeyxrgg)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Unveiling Group's Modus Operandi","url":"https://daily.dev/posts/unveiling-group-s-modus-operandi-vozeyxrgg","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/unveiling-group-s-modus-operandi-vozeyxrgg"},"datePublished":"2026-03-12T17:32:01.882Z","dateModified":"2026-03-12T17:32:54.894Z","description":"Check Point Research details the tactics, techniques, and procedures (TTPs) of Handala Hack, an Iranian MOIS-affiliated threat actor also tracked as Void...","image":"https://media.daily.dev/image/upload/s--VDukGCjf--/f_auto/v1722860399/public/Placeholder%2002","thumbnailUrl":"https://media.daily.dev/image/upload/s--VDukGCjf--/f_auto/v1722860399/public/Placeholder%2002","isAccessibleForFree":true,"articleSection":"Check Point Research","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Check Point Research","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/7e3b130555214df2bf737ee6c764fa42","url":"https://daily.dev/sources/cpresearch"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/unveiling-group-s-modus-operandi-vozeyxrgg","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware","timeRequired":"PT11M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Check Point Research","item":"https://daily.dev/sources/cpresearch"},{"@type":"ListItem","position":3,"name":"Unveiling Group's Modus Operandi"}]}
```

