This article presents the hacker group Handala as part of Iran’s digital theater of terror…

Abstract

This article presents the hacker group Handala as part of Iran’s digital theater of terror and highlights its central role in the realm of psychological and cognitive warfare. The group’s activities combine cyberattacks, data leaks, and threats with carefully orchestrated media campaigns designed to shape perceptions, amplify feelings of fear and anxiety, and undermine the sense of security among target audiences. The study further demonstrates a gradual shift in the group’s branding and messaging strategies over time, moving from a framework primarily rooted in Palestinian narratives toward a more explicit alignment with Iranian interests and narratives, particularly in the context of escalating tensions between Iran and Israel. Within this framework, Handala is portrayed as an influential actor serving as an Iranian proxy in cyberspace, employing both offensive cyber operations and information campaigns to shape public opinion, influence security perceptions, and promote messages aligned with Iran’s broader strategic objectives.

Introduction

Handala is a sophisticated offensive cyber group attributed to actors operating on behalf of Iran’s Ministry of Intelligence (MOIS). Although it does not function as an official arm of the Iranian regime, its activities demonstrate a clear alignment with the interests and narratives that Tehran seeks to promote. The group adopted both its name and emblem from Handala, the iconic cartoon character created by Palestinian cartoonist Naji al-Ali. Depicted as a young Palestinian boy with his back turned to the viewer, Handala symbolizes the resilience, steadfastness, and perseverance of the Palestinian people. The group’s appropriation of this figure reflects a distinct ideological affiliation and suggests an effort to frame its activities as part of a broader cognitive and political struggle. This choice is particularly significant given that the group emerged in the months following the October 7, 2023 attacks.[1] The timing of its appearance, together with the consistently pro-Palestinian messaging evident in its publications since its inception, supports the assessment that Handala initially sought to position itself as part of the Palestinian cause and to legitimize its operations through identification with the Palestinian narrative.

Since its establishment in December 2023, Handala has carried out numerous cyber operations, primarily targeting entities in Israel, as well as organizations in Europe, the United States, and the Gulf region. Its targets have included institutions in healthcare, media, information technology, education, government, and security sectors. Unlike many state-sponsored cyber actors, such as those associated with Russia, North Korea, China, or Syria, which typically operate covertly, Handala conducts its activities openly, following a publicly articulated operational agenda and openly disclosing its operations, targets, and claimed achievements. This unusual level of transparency provides a valuable opportunity to examine the strategies and tactics employed by cyber actors engaged in politically motivated and ideologically driven operations.

This paper examines Handala’s role within the broader Iranian cyber and influence ecosystem. Through an analysis of the group’s online activity, attributed cyber operations, operational patterns, and strategic messaging, the study seeks to assess its function within Iran’s digital theater of terror from its emergence through its activities during the 2026 escalation between Iran and Israel. To this end, the research analyzes the group’s publications, operations, and the narratives it promotes across the digital domain.

From Operation “Swords of Iron” to Operation “Roaring Lion”: The Evolution of Handala’s Activities

Handala presents its activities under the banner of hacktivism; however, its operational characteristics, target selection, and overall conduct position it within the broader offensive cyber ecosystem associated with Iran. Since its emergence in December 2023, the group has become integrated into the network of cyber units operating in support of Iranian state interests, alongside other groups attributed to Iran’s Ministry of Intelligence (MOIS) and the Islamic Revolutionary Guard Corps (IRGC).[2] These actors use cyberspace to advance a range of objectives, including espionage, targeting regime opponents and adversaries, psychological warfare, influence operations, and the dissemination of propaganda. Over the years, many of the cyber groups operating within this ecosystem have been publicly exposed by Western governments, cybersecurity firms, and international media outlets as being directly or indirectly linked to the Iranian regime and the IRGC.

Handala employs a broad spectrum of offensive cyber techniques, including website defacement, data leaks, distributed denial-of-service (DDoS) attacks, phishing campaigns, ransomware operations, and the dissemination of propaganda through social media platforms and messaging applications. Its activities are directed primarily against Israeli targets, including public institutions, private companies, security-related organizations, and public figures, as well as international actors perceived as adversaries of Iran, supporters of Israel, or opponents of the Iranian regime. An examination of the group’s operational patterns reveals a gradual evolution in its target selection and strategic priorities.[3]

In the aftermath of the October 7 attacks and the outbreak of the Swords of Iron war, Handala concentrated much of its activity on private-sector companies and organizations, portraying them as integral components of Israel’s civilian, economic, and security-support infrastructure. Beginning in mid-2025, however, the group increasingly shifted its focus toward governmental, security, and political targets, including security agencies, government ministries, and senior Israeli officials. At the same time, its influence activities expanded considerably, with growing reliance on data leaks, the exposure of personal information, and claims of compromising private communication accounts in order to generate public attention and media coverage.[4]

A particularly significant development occurred during Operation “Roaring Lion” in 2026, when Handala’s alignment with Iran became increasingly explicit. Although the twelve-day Iran–Israel confrontation in June 2025 had already witnessed a substantial increase in the group’s operational tempo[5] and identification with Iranian narratives, the events of 2026 marked a further escalation in both its public support for Iran and its involvement in the broader information campaign and, according to its own claims, aspects of the operational campaign as well.

Prior to Operation “Roaring Lion”, the majority of Handala’s activities focused on Israeli targets, with more limited attention directed toward American entities and individuals perceived as opponents of the Iranian regime. During the conflict and even throughout the subsequent ceasefire period, the group significantly diversified its target portfolio in a manner that closely mirrored Iran’s strategic priorities and conflict arenas. As Iran simultaneously confronted Israel, the United States, and several Gulf states, Handala conducted cyber operations against entities associated with these same theaters of confrontation.

With regard to the United States, Handala claimed responsibility for breaching the American medical technology company Stryker and remotely wiping more than 200,000 computers, servers, and smartphones belonging to employees across seventy-nine countries. The group justified the operation as retaliation for what it described as “ongoing cyberattacks against the infrastructure of the Axis of Resistance.” Handala also claimed to have compromised the Director of the FBI’s personal email account. Its public release included personal photographs allegedly obtained from the account, as well as what it claimed were the director’s professional credentials.

During Operation “Roaring Lion”, several incidents further illustrated the alignment between Handala’s target selection and Iran’s strategic objectives. For example, alongside Iranian actions targeting energy infrastructure, Handala claimed responsibility for cyber operations against gas stations in Jordan, asserting that the attacks were carried out in response to the “betrayal” of Jordan’s rulers. Similarly, the group targeted energy-related assets in the Gulf region. One of the most notable cases involved the publication of documents allegedly obtained from the Saudi energy company Saudi Aramco, which were subsequently released through Handala’s online platforms.

Handala’s Announcement Claiming a Cyberattack Against Gas Stations in Jordan

In March 2026, the U.S. Department of Justice announced the seizure and disruption of websites associated with Handala as part of a broader effort to counter cyber operations attributed to Iran’s Ministry of Intelligence and Security (MOIS), the principal intelligence organization of the Islamic Republic. In connection with this action, the FBI stated that Handala’s online activities were intended to advance influence operations and psychological warfare campaigns directed against adversaries of the Iranian regime.[6] This assessment reinforced growing perceptions that Handala functions not merely as a cyber threat actor but also as a strategic instrument within Iran’s broader information and influence apparatus.

FBI seizure notice displayed on Handala’s website

The Media and Psychological Dimensions of Handala

Like many terrorist organizations and politically motivated cyber actors, Handala seeks to achieve broad public visibility through what scholars of terrorism and communication have described as the “theater of terror.”[7] This concept emphasizes that the primary audience of terrorist activity extends far beyond its immediate victims. From the attack at the 1972 Munich Olympics and the September 11 attacks to the October 7, 2023 attacks and contemporary waves of terrorism, the broader objective has often been to influence the perceptions, emotions, and behavior of mass audiences exposed to these events through the media. Modern terrorist actors have increasingly incorporated media considerations into their operational planning, designing actions not only to inflict damage but also to maximize visibility, shape narratives, and generate psychological effects. The rise of digital platforms has significantly amplified these dynamics by removing many of the traditional gatekeeping functions once exercised by editors and broadcasters in the era of conventional mass media.

Within this environment, terrorist and extremist actors increasingly employ what can be described as a “visibility strategy,” leveraging digital platforms to maximize exposure and influence target audiences. Handala has adopted this approach extensively, combining offensive cyber activities with a sophisticated communications effort designed to amplify the impact of its operations. The group pursues visibility through several complementary mechanisms:

  • Immediate public disclosure of cyber intrusions and attacks.
  • Extensive use of hashtags, tagging, and cross-platform amplification.
  • Simultaneous dissemination of messages across multiple platforms and languages.
  • Integration of visual content, including images, illustrations, screenshots, documents, and videos.
  • Re-establishment of websites, channels, and online communities following takedowns or disruptions by authorities.

An examination of Handala’s operational patterns suggests that its activities are guided by a structured strategy that closely integrates cyber operations with carefully orchestrated influence campaigns. Most of the group’s cyber activities are accompanied by a sustained communication effort aimed at maximizing the psychological and public impact of each operation. These campaigns typically follow a multi-stage structure. In the first stage, the group releases threats, hints, or promises of forthcoming disclosures in order to generate anticipation, curiosity, and anxiety among target audiences. In the second stage, partial information is released alongside ideological justifications intended to frame the operation as part of a broader political or moral struggle. Finally, the group publishes the full set of allegedly compromised materials, either through public disclosure or by offering them for sale, thereby extending the media life cycle of the incident and amplifying its public impact.[8]

A prominent example of this approach can be found in the RedWanted campaign, through which Handala systematically published information allegedly relating to Israeli political and security figures. The campaign was characterized by consistent visual branding, standardized language, and recurring publication patterns, all of which suggest careful planning and a sophisticated understanding of media influence mechanisms. Rather than focusing primarily on causing substantial physical or economic damage, Handala frequently appears to use cyber operations as vehicles for psychological influence and public visibility. Its communications repeatedly emphasize the group’s capabilities, aiming to project an image of strength, reach, and operational success. For example, the group has published threatening messages on X (formerly Twitter), including statements such as, “We choose what you will fear next,” intended to cultivate uncertainty and psychological pressure among its intended audiences.

Handala’s psychological warfare activities rely on a combination of methods, including:

  • Public announcements of future attacks and gradual pre-attack “teasing” campaigns.
  • The public display of purported successes involving websites, mobile devices, and computer systems.
  • “Hack-and-leak” operations involving the disclosure of allegedly compromised information.
  • Strategic tagging of journalists and media outlets to maximize publicity and media coverage.

The combination of cyber operations designed for publicity, visibility-enhancing communication techniques, and psychological warfare activities is accompanied by a systematic effort to shape the narrative surrounding the group and its motivations. Handala employs sophisticated framing strategies intended to portray itself as an authentic voice of popular resistance while drawing upon culturally resonant symbols and visual imagery to enhance identification with its cause. These tactics are consistent with established principles of modern propaganda, in which the narrative surrounding an operation can be as important as the operation itself. In this sense, Handala’s cyber activities function not merely as technical operations but as components of a broader influence campaign aimed at shaping perceptions, generating attention, and reinforcing narratives aligned with the strategic interests of Iran and the so-called Axis of Resistance.

Left: A Handala post publishing information about an individual allegedly affiliated with the Mossad. The post tagged the X accounts of major Israeli news outlets in an apparent effort to maximize media exposure and public attention. Right: A post published on Handala’s X (formerly Twitter) account claiming the compromise of former Israeli Minister Ayelet Shaked’s mobile phone as part of the RedWanted campaign. The post, titled “The Queen’s Secrets: Unveiling the Mystery Behind Ayelet Shaked,” stated: “Once again, the cyber world has witnessed our true power! This time, our target was none other than Ayelet Shaked, the controversial figure and so-called security champion of the Zionist regime.”

Narratives and Messaging in Handala’s Influence Campaigns

An analysis of Handala’s discourse reveals that the group frames its activities through ideological rhetoric designed to legitimize its operations and justify its targeting decisions. Prior to Operation “Roaring Lion”, the group’s primary narrative centered on support for the Palestinian cause in the context of the Swords of Iron war. Cyber operations were portrayed as acts of solidarity with Palestinians and as part of a broader political and ideological struggle. Alongside this framing, Handala frequently sought to delegitimize Israeli political and security leadership by portraying decision-makers as incompetent, ineffective, or incapable of protecting state institutions and citizens. Through this narrative framework, cyberattacks were presented not merely as technical operations but also as instruments for conveying political and psychological messages.[9]

Another central theme in Handala’s communications is the projection of operational superiority in cyberspace. The group consistently portrays itself as possessing advanced intrusion capabilities and privileged access to sensitive systems. Its messaging emphasizes control, deep penetration, technological sophistication, and intelligence-gathering capabilities. These claims are often accompanied by the publication of allegedly leaked materials intended to reinforce the credibility of the group’s assertions and demonstrate its operational reach. At the same time, Handala cultivates an image of persistent access to target systems through messages suggesting continuous monitoring and ongoing visibility into sensitive information. This rhetoric serves two complementary purposes: strengthening the group’s image as a capable cyber actor while simultaneously increasing feelings of vulnerability and exposure among target audiences.[10]

The analysis of Handala’s publications throughout the research period indicates a gradual evolution in the narratives promoted by the group. During its early stages, Handala’s rhetoric relied heavily on a distinctly Palestinian framing that emphasized support for Palestinians and the so-called “Axis of Resistance,” alongside frequent references to Gaza and operations portrayed as responses to harm inflicted upon Palestinians. This trend is consistent with the group’s adoption of the name Handala shortly after the events of October 7, 2023, and its appropriation of a symbol deeply associated with Palestinian national identity. During this period, the group portrayed its cyber activities as a direct continuation of the Palestinian struggle and as part of the broader resistance against Israel. In some cases, operations were explicitly justified as retaliation for events such as the attempted assassination of Mohammed Deif.

As tensions between Iran and Israel intensified, however, the focus of the group’s messaging shifted noticeably. While pro-Palestinian symbols and themes remained present, increasing attention was devoted to issues directly related to Iran and the interests of the Iranian regime. Numerous publications framed cyber operations as responses to alleged “American attacks against Iranian civilians,” the “murder of the children of Minab,” or actions attributed to Israel and the United States against Iran. At the same time, the group published information on approximately 600 individuals it claimed were connected to the Israeli intelligence service within Iran, exposed alleged regime opponents, and released information concerning individuals portrayed as participating in activities directed against the Iranian state.

During the 2026 conflict, Handala increasingly functioned as a digital amplifier of Iranian messaging. In addition to the cyber operations attributed to the group, its communication channels were used to disseminate threats, deterrence messages, and propaganda closely aligned with narratives promoted by official Iranian actors. In several instances, the group issued warnings of imminent attacks against Israel. One such message stated that “within the coming hours, a rapid and fierce roar of fire will reach locations recently identified in the dark skies above the occupied territories.” In another case, Israeli media reported a wave of threatening WhatsApp messages attributed to Handala that sought to influence Israeli public opinion. One message warned that Israeli residents should “prepare for a barrage of Sayyad Majid missiles” and stockpile supplies in anticipation of extended periods in bomb shelters.[11] In a separate incident, accounts associated with Handala were reportedly used to send death threats to Iranian dissidents and journalists residing in the United States and elsewhere abroad.

Ahead of the FIFA World Cup and amid continuing tensions between the United States and Iran, Handala claimed that it had maintained access for several months to FBI security drones equipped with facial-recognition and license-plate scanning capabilities that were allegedly used for counterterrorism purposes. According to the group, information collected by these drones, including photographs, surveillance data, and information relating to FBI personnel, had also become accessible to Handala. As part of its publication, the group released images that it claimed originated from the compromised systems and asserted that they demonstrated that “the American security apparatus is nothing more than an empty performance.” Beyond the specific technical claims, the publication reflected one of the recurring themes in Handala’s messaging strategy: the projection of deep penetration into highly sensitive security systems. Such claims are intended not only to demonstrate technical capability but also to undermine confidence in the institutions responsible for public security and national defense.

Taken together, these findings suggest that Handala’s narrative evolution reflects a broader transition from a cyber actor primarily presenting itself as a supporter of the Palestinian cause toward one increasingly aligned with Iranian strategic messaging. While Palestinian themes continue to provide a source of ideological legitimacy, the group’s communications have become progressively intertwined with Iran’s geopolitical priorities, transforming Handala into an important component of Tehran’s broader influence and psychological warfare ecosystem in cyberspace.

Conclusion

The hacker group Handala constitutes a significant component of Iran’s digital theater of terror, operating according to a model in which cyberattacks serve as a foundation for generating media attention and amplifying psychological influence. The group employs a comprehensive visibility strategy that includes the publication of threats, data leaks, exposure of personal information, dissemination of messages across social media platforms, and the management of sustained campaigns designed to extend the media life cycle of each cyber operation. Through these mechanisms, Handala seeks to shape perceptions, increase feelings of exposure and vulnerability, undermine the sense of security among target audiences, and enhance the public visibility of its activities.

A second key finding is the growing alignment between Handala’s activities and the strategic interests of the Iranian regime. While the group’s early operations relied heavily on a distinctly Palestinian identity and messaging associated with the Palestinian struggle and the Swords of Iron war, its subsequent evolution revealed an increasing convergence between its targets, narratives, and operational patterns and Iran’s broader strategic agenda. This trend became particularly evident during Operation “Roaring Lion”, when the group expanded its activities toward targets and objectives that closely reflected Iran’s principal arenas of confrontation and the narratives promoted by Iranian state actors.

This evolution reflects the broader relationship between Handala and Iran and highlights the group’s integration into the cyber ecosystem associated with the Iranian regime. In this context, the Palestinian branding adopted by the group—including the use of the Handala symbol and narratives associated with the “Axis of Resistance”—provided an ideological framework and a source of public legitimacy that enabled the group to advance messages and interests that increasingly overlapped with those of Tehran.

Ultimately, Handala represents a model of a digital proxy operating in cyberspace that integrates offensive cyber capabilities and psychological warfare within a unified strategic framework. The group’s activities illustrate the growing importance of influence operations and psychological warfare in contemporary conflicts, as well as the expanding role of cyber actors as instruments of state power and strategic communication. Handala demonstrates how cyber operations can be leveraged not only to achieve technical effects but also to shape perceptions, influence public discourse, and support broader geopolitical objectives.

[1] Idan Dror and Hadar Eichler, “Handala Hack: What We Know About the Rising ThreatActor”, Check Point Report (July 16, 2024), https://cyberint.com/blog/threat-intelligence/handala-hack-what-we-know-about-the-rising-threat-actor/

[2] Avi Davidi, “Cyber as A Continuation of War By Other Means: Iranian “Handala” Activity, Special Report by the Jerusalem Institute for Strategy and Security (August 2025), https://jiss.org.il/en/davidi-cyber-as-the-continuation-of-war-by-other-means/.

[3] Cyber Desk. (2025, December 31). Bibi Gate: Handala Hack Team—A mask for Iranian psychological warfare. International Institute for Counter-Terrorism (ICT). https://ict.org.il/bibi-gate-handala-hack-team-a-mask-for-iranian-psychological-warfare/

[4] Haberfeld, D., & Weimann, G. (2026). Iran’s “Handala”: Cyberterrorism or Psychological Terrorism?. Studies in Conflict & Terrorism, 1-16.

[5] Haberfeld, D., & Weimann, G. (2026). Iran’s “Handala”: Cyberterrorism or Psychological Terrorism?. Studies in Conflict & Terrorism, 1-16.

[6] U.S. Department of Justice. (2026, March 19). Justice Department disrupts Iranian cyber-enabled psychological operations. Office of Public Affairs. https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations

[7] Weimann, G., & Winn, C. (1993). The theater of terror: Mass media and international terrorism. Longman.

[8] Haberfeld, D., & Weimann, G. (2026). Iran’s “Handala”: Cyberterrorism or Psychological Terrorism?. Studies in Conflict & Terrorism, 1-16.

[9] Haberfeld, D., & Weimann, G. (2026). Iran’s “Handala”: Cyberterrorism or Psychological Terrorism?. Studies in Conflict & Terrorism, 1-16.

[10] Haberfeld, D., & Weimann, G. (2026). Iran’s “Handala”: Cyberterrorism or Psychological Terrorism?. Studies in Conflict & Terrorism, 1-16.

[11] Gal, A. (2026, April 27). Hundreds of thousands of Israelis received a threatening message: “Netanyahu, the leader of the Epstein cult” [in Hebrew]. Maariv. https://www.maariv.co.il/news/israel/article-1314706