{"id":892003,"date":"2026-06-25T15:09:20","date_gmt":"2026-06-25T15:09:20","guid":{"rendered":"https:\/\/www.europesays.com\/us\/892003\/"},"modified":"2026-06-25T15:09:20","modified_gmt":"2026-06-25T15:09:20","slug":"handala-irans-digital-theater-of-terror","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/892003\/","title":{"rendered":"Handala: Iran\u2019s Digital Theater of Terror"},"content":{"rendered":"<p>This article presents the hacker group Handala as part of Iran\u2019s digital theater of terror\u2026<\/p>\n<p><strong>Abstract<\/strong><\/p>\n<p class=\"wp-block-paragraph\">This article presents the hacker group Handala as part of Iran\u2019s digital theater of terror and highlights its central role in the realm of psychological and cognitive warfare. The group\u2019s activities combine cyberattacks, data leaks, and threats with carefully orchestrated media campaigns designed to shape perceptions, amplify feelings of fear and anxiety, and undermine the sense of security among target audiences. The study further demonstrates a gradual shift in the group\u2019s branding and messaging strategies over time, moving from a framework primarily rooted in Palestinian narratives toward a more explicit alignment with Iranian interests and narratives, particularly in the context of escalating tensions between Iran and Israel. Within this framework, Handala is portrayed as an influential actor serving as an Iranian proxy in cyberspace, employing both offensive cyber operations and information campaigns to shape public opinion, influence security perceptions, and promote messages aligned with Iran\u2019s broader strategic objectives.<\/p>\n<p><strong>Introduction<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Handala is a sophisticated offensive cyber group attributed to actors operating on behalf of Iran\u2019s Ministry of Intelligence (MOIS). Although it does not function as an official arm of the Iranian regime, its activities demonstrate a clear alignment with the interests and narratives that Tehran seeks to promote. The group adopted both its name and emblem from Handala, the iconic cartoon character created by Palestinian cartoonist Naji al-Ali. Depicted as a young Palestinian boy with his back turned to the viewer, Handala symbolizes the resilience, steadfastness, and perseverance of the Palestinian people. The group\u2019s appropriation of this figure reflects a distinct ideological affiliation and suggests an effort to frame its activities as part of a broader cognitive and political struggle. This choice is particularly significant given that the group emerged in the months following the October 7, 2023 attacks.<a href=\"#_ftn1\" id=\"_ftnref1\">[1]<\/a> The timing of its appearance, together with the consistently pro-Palestinian messaging evident in its publications since its inception, supports the assessment that Handala initially sought to position itself as part of the Palestinian cause and to legitimize its operations through identification with the Palestinian narrative.<\/p>\n<p class=\"wp-block-paragraph\">Since its establishment in December 2023, Handala has carried out numerous cyber operations, primarily targeting entities in Israel, as well as organizations in Europe, the United States, and the Gulf region. Its targets have included institutions in healthcare, media, information technology, education, government, and security sectors. Unlike many state-sponsored cyber actors, such as those associated with Russia, North Korea, China, or Syria, which typically operate covertly, Handala conducts its activities openly, following a publicly articulated operational agenda and openly disclosing its operations, targets, and claimed achievements. This unusual level of transparency provides a valuable opportunity to examine the strategies and tactics employed by cyber actors engaged in politically motivated and ideologically driven operations.<\/p>\n<p class=\"wp-block-paragraph\">This paper examines Handala\u2019s role within the broader Iranian cyber and influence ecosystem. Through an analysis of the group\u2019s online activity, attributed cyber operations, operational patterns, and strategic messaging, the study seeks to assess its function within Iran\u2019s digital theater of terror from its emergence through its activities during the 2026 escalation between Iran and Israel. To this end, the research analyzes the group\u2019s publications, operations, and the narratives it promotes across the digital domain.<\/p>\n<p><strong>From Operation \u201cSwords of Iron\u201d to Operation \u201cRoaring Lion\u201d: The Evolution of Handala\u2019s Activities<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Handala presents its activities under the banner of hacktivism; however, its operational characteristics, target selection, and overall conduct position it within the broader offensive cyber ecosystem associated with Iran. Since its emergence in December 2023, the group has become integrated into the network of cyber units operating in support of Iranian state interests, alongside other groups attributed to Iran\u2019s Ministry of Intelligence (MOIS) and the Islamic Revolutionary Guard Corps (IRGC).<a href=\"#_ftn2\" id=\"_ftnref2\">[2]<\/a> These actors use cyberspace to advance a range of objectives, including espionage, targeting regime opponents and adversaries, psychological warfare, influence operations, and the dissemination of propaganda. Over the years, many of the cyber groups operating within this ecosystem have been publicly exposed by Western governments, cybersecurity firms, and international media outlets as being directly or indirectly linked to the Iranian regime and the IRGC.<\/p>\n<p class=\"wp-block-paragraph\">Handala employs a broad spectrum of offensive cyber techniques, including website defacement, data leaks, distributed denial-of-service (DDoS) attacks, phishing campaigns, ransomware operations, and the dissemination of propaganda through social media platforms and messaging applications. Its activities are directed primarily against Israeli targets, including public institutions, private companies, security-related organizations, and public figures, as well as international actors perceived as adversaries of Iran, supporters of Israel, or opponents of the Iranian regime. An examination of the group\u2019s operational patterns reveals a gradual evolution in its target selection and strategic priorities.<a href=\"#_ftn3\" id=\"_ftnref3\">[3]<\/a><\/p>\n<p class=\"wp-block-paragraph\">In the aftermath of the October 7 attacks and the outbreak of the Swords of Iron war, Handala concentrated much of its activity on private-sector companies and organizations, portraying them as integral components of Israel\u2019s civilian, economic, and security-support infrastructure. Beginning in mid-2025, however, the group increasingly shifted its focus toward governmental, security, and political targets, including security agencies, government ministries, and senior Israeli officials. At the same time, its influence activities expanded considerably, with growing reliance on data leaks, the exposure of personal information, and claims of compromising private communication accounts in order to generate public attention and media coverage.<a href=\"#_ftn4\" id=\"_ftnref4\">[4]<\/a><\/p>\n<p class=\"wp-block-paragraph\">A particularly significant development occurred during Operation \u201cRoaring Lion\u201d in 2026, when Handala\u2019s alignment with Iran became increasingly explicit. Although the twelve-day Iran\u2013Israel confrontation in June 2025 had already witnessed a substantial increase in the group\u2019s operational tempo<a href=\"#_ftn5\" id=\"_ftnref5\">[5]<\/a> and identification with Iranian narratives, the events of 2026 marked a further escalation in both its public support for Iran and its involvement in the broader information campaign and, according to its own claims, aspects of the operational campaign as well.<\/p>\n<p class=\"wp-block-paragraph\">Prior to Operation \u201cRoaring Lion\u201d, the majority of Handala\u2019s activities focused on Israeli targets, with more limited attention directed toward American entities and individuals perceived as opponents of the Iranian regime. During the conflict and even throughout the subsequent ceasefire period, the group significantly diversified its target portfolio in a manner that closely mirrored Iran\u2019s strategic priorities and conflict arenas. As Iran simultaneously confronted Israel, the United States, and several Gulf states, Handala conducted cyber operations against entities associated with these same theaters of confrontation.<\/p>\n<p class=\"wp-block-paragraph\">With regard to the United States, Handala claimed responsibility for breaching the American medical technology company Stryker and remotely wiping more than 200,000 computers, servers, and smartphones belonging to employees across seventy-nine countries. The group justified the operation as retaliation for what it described as \u201congoing cyberattacks against the infrastructure of the Axis of Resistance.\u201d Handala also claimed to have compromised the Director of the FBI\u2019s personal email account. Its public release included personal photographs allegedly obtained from the account, as well as what it claimed were the director\u2019s professional credentials.<\/p>\n<p class=\"wp-block-paragraph\">During Operation \u201cRoaring Lion\u201d, several incidents further illustrated the alignment between Handala\u2019s target selection and Iran\u2019s strategic objectives. For example, alongside Iranian actions targeting energy infrastructure, Handala claimed responsibility for cyber operations against gas stations in Jordan, asserting that the attacks were carried out in response to the \u201cbetrayal\u201d of Jordan\u2019s rulers. Similarly, the group targeted energy-related assets in the Gulf region. One of the most notable cases involved the publication of documents allegedly obtained from the Saudi energy company Saudi Aramco, which were subsequently released through Handala\u2019s online platforms.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"261\" height=\"287\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" alt=\"\" class=\"wp-image-26800\" style=\"aspect-ratio:0.9094027331627376;width:461px;height:auto\" data-lazy-src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2026\/06\/image-2.jpg\"\/><\/p>\n<p class=\"has-text-align-center wp-block-paragraph\"><strong>Handala\u2019s Announcement Claiming a Cyberattack Against Gas Stations in Jordan<\/strong><\/p>\n<p class=\"wp-block-paragraph\">In March 2026, the U.S. Department of Justice announced the seizure and disruption of websites associated with Handala as part of a broader effort to counter cyber operations attributed to Iran\u2019s Ministry of Intelligence and Security (MOIS), the principal intelligence organization of the Islamic Republic. In connection with this action, the FBI stated that Handala\u2019s online activities were intended to advance influence operations and psychological warfare campaigns directed against adversaries of the Iranian regime.<a href=\"#_ftn6\" id=\"_ftnref6\">[6]<\/a> This assessment reinforced growing perceptions that Handala functions not merely as a cyber threat actor but also as a strategic instrument within Iran\u2019s broader information and influence apparatus.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"740\" height=\"423\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" alt=\"\" class=\"wp-image-26802\" data-lazy- data-lazy- data-lazy-src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2026\/06\/image-7.jpeg\"\/><\/p>\n<p class=\"has-text-align-center wp-block-paragraph\"><strong>FBI seizure notice displayed on Handala\u2019s website<\/strong><\/p>\n<p><strong>The Media and Psychological Dimensions of Handala<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Like many terrorist organizations and politically motivated cyber actors, Handala seeks to achieve broad public visibility through what scholars of terrorism and communication have described as the \u201ctheater of terror.\u201d<a href=\"#_ftn7\" id=\"_ftnref7\">[7]<\/a> This concept emphasizes that the primary audience of terrorist activity extends far beyond its immediate victims. From the attack at the 1972 Munich Olympics and the September 11 attacks to the October 7, 2023 attacks and contemporary waves of terrorism, the broader objective has often been to influence the perceptions, emotions, and behavior of mass audiences exposed to these events through the media. Modern terrorist actors have increasingly incorporated media considerations into their operational planning, designing actions not only to inflict damage but also to maximize visibility, shape narratives, and generate psychological effects. The rise of digital platforms has significantly amplified these dynamics by removing many of the traditional gatekeeping functions once exercised by editors and broadcasters in the era of conventional mass media.<\/p>\n<p class=\"wp-block-paragraph\">Within this environment, terrorist and extremist actors increasingly employ what can be described as a \u201cvisibility strategy,\u201d leveraging digital platforms to maximize exposure and influence target audiences. Handala has adopted this approach extensively, combining offensive cyber activities with a sophisticated communications effort designed to amplify the impact of its operations. The group pursues visibility through several complementary mechanisms:<\/p>\n<ul class=\"wp-block-list\">\n<li>Immediate public disclosure of cyber intrusions and attacks.<\/li>\n<li>Extensive use of hashtags, tagging, and cross-platform amplification.<\/li>\n<li>Simultaneous dissemination of messages across multiple platforms and languages.<\/li>\n<li>Integration of visual content, including images, illustrations, screenshots, documents, and videos.<\/li>\n<li>Re-establishment of websites, channels, and online communities following takedowns or disruptions by authorities.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">An examination of Handala\u2019s operational patterns suggests that its activities are guided by a structured strategy that closely integrates cyber operations with carefully orchestrated influence campaigns. Most of the group\u2019s cyber activities are accompanied by a sustained communication effort aimed at maximizing the psychological and public impact of each operation. These campaigns typically follow a multi-stage structure. In the first stage, the group releases threats, hints, or promises of forthcoming disclosures in order to generate anticipation, curiosity, and anxiety among target audiences. In the second stage, partial information is released alongside ideological justifications intended to frame the operation as part of a broader political or moral struggle. Finally, the group publishes the full set of allegedly compromised materials, either through public disclosure or by offering them for sale, thereby extending the media life cycle of the incident and amplifying its public impact.<a href=\"#_ftn8\" id=\"_ftnref8\">[8]<\/a><\/p>\n<p class=\"wp-block-paragraph\">A prominent example of this approach can be found in the RedWanted campaign, through which Handala systematically published information allegedly relating to Israeli political and security figures. The campaign was characterized by consistent visual branding, standardized language, and recurring publication patterns, all of which suggest careful planning and a sophisticated understanding of media influence mechanisms. Rather than focusing primarily on causing substantial physical or economic damage, Handala frequently appears to use cyber operations as vehicles for psychological influence and public visibility. Its communications repeatedly emphasize the group\u2019s capabilities, aiming to project an image of strength, reach, and operational success. For example, the group has published threatening messages on X (formerly Twitter), including statements such as, \u201cWe choose what you will fear next,\u201d intended to cultivate uncertainty and psychological pressure among its intended audiences.<\/p>\n<p class=\"wp-block-paragraph\">Handala\u2019s psychological warfare activities rely on a combination of methods, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>Public announcements of future attacks and gradual pre-attack \u201cteasing\u201d campaigns.<\/li>\n<li>The public display of purported successes involving websites, mobile devices, and computer systems.<\/li>\n<li>\u201cHack-and-leak\u201d operations involving the disclosure of allegedly compromised information.<\/li>\n<li>Strategic tagging of journalists and media outlets to maximize publicity and media coverage.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The combination of cyber operations designed for publicity, visibility-enhancing communication techniques, and psychological warfare activities is accompanied by a systematic effort to shape the narrative surrounding the group and its motivations. Handala employs sophisticated framing strategies intended to portray itself as an authentic voice of popular resistance while drawing upon culturally resonant symbols and visual imagery to enhance identification with its cause. These tactics are consistent with established principles of modern propaganda, in which the narrative surrounding an operation can be as important as the operation itself. In this sense, Handala\u2019s cyber activities function not merely as technical operations but as components of a broader influence campaign aimed at shaping perceptions, generating attention, and reinforcing narratives aligned with the strategic interests of Iran and the so-called Axis of Resistance.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"217\" height=\"250\" data-id=\"26804\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" alt=\"\" class=\"wp-image-26804\" data-lazy-src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2026\/06\/image-3.jpg\"\/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"203\" height=\"248\" data-id=\"26806\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" alt=\"\" class=\"wp-image-26806\" data-lazy-src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2026\/06\/image-4.jpg\"\/><\/p>\n<p class=\"has-text-align-center wp-block-paragraph\"><strong>Left: A Handala post publishing information about an individual allegedly affiliated with the Mossad. The post tagged the X accounts of major Israeli news outlets in an apparent effort to maximize media exposure and public attention. Right: A post published on Handala\u2019s X (formerly Twitter) account claiming the compromise of former Israeli Minister Ayelet Shaked\u2019s mobile phone as part of the RedWanted campaign. The post, titled \u201cThe Queen\u2019s Secrets: Unveiling the Mystery Behind Ayelet Shaked,\u201d stated: \u201cOnce again, the cyber world has witnessed our true power! This time, our target was none other than Ayelet Shaked, the controversial figure and so-called security champion of the Zionist regime.\u201d<\/strong><\/p>\n<p><strong>Narratives and Messaging in Handala\u2019s Influence Campaigns<\/strong><\/p>\n<p class=\"wp-block-paragraph\">An analysis of Handala\u2019s discourse reveals that the group frames its activities through ideological rhetoric designed to legitimize its operations and justify its targeting decisions. Prior to Operation \u201cRoaring Lion\u201d, the group\u2019s primary narrative centered on support for the Palestinian cause in the context of the Swords of Iron war. Cyber operations were portrayed as acts of solidarity with Palestinians and as part of a broader political and ideological struggle. Alongside this framing, Handala frequently sought to delegitimize Israeli political and security leadership by portraying decision-makers as incompetent, ineffective, or incapable of protecting state institutions and citizens. Through this narrative framework, cyberattacks were presented not merely as technical operations but also as instruments for conveying political and psychological messages.<a href=\"#_ftn9\" id=\"_ftnref9\">[9]<\/a><strong\/><\/p>\n<p class=\"wp-block-paragraph\">Another central theme in Handala\u2019s communications is the projection of operational superiority in cyberspace. The group consistently portrays itself as possessing advanced intrusion capabilities and privileged access to sensitive systems. Its messaging emphasizes control, deep penetration, technological sophistication, and intelligence-gathering capabilities. These claims are often accompanied by the publication of allegedly leaked materials intended to reinforce the credibility of the group\u2019s assertions and demonstrate its operational reach. At the same time, Handala cultivates an image of persistent access to target systems through messages suggesting continuous monitoring and ongoing visibility into sensitive information. This rhetoric serves two complementary purposes: strengthening the group\u2019s image as a capable cyber actor while simultaneously increasing feelings of vulnerability and exposure among target audiences.<a href=\"#_ftn10\" id=\"_ftnref10\">[10]<\/a><\/p>\n<p class=\"wp-block-paragraph\">The analysis of Handala\u2019s publications throughout the research period indicates a gradual evolution in the narratives promoted by the group. During its early stages, Handala\u2019s rhetoric relied heavily on a distinctly Palestinian framing that emphasized support for Palestinians and the so-called \u201cAxis of Resistance,\u201d alongside frequent references to Gaza and operations portrayed as responses to harm inflicted upon Palestinians. This trend is consistent with the group\u2019s adoption of the name Handala shortly after the events of October 7, 2023, and its appropriation of a symbol deeply associated with Palestinian national identity. During this period, the group portrayed its cyber activities as a direct continuation of the Palestinian struggle and as part of the broader resistance against Israel. In some cases, operations were explicitly justified as retaliation for events such as the attempted assassination of Mohammed Deif.<\/p>\n<p class=\"wp-block-paragraph\">As tensions between Iran and Israel intensified, however, the focus of the group\u2019s messaging shifted noticeably. While pro-Palestinian symbols and themes remained present, increasing attention was devoted to issues directly related to Iran and the interests of the Iranian regime. Numerous publications framed cyber operations as responses to alleged \u201cAmerican attacks against Iranian civilians,\u201d the \u201cmurder of the children of Minab,\u201d or actions attributed to Israel and the United States against Iran. At the same time, the group published information on approximately 600 individuals it claimed were connected to the Israeli intelligence service within Iran, exposed alleged regime opponents, and released information concerning individuals portrayed as participating in activities directed against the Iranian state.<\/p>\n<p class=\"wp-block-paragraph\">During the 2026 conflict, Handala increasingly functioned as a digital amplifier of Iranian messaging. In addition to the cyber operations attributed to the group, its communication channels were used to disseminate threats, deterrence messages, and propaganda closely aligned with narratives promoted by official Iranian actors. In several instances, the group issued warnings of imminent attacks against Israel. One such message stated that \u201cwithin the coming hours, a rapid and fierce roar of fire will reach locations recently identified in the dark skies above the occupied territories.\u201d In another case, Israeli media reported a wave of threatening WhatsApp messages attributed to Handala that sought to influence Israeli public opinion. One message warned that Israeli residents should \u201cprepare for a barrage of Sayyad Majid missiles\u201d and stockpile supplies in anticipation of extended periods in bomb shelters.<a href=\"#_ftn11\" id=\"_ftnref11\">[11]<\/a> In a separate incident, accounts associated with Handala were reportedly used to send death threats to Iranian dissidents and journalists residing in the United States and elsewhere abroad.<\/p>\n<p class=\"wp-block-paragraph\">Ahead of the FIFA World Cup and amid continuing tensions between the United States and Iran, Handala claimed that it had maintained access for several months to FBI security drones equipped with facial-recognition and license-plate scanning capabilities that were allegedly used for counterterrorism purposes. According to the group, information collected by these drones, including photographs, surveillance data, and information relating to FBI personnel, had also become accessible to Handala. As part of its publication, the group released images that it claimed originated from the compromised systems and asserted that they demonstrated that \u201cthe American security apparatus is nothing more than an empty performance.\u201d Beyond the specific technical claims, the publication reflected one of the recurring themes in Handala\u2019s messaging strategy: the projection of deep penetration into highly sensitive security systems. Such claims are intended not only to demonstrate technical capability but also to undermine confidence in the institutions responsible for public security and national defense.<\/p>\n<p class=\"wp-block-paragraph\">Taken together, these findings suggest that Handala\u2019s narrative evolution reflects a broader transition from a cyber actor primarily presenting itself as a supporter of the Palestinian cause toward one increasingly aligned with Iranian strategic messaging. While Palestinian themes continue to provide a source of ideological legitimacy, the group\u2019s communications have become progressively intertwined with Iran\u2019s geopolitical priorities, transforming Handala into an important component of Tehran\u2019s broader influence and psychological warfare ecosystem in cyberspace.<\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p class=\"wp-block-paragraph\">The hacker group Handala constitutes a significant component of Iran\u2019s digital theater of terror, operating according to a model in which cyberattacks serve as a foundation for generating media attention and amplifying psychological influence. The group employs a comprehensive visibility strategy that includes the publication of threats, data leaks, exposure of personal information, dissemination of messages across social media platforms, and the management of sustained campaigns designed to extend the media life cycle of each cyber operation. Through these mechanisms, Handala seeks to shape perceptions, increase feelings of exposure and vulnerability, undermine the sense of security among target audiences, and enhance the public visibility of its activities.<\/p>\n<p class=\"wp-block-paragraph\">A second key finding is the growing alignment between Handala\u2019s activities and the strategic interests of the Iranian regime. While the group\u2019s early operations relied heavily on a distinctly Palestinian identity and messaging associated with the Palestinian struggle and the Swords of Iron war, its subsequent evolution revealed an increasing convergence between its targets, narratives, and operational patterns and Iran\u2019s broader strategic agenda. This trend became particularly evident during Operation \u201cRoaring Lion\u201d, when the group expanded its activities toward targets and objectives that closely reflected Iran\u2019s principal arenas of confrontation and the narratives promoted by Iranian state actors.<\/p>\n<p class=\"wp-block-paragraph\">This evolution reflects the broader relationship between Handala and Iran and highlights the group\u2019s integration into the cyber ecosystem associated with the Iranian regime. In this context, the Palestinian branding adopted by the group\u2014including the use of the Handala symbol and narratives associated with the \u201cAxis of Resistance\u201d\u2014provided an ideological framework and a source of public legitimacy that enabled the group to advance messages and interests that increasingly overlapped with those of Tehran.<\/p>\n<p class=\"wp-block-paragraph\">Ultimately, Handala represents a model of a digital proxy operating in cyberspace that integrates offensive cyber capabilities and psychological warfare within a unified strategic framework. The group\u2019s activities illustrate the growing importance of influence operations and psychological warfare in contemporary conflicts, as well as the expanding role of cyber actors as instruments of state power and strategic communication. Handala demonstrates how cyber operations can be leveraged not only to achieve technical effects but also to shape perceptions, influence public discourse, and support broader geopolitical objectives.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref1\" id=\"_ftn1\">[1]<\/a> Idan Dror and Hadar Eichler, \u201cHandala Hack: What We Know About the Rising ThreatActor\u201d, Check Point Report (July 16, 2024), https:\/\/cyberint.com\/blog\/threat-intelligence\/handala-hack-what-we-know-about-the-rising-threat-actor\/<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref2\" id=\"_ftn2\">[2]<\/a> Avi Davidi, \u201cCyber as A Continuation of War By Other Means: Iranian \u201cHandala\u201d Activity, Special Report by the Jerusalem Institute for Strategy and Security (August 2025), https:\/\/jiss.org.il\/en\/davidi-cyber-as-the-continuation-of-war-by-other-means\/.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref3\" id=\"_ftn3\">[3]<\/a> Cyber Desk. (2025, December 31).\u00a0Bibi Gate: Handala Hack Team\u2014A mask for Iranian psychological warfare. International Institute for Counter-Terrorism (ICT).\u00a0<a href=\"https:\/\/ict.org.il\/bibi-gate-handala-hack-team-a-mask-for-iranian-psychological-warfare\/\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/ict.org.il\/bibi-gate-handala-hack-team-a-mask-for-iranian-psychological-warfare\/<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref4\" id=\"_ftn4\">[4]<\/a> Haberfeld, D., &amp; Weimann, G. (2026). Iran\u2019s \u201cHandala\u201d: Cyberterrorism or Psychological Terrorism?.\u00a0Studies in Conflict &amp; Terrorism, 1-16.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref5\" id=\"_ftn5\">[5]<\/a> Haberfeld, D., &amp; Weimann, G. (2026). Iran\u2019s \u201cHandala\u201d: Cyberterrorism or Psychological Terrorism?.\u00a0Studies in Conflict &amp; Terrorism, 1-16.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref6\" id=\"_ftn6\">[6]<\/a> U.S. Department of Justice. (2026, March 19).\u00a0Justice Department disrupts Iranian cyber-enabled psychological operations. Office of Public Affairs.\u00a0<a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-disrupts-iranian-cyber-enabled-psychological-operations\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/www.justice.gov\/opa\/pr\/justice-department-disrupts-iranian-cyber-enabled-psychological-operations<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref7\" id=\"_ftn7\">[7]<\/a> Weimann, G., &amp; Winn, C. (1993).\u00a0The theater of terror: Mass media and international terrorism. Longman.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref8\" id=\"_ftn8\">[8]<\/a> Haberfeld, D., &amp; Weimann, G. (2026). Iran\u2019s \u201cHandala\u201d: Cyberterrorism or Psychological Terrorism?.\u00a0Studies in Conflict &amp; Terrorism, 1-16.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref9\" id=\"_ftn9\">[9]<\/a> Haberfeld, D., &amp; Weimann, G. (2026). Iran\u2019s \u201cHandala\u201d: Cyberterrorism or Psychological Terrorism?.\u00a0Studies in Conflict &amp; Terrorism, 1-16.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref10\" id=\"_ftn10\">[10]<\/a>\u00a0Haberfeld, D., &amp; Weimann, G. (2026). Iran\u2019s \u201cHandala\u201d: Cyberterrorism or Psychological Terrorism?.\u00a0Studies in Conflict &amp; Terrorism, 1-16.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref11\" id=\"_ftn11\">[11]<\/a> Gal, A. (2026, April 27). Hundreds of thousands of Israelis received a threatening message: \u201cNetanyahu, the leader of the Epstein cult\u201d [in Hebrew]. Maariv. <a href=\"https:\/\/www.maariv.co.il\/news\/israel\/article-1314706\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/www.maariv.co.il\/news\/israel\/article-1314706<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"This article presents the hacker group Handala as part of Iran\u2019s digital theater of terror\u2026 Abstract This article&hellip;\n","protected":false},"author":3,"featured_media":892004,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[2],"tags":[14460,27484,83,99,50],"class_list":["post-892003","post","type-post","status-publish","format-standard","has-post-thumbnail","category-news","tag-cyber","tag-cyberspace","tag-iran","tag-israel","tag-news"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/116811383734616932","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/892003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=892003"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/892003\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/892004"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=892003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=892003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=892003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}