1,086
Views
0
CrossRef citations to date
17
Altmetric
Research Article

Iran’s “Handala”: Cyberterrorism or Psychological Terrorism?

& ORCID Icon
Received 22 Mar 2026, Accepted 14 May 2026, Published online: 06 Jun 2026

Abstract

The Handala Hacker Group is as a sophisticated and advanced cyber-attack group, tied to Iran’s Ministry of Intelligence. Handala allows Iran to conduct information warfare against Israel and the Iranian opposition, joining Iran’s existing roster of offensive cyber strike units. Beginning in 2023, Handala conducted numerous cyber-attacks, primarily against targets in Israel, with several incidents also reported in the United States and Europe. Targets included healthcare facilities, information technology, electronics, education, government and defense. While other state-operated hackers (such as those known to operate in Russia, North Korea, Syria, China and elsewhere), are clandestine and almost invisible, Handala operates openly, following a released plan, exposing and taking responsibility for each of their achievements. This mode of operating openly allows researchers to study the strategies and tactics used by these types of cyber attackers. This study’s research question is to what extent does the Handala hacking group engage in cyberterrorism as opposed to using hacking primarily as a tool of psychological warfare? The study is based on a database of publicly available content associated with the Handala hacker group. We applied a qualitative content analysis of posts by the Handala hacker group, employing natural language processing (NLP) analysis in Google Colab in order to identify patterns and trends in the data, while relying on inductive manual coding. The findings indicate that Handala’s activity focuses more on psychological warfare than on damaging the systems they have penetrated.

Introduction

Handala, Iran’s cyber hacking group presents a unique pattern of operations in the digital space. It uses cyber personas that, while not defined as official arms of the regime, nevertheless act on its behalf. Since the outbreak of the Israel-Hamas war in October 2023, and especially following the end of direct fighting between Israel and Iran in June 2025, Handala’s activity illustrates how Tehran uses cyber-attacks not only as a means of ideological and operational warfare, but also to replace military capabilities that may have been damaged or lost in the war. Handala allows Iran to conduct information warfare against Israel and the Iranian opposition and could develop into a significant external cyber weapon, joining Iran’s existing roster of offensive cyber strike units. Some affiliated with the Ministry of Intelligence and others with the Revolutionary Guards, these units carry out cyber-attacks for a variety of purposes—espionage, influence, damage, and destruction—using a variety of personas and coverts designed to obscure direct ties to the regime. Many of these units have previously been exposed (by countries, media outlets, Microsoft, and information security companies for example), as being directly connected to the Iranian regime.Footnote1

In March 2026, the US Justice Department announced the seizure of four domains as part of an ongoing effort to disrupt hacking and transnational repression schemes conducted by the Islamic Republic of Iran’s Ministry of Intelligence and Security (MOIS).Footnote2 The affidavit supporting the seizure included the Handala domains arguing that they were used by the MOIS in furtherance of attempted psychological operations targeting adversaries of the regime by claiming credit for hacking activity, posting sensitive data stolen during such hacks, and calling for the killing of journalists, regime dissidents, and Israeli persons. For example, the MOIS used the Handala domain to claim credit for a March 2026 destructive malware attack against a U.S.-based multinational medical technologies firm. The FBI’s investigation revealed that the four seized domains were linked to each other through shared leak sites, Iranian IP ranges, and a common operational “playbook.” That playbook includes: destructive and disruptive cyber-attacks; and “faketivist” psychological operations using data stolen via hacking.

As alleged in court documents, after the U.S.–Iran conflict began on 28 February 2026, the Handala domains were used to published personally identifiable information associated with targeted individuals and also claimed responsibility for hacks conducted by the group. Specifically:

  • On 11 March 2026, Handala claimed credit for conducting a destructive malware attack against a U.S.-based multinational medical technologies firm. The Handala persona claimed the hack was retaliation for “ongoing cyber assaults against the infrastructure of the Axis of Resistance.”

  • As of 9 March 2026, Handala posted the names and sensitive information of approximately 190 individuals associated with or employed by the Israeli Defense Force (IDF) and/or Israeli government. The Handala Hack posting contained threats indicating the individuals were being monitored, their residences were known, and that consequences would soon follow.

  • On 6 March 2026, Handala posted names and confidential data corresponding to individuals Handala hacking team claimed worked for the IDF. The post stated, in part, “Your iPhone 12 Pro Max holds no security for us; we even know your exact location …,” and urged “People of the Axis of Resistance! See these names and respond to these Zionist pigs yourselves.”

  • These threats and the related information were not just publicly posted. The FBI’s investigation also revealed that the email account of Handala was used to send death threats to Iranian dissidents and journalists living in the United States and abroad.Footnote3

In this study, we explored and analyzed Handala’s online content, in an attempt to assess whether this is a state-operated cyberterrorism or psychological terrorism or a combination of the two. We will look at how Handala’s content has changed over time and how the group’s online strategy has been impacted by evolving events.

Background

The Handala Hacker Group takes its name from the Arabic word “Hanzal,” referring to a plant known for its bitter fruit and ability to regrow after being cut, and recognized as a symbol of resilience and persistence. The group’s logo is a cartoon character of a young boy, representing the struggle, suffering and resilience of the Palestinian people.Footnote4

Since its establishment in 2023, the group has presented itself as a sophisticated and advanced cyber-attack group that challenges the enemies’ essential institutions and infrastructures while challenging and antagonizing its counter cyberterrorism agencies such as the Israel National Cyber Directorate. Handala is tied to Iran’s Ministry of Intelligence. The group is actually one of many cyberattack teams operating within the Storm0842 unit of Iran’s Ministry of Intelligence and National Security (MOIS). According to a report by the Microsoft Cyber Research Center, this unit includes other teams such as DarkBit, Homeland Justice, Red Sandstorm, and more.Footnote5 Where the group’s members are physically located is not clear. They may be working from one of the Iranian Ministry of Intelligence’s secret centers; or members may be scattered throughout Iran, or even dispersed throughout the world.Footnote6 The group’s X account is known to operate from Denmark though the group attempts to conceal its actual location. In August 2025, the identity of some members of Handala was exposed by Iran International, a dissident channel in London which revealed the name of one of the unit’s central figures. The publication identified Ali Bermuda, a 27-year-old from Tabriz, who is known to have engaged in cyber warfare in the service of Iran since the age of 16. The channel also published the name of Bermuda’s operator, linking both to Lihya Hosseini Panjaki, the Deputy Minister of Intelligence for Internal Security Affairs, a person wanted by the FBI for a long list of suspected crimes.

The group uses multiple online platforms, including websites and various social media accounts. Their primary presence is a Telegram channel established on 18 December 2023. Handala also maintains a Twitter (X) account, a backup Telegram channel, and a Telegram data leak channel which was set up on 2 April 2024. A review of their online activities reveals posts boasting of sophisticated cyber-attacks, including phishing campaigns, ransomware, and website defacements. Partial evidence of their successes is frequently released, to solidify a reputation of being a significant threat, even though the full extent of their claims is not verifiable. Most of Handala’s online activity relies on phishing campaigns whereby trusted users are impersonated to deceive targets into installing malicious software disguised as fake updates. These sophisticated campaigns are designed to deploy wipers and infostealers capable of compromising both Windows and Linux operating systems.Footnote7

Iran’s Psychological Warfare Against Israel

Iran’s propaganda warfare strategy, developed as a practical response to its limited military power, has become a central part of its military security doctrine and of its “soft war” strategy against the West.Footnote8 To advance this strategy, Iran combines the dissemination of political or religious beliefs, psychological operations, cyber-attacks, with almost total control of information channels.Footnote9 These efforts target Iran’s supporters and opponents as well as external audiences,Footnote10 where the goal is to portray the United-States and Israel as aggressors.Footnote11 Handala is part of Iran’s psychological operations (PSYOP) against Israel, representing a longstanding component of the Islamic Republic’s asymmetric strategy in the shadow war that escalated into direct confrontations in 2024–2025. The objective of these efforts is primarily to erode Israeli societal resilience, amplify perceptions of vulnerability, exacerbate internal divisions, and project Iranian deterrence without always requiring proportional kinetic success.Footnote12 Iran’s use of PSYOP against Israel is more than an instrument of “instant retaliation” during “real time” conflict; it is part of a deliberate, calculated, long-term strategy. These efforts are deeply intertwined with Iran’s broader regional ambitions and are designed to upset the power dynamics of the Middle East over time. Over recent decades, these efforts have extended beyond conventional military means into cyberwarfare, influence campaigns, and PSYOP targeting the Israeli public, security establishment, and international perception. When Israel is the target, Iran’s PSYOP has several specific objectives:

  • Deterrence: Creating the perception of overwhelming retaliation capabilities.

  • Disruption of civil morale: Undermining public confidence in Israel’s government and security forces.

  • Communicating victory: Framing regional developments as Iranian successes.

  • Mobilization of the “resistance axis”: Strengthening ideological cohesion among Iran-backed groups.Footnote13

A notable early example occurred in the April 2024 direct missile and drone attack (Operation True Promise), Iran’s first overt strike on Israeli territory, following the Israeli bombing of Iran’s Damascus consulate. While the barrage caused minimal physical damage due to effective Israeli and allied defenses, Iranian state media and proxies framed it as a decisive victory, claiming high success rates (e.g. 90% in some IRGC-affiliated outlets) despite evidence to the contrary. This narrative sought to instill fear and undermine confidence in Israel’s multilayered air defenses, portraying them as fragile or exaggerated. Studies conducted shortly after the attacks documented significant psychological fallout in Israel, with 41% of surveyed adults reporting clinical levels of peritraumatic distress and 19% showing elevated anxiety five days post-attack, linked partly to intense real-time media consumption.Footnote14

Iran has also employed influence operations via social media, hacktivist proxies, and covert networks to sow discord.Footnote15 These activities have included Hebrew-language campaigns (e.g. the “Israeli Avengers Organization”) aimed at inciting internal political tensions, the sending of threatening messages or of symbolic items (such as condolence wreaths to families of hostages), and the spreading of disinformation over issues such as hostages and governance to deepen societal fractures. Such tactics align with Tehran’s broader “cognitive warfare” doctrine, which integrates ideological messaging, cyber-enabled propaganda, and perception management to weaken adversaries psychologically.Footnote16

In the escalated 2025 Israel–Iran war (including the June 12-day conflict following Israel’s Operation Rising Lion), Iran shifted toward hybrid psyops. These involved exaggerated cyber claims, fake data leaks, spoofed alerts, DDoS floods, and threats via hacktivist groups to provoke public anxiety and undermine morale. Iranian officials labeled Israeli actions as “cognitive warfare” designed to foster distrust and unrest, while Tehran amplified its own narrative of resilience and inevitable retaliation to maintain domestic cohesion and project strength regionally. Overall, Iran’s psyops emphasize a focus on influencing public perception over the desire to promote decisive kinetic outcomes, exploiting media cycles and uncertainty to impose sustained stress on Israeli society. While effective in generating short-term anxiety and in testing deterrence thresholds, their strategic impact remains limited against the resilience of Israel’s robust communication systems and counter-psyop capabilities, often backfiring by highlighting Iranian operational shortfalls.

Handala’s activity since the outbreak of the Israel-Hamas war in October 2023, and especially after the end of direct fighting between Israel and Iran in June 2025, illustrates how Tehran uses cyber-attacks not only as a means of ideological and operational warfare, but also as a partial replacement for the loss of military capabilities damaged in the war. Handala’s operations allow Iran to maintain a space of denial and to conduct information warfare against Israel and the Iranian opposition at relatively low risk.Footnote17

Research Questions

Handala is an interesting case especially due to its mix of cyber warfare, state’s interests, online terrorism and psychological warfare. According to Cyber-Terror Desk’s report, “Since late 2023, the Handala Hack Team (HHT) has evolved into a calculated instrument of Iranian psychological warfare. Over the past year (2025), HHT has increasingly shifted from conventional cyber intrusions to targeted influence campaigns designed to erode morale, generate public pressure and drama, and project reach far beyond cyberspace.”Footnote18 This claim, unsupported yet by empirical data, leads to our main research question followed by sub-questions:

QA1: To what extent does the Handala hacking group engage in cyberterrorism as opposed to psychological warfare?

QA1.1: How does Handala’s choice of targets and timing reflect their strategic goal?

QA1.2: What narratives and influence strategies are being used by Handala?

QA1.3: Which audiences appear to be the primary targets of Handala’s activities?

Handala’s Online Activities

In October 2025, Handala published its “Statement of Establishment of the Grassroots Resistance Front of Right-Seekers—Handala” online.Footnote19 The statement, published in English, Hebrew, Arabic, and Farsi, outlines the group plans, targets and tactics. It starts with the declaration “We, a collective of popular, cultural, scientific, legal and cyber activists, inspired by the name Handala, the symbol of the awakened conscience of the Islamic nation, now officially announce our existence as the Grassroots Resistance Front of Right-Seekers—Handala, a human and global movement founded on science and knowledge.” Then the text lists Handala’s “Fundamental Principles”: 1. Unwavering Struggle for Righteous Goals; 2. Supporting the Oppressed and Vulnerable; 3. Aggressive Cyber Operations; 4. Identifying Zionist Criminal Elements; 5. Legal and Cultural Activism; 6. Transnational and Popular Cooperation; 7. Holding Gatherings and Marches in Countries; and 8. Structure and Path of Activity. Noteworthy are the plans for cyber activities, listed, for example, in point 3: “Today’s cyber technology can transform political and economic equations. Digital attacks can disrupt vital infrastructure, while robust cyber defense capabilities protect data security and national stability. Therefore, we will continue our smart and targeted cyberattacks against the Zionist regime more powerfully than ever before.” The statement also suggests the use of various cyber operations, including identifying enemy individuals involved in alleged “criminal projects,” and collecting and using information on thousands of individuals for intelligence and psychological exploitation:

Today’s cyber technology can transform political and economic equations. Digital attacks can disrupt vital infrastructure, while robust cyber defense capabilities protect data security and national stability. Therefore, we will continue our smart and targeted cyberattacks against the Zionist regime more powerfully than ever before… Having gained access to information on hundreds of thousands of Zionists over the years, we recognize the need to introduce individuals involved in the criminal projects of the Zionist regime to enhance intelligence, operational, and psychological exploitation.Footnote20

Handala has demonstrated the practical application of these principles: Beginning in 2023, Handala conducted numerous cyber-attacks, primarily against targets in Israel, with several incidents also reported in the United States and Europe. Targets included healthcare facilities, information technology, electronics, education, government and defense. Handala claimed responsibility for a cyberattack on Israeli kindergartens that disrupted public address systems at about 20 locations. In August 2025, the group was linked to hacks targeting multiple Israeli entities, including academic institutions, technology firms, media outlets and industrial companies.

The group’s primary modus operandi includes a wide variety of cyber-attacks, from the defacement of internet sites and Denial of Service (DoS) attacks to phishing and data-leak operations. During the Iran–Israel War in June 2025, Handala released a poster online titled “12 Days of Cyber War,” following the narrative of launching a set of cyber-attacks against Israel. The poster presented various activities as “assisting cyber fronts” and “attacking enemy groups,” framing the battle as a part of a broader cyber campaign. This campaign represents Handala’s status in the Iranian ecosystem: the group operates as part of the Iranian cyberwar where activities are designed not only for technical disruption but also for intimidation, messaging, and narrative warfare: “The poster helps contextualize Handala as part of a state-aligned psychological warfare effort that blends cyber operations with strategic propaganda to project capability, create fear, and legitimize Iranian involvement in the cyber domain.”Footnote21

In late 2024, Handala claimed it hacked into the servers of the Israeli Nuclear Research Center in Nahal Sorek. Then, it hacked into Israel Police databases and leaked large amounts of data, including the details of gun license holders. In early 2025. Handala also breached the computer system at the Israeli Ramat Gan Academic College, ng planti threatening messages on the site. There was also a hack into a large Tel Aviv PR firm, for which a practical purpose is hard to imagine, unless it was to cause distress to its clients. In September 2025, the Canadian government’s Rapid Response Mechanism (RRM Canada) reported that it had detected a “hack and leak” operation by Handala targeting five Iran International journalists, including one from Canada. The hacked materials (released via Handala’s website) ranged from photos of government IDs to intimate content. RRM Canada also detected amplification of the leaked information via multiple AI chatbots, including ChatGPT, Gemini, Copilot, Claude, Grok, and DeepSeek.

On 27 September 2025, on the one-year anniversary of Hezbollah leader Hassan Nasrallah’s death, Handala’s posts claimed that the group had managed to extract what they described as “sensitive information,” including military, governmental, and security data from the Israeli Amos Spacecom Company. They also claimed that they breached into “top-secret communications that, if disclosed, would severely jeopardize (Israeli) national security and disrupt vital defense operations.” To demonstrate the data collected by these operations, the group released what they claimed were “several thousand samples of the company’s orbital satellite communications.”Footnote22 In November 2025, Handala Hacktivists claimed that members of the group broke into the vehicle of a “senior Israeli nuclear scientist,” leaving behind a bouquet of flowers. Handala claimed that a note left at the scene read: “Yesterday, you received our bouquet. A harmless object, at first glance. But you noticed its weight, didn’t you? ,” suggesting that explosives were attached to the bouquet. In December 2025, Handala posted material claiming to identify Israelis engineers involved in designing Israeli missile defense systems. It presented photos, names, professional credentials, email addresses, locations and phone numbers of 13 individuals which Handala described as being key designers of Israeli air defense systems such as Arrow and David’s Sling. “These individuals, who were once thought to be hidden in the shadows, are now fully exposed to the world,” the group argued in its statement. Later in December 2025, Handala claimed to have fully breached the mobile devices of several prominent Israeli political figures. However, “the breaches were limited to Telegram accounts only, not complete phone access.”Footnote23 The first person mentioned was former Prime Minister Naftali Bennett. Handala first claimed to have hacked his iPhone and then released records collected from the phone, including contact lists, photos, videos, and approximately 1,900 chat conversations. Bennett initially denied the breach but later confirmed unauthorized Telegram access while stating his phone remained secure. Shortly afterward, Handala claimed to have breached the iPhone of Tzachi Braverman, Netanyahu’s Chief of Staff. The group claimed having accessed content like financial records, photos, emails, encrypted communications, and evidence of corruption. Handala’s hackers also managed to break into the personal phone of Israeli TV Channel 14 presenter Yinon Magal and released posts against the Prime Minister from his Telegram account. In a similar manner, the account of Israel’s Ambassador to Germany Ron Proshor was also hacked, with tens of thousands of emails exposed. Handala kept posting threats to expose materials tied to political scandals in Israel, including contact lists of senior officials, private videos and classified documents. In March 2026, Handala hackers have broken into the personal email inbox of Kash Patel, FBI’s director, publishing photographs of him and other documents on the internet. The FBI confirmed Patel’s emails had been targeted claimed and that the data involved was historical in nature and involves no government information.

Method

This study applies qualitative content analysis of posts by the Handala hacker group. The aim is to assess whether Handala’s actions are more consistent with state-sponsored cyberterrorism or of psychological warfare and to answer the three sub-questions. The study combines natural language processing (NLP) analysis in Google Colab in order to identify patterns and trends in the data, while relying on inductive manual coding. The study is based on a database of publicly available content associated with the Handala hacker group. The information was manually collected from their official Telegram channels, X-accounts, and website between December 2023 and January 2026. The content includes posts and statements, along with related metadata such as publication date, time, and platform source. The database contains a nearly complete archive of more than 200 posts in English and Persian. Some deleted posts may not have been captured. All posts in Persian were translated into English using online translation tools. Each entry in the database identifies the original text, the publication date, platform used, and language.

The analysis focuses on three dimensions. First, Handala’s narratives were examined using keyword frequency analysis, and inductive thematic coding. This examination was performed to identify patterns relevant to psychological warfare. Second, patterns in cyberattack campaigns and target selection were analyzed by calculating the frequency of cyberattacks based on posts published on Handala’s website. The posting patterns associated with cyber-attack campaigns were analyzed to understand influence attempts (e.g. which posts were designed specifically to influence public sentiment?). Target selection was examined through manual coding of sectors (private, government, security/military, education, media, transportation, and medical). Third, the target audience was identified and categorized by examining language use and framing. At the final stage, the analysis examines the extent to which the patterns observed in the group’s activities and discourse align more closely with the theoretical characteristics of cyberterrorism or psychological warfare.

Analysis

A. Thematic Analysis

At the first stage, keyword frequency analysis was used to identify recurring terms in the database. These terms served as an initial guide for an inductive thematic coding of the posts. Then, at the second stage, the identified themes were grouped into broader narrative frameworks. This process enabled the identification of the main narratives in the database and provided the basis for addressing one of the study’s central research questions: What narratives and influence strategies are used by the Handala Group?

  1. Ideological justification and delegitimization of targets: the Handala hacker group justifies its cyber-attacks with ideological arguments. The main ideological justification is support for Palestinians amid the “Sword of Iron” war. For example, after an alleged hack on the Rosh Ha’ayin Municipal Society Community Center website in February 2024, Handala stated, “We stood by Rafah! This was just a warning. In other cases, they have provided a more detailed justification within the context of current discourse and the situation on the ground: “Ceasefires are meaningless. As long as Kahanists, Bibi, and Sara exist, there will be no peace. Our campaign only intensifies from here.” While the attacks mentioned above were accompanied by statements offering some form of justification, the Octopus Bennett case was primarily aimed at delegitimizing the Israeli leadership. The case of “Operation Octopus,” in which Naftali Bennett’s phone was allegedly hacked in December 2025, exposed chats, and concluded with the following statement: “These chats read less like a conspiracy and more like a cautionary tale. Power without protection. Loyalty without reward. Strategy without execution. In the end, the irony is unavoidable: the man who spoke relentlessly about security could not secure his own circle.”

  2. Cyber dominance and demonstration of capabilities: Handala posts attempt to emphasize their alleged superior abilities in attacking and penetrating Israeli networks in cyberspace. Frequently-used phrases include: “the cyber world has witnessed the true extent of our power!” or, “With operational precision and unwavering resolve, we have breached their layers of secrecy and penetrated to the core of their intelligence network” and “Our ability to infiltrate their most sensitive circles proves that no operation is beyond our reach.” In most cases, Handala provided evidence of their actions by publishing portions of the leaked data for free download or by offering it for sale using a star-based coin on Telegram.

  3. Dominance and control over information: This theme highlights the narratives of Handala’s dominance in cyberspace and their ability to conduct continuous surveillance over their enemies. Posts include phrases such as “We see everything,” “Your communications have been in our hands,” and “Every move you make is being watched,” which all aim to project an image of constant monitoring and control.

  4. Exposure of secrets and hidden truth: Posts associated with the theme of Handala operating with a moral compass, claiming to uncover the “secret machinery of the Zionist regime. Statements such as “no secret is safe. Justice is inevitable” and “the secret machine of the Zionist regime” position Handala as engaged in a campaign of truth and justice.

  5. Continuity and intimidation through timing: The analysis shows that Handala uses timely-worded messaging for intimidation. Phrases such as “The countdown has begun,” “Stay tuned,” and “This isn’t just a single episode” aim to project a sense of intimidation about what is to come and the continuation of cyber-attacks.

  6. Organizational structure and operational continuity: The discourse includes an effort to build an organizational identity. Terms such as operations, unit, team, group, as well as references to official channels and framed campaigns, present military-operational discourse and contribute to conveying a sense of legitimacy and capability. Formal statements of new wings, such as the Handala “Alert Unit,” suggest the group is growing: “We are proud to announce that the Handala People’s Resistance Front of Truth-Seekers (HPR), in line with expanding its range of activities and responding to the growing needs of freedom movements, has launched a new division called Handala Alert.”

B. Target Selection

Target selection was analyzed to answer: How does Handala’s choice of targets and timing reflect their strategic goal? Patterns in cyberattack campaigns and target selection were analyzed by calculating the frequency of cyberattacks based on posts published on Handala’s website. The posting patterns associated with cyber-attack campaigns were analyzed to understand influence attempts. Target selection was examined through manual coding of sectors, including private, government, security/military, education, media, transportation, and medical.

Figure 1. Monthly Emotional Trends (Normalized NRC Scores).

Line graph showing monthly emotional trends (anger, fear, anticipation, trust) from January 2024 to January 2026.

The database analysis indicates that most attacks were directed at Israel. Among the target selection, the private sector is the most prominent, accounting for more than 50% of attacks. Handala justifies attacks on private-sector entities by emphasizing their perceived links to the Israeli government or to security organizations. Therefore, in their view, the sector is not truly private. For example, in reference to an attack on the “Viber” company, Handala stated, “we hacked Viber Messenger, which had become a global spying tool for the Zionists!” In some cases, these companies are also described as providing services that directly or indirectly assisted the Israeli government or Israeli security organizations. For example, in an alleged hack of “Hacked 99 digital,” Handala claimed, “this was a clear message to 8200 not to test our patience with their shell groups!”

After the private sector, security and military targets are most common, accounting for more than 16% of targeted activity. Handala’s cyber-attacks allegedly targeted the IDF, Mossad, Israel Security Agency (ISA), and police. Government targets are equally frequent and include both cyber-attacks on local municipalities and government ministries, with a clear focus on Israeli politicians and government officials. Media and education targets occur considerably less often. Finally, medical and transportation targets are the least represented categories ().

Table 1. Frequency of attacks by target sector (December 2023–January 2026).

An analysis of cyberattacks carried out by the Handala hacker group, by month, found that damage to the private sector occurred from the end of 2023 (the date the hacker group began its activities) until approximately mid-2025, peaking in June 2025. Since that month, the selection of targets shows a relative shift toward security, military, media, and government bodies, including politicians. This situation underscores a strategic shift, one that can be explained by a desire to increase public exposure and influence.

Ideological Campaigns

This analysis seeks to identify patterns in Handala’s operations, including attack timing and operational framing. The analysis focuses on the names Handala gave to their operations and their temporal proximity.

An examination of how the Handala Group publishes and distributes posts about cyberattacks shows that this is not random. In most cases, the group runs targeted campaigns, though some lack a clear distinction; they are linked by the temporal proximity of posts and the use of similar wording. In contrast, some campaigns are framed in uniform language, share a similar design, and exhibit consistent publication patterns. One example is Handala’s “RedWanted” campaign, which included weekly leaks of information on Israeli political or security figures. Analysis of publication patterns on Handala’s Telegram channels indicates that most campaigns are characterized by a preliminary phase that includes threats and promises of future exposure, such as tagging Israeli media outlets, usually on the X network, a central phase consisting of publishing general information and justifications for action, and a concluding phase that includes full advertising and the sale of the data. For example, on 27 December 2025, the day before Benjamin Netanyahu, chief of staff, Tzachi Braverman’s account hack was announced, Handala published a threat in anticipation of the public exposure that was to come: “Bibi, it seems you’re carrying some rather interesting souvenirs with you this time. TikTok… TikTok Sunday, 28 December 2025. 7:30 AM.”

Figure 2. Total number of published attacks posted by Handala.

Line graph showing monthly total attacks from December 2023 to March 2026, peaking at 14 attacks in July 2024.

C. Targeted Audiences

After looking at target selection (which sites or organizations were chosen for attack), we turn to a different question: Which audiences appear to be the primary targets of Handala’s communications? The target audiences were identified by examining use of language, the framing of messaging threats, and mobilization strategies. The analysis suggests that Handala’s posts are targeted at multiple audiences. These include the Israeli public, the Israeli media, political leadership, and the security establishment as well as Western observers and local audiences within Iran—both supporters and opposition groups. The Handala hacker group is directly targeting Israeli news and mainstream media to influence the public and decision-makers. The use of English on almost all of their platforms suggests that their activity is focusing on the West, particularly the U.S. and Israel. In practice, however, their main appeal is mostly to Israel, as evidenced by their tagging of Israeli mainstream media on the X platform in the aftermath of a cyber-attack, which is something they do to increase their exposure. The use of Telegram in English is intended to reach international and Israeli audiences, whereas Telegram in Persian is intended for the Iranian audience, to enhance their sense of power and, conversely, to intimidate their opponents.

Discussion

Our findings reveal that the Handala hacker group systematically employs several key themes in its communication strategy. The first theme concerns the moral framing of the group’s activities, presenting Handala not as a terrorist hacker group, but as an entity with a moral mission to support the Palestinian people and actors it perceives as being attacked by the United States and Israel. By framing their messaging in the context of morality, the group seeks to legitimize its activities and to justify its actions while portraying itself as a legitimate entity operating in the name of justice and moral values. The theme of “exposure of secrets and hidden truth” complements and supports the above-noted theme. Handala presents itself as a group whose goal is to disclose the truth, thereby it attempts to frame its actions as legitimate and even moral, while automatically portraying the opposing side in a negative light. This enables the group to justify its activities while attempting to gain legitimacy from the international audience.

Another central theme is intended to showcase Handala’s “cyber superiority” and to convey an alleged ability to penetrate sensitive systems within Israel. For the group, creating the perception of its enemies being vulnerable appears to be more important than the real effects of the cyber operations themselves. This is also reflected in the group’s rhetoric. In this context, the theme of dominance over information plays a key role, conveying a message of constant presence: “We see everything and are everywhere.” This is an attempt to create the perception of having continuous oversight over enemy systems, in order to exert prolonged psychological pressure. The central message is not the attack itself, but fostering a belief, on the other side that there is no safe space. Handala also presents itself as an expanding and evolving organization, establishing additional units beyond a small group of hackers, with the aim of reinforcing perceptions of power and persistence, which contributes to the overall projection of superiority. These three themes are prominent and intended to exert psychological pressure on the group’s target audiences. The theme of continuity and intimidation through the use of well-timed rhetoric is aimed at having an even greater psychological effect. This approach includes three stages for almost any attack: a pre-threat, set as a promo; a public announcement; and a gradual release of content. The goal is to control how information is released, its timing, the discourse, and to manipulate or control the public exposure to a single attack over an extended period to achieve maximum effect.

Three main axes emerge from the overall thematic analysis. The first emphasizes the legitimacy of the group’s activities and its support for the Palestinian people and justice. The second is designed to create deterrence through messaging that conveys being present everywhere and at all times. The third focuses on sustained attrition, implemented through timed information campaigns that accompany each attack. In this sense, the cyberattacks themselves become the central story, while the actual damage caused is marginalized.

The findings related to target selection indicate that despite repeated declarations of technological superiority, attacks on critical infrastructure intended to cause significant damage have rarely been observed. Handala appears to operate primarily by identifying opportunities for cyber-attack and carefully choosing how to present targets in ways that reinforce a sense of mission, exposure, visible harm, and political–ideological justification. The private sector showcases this dynamic: inconsistent security standards across companies, coupled with a vast target base, create conditions for opportunistic attacks. The shift to targeting political figures toward the end of 2025 was intended to raise awareness of the group’s activities and to garner wider media coverage. These attacks provided Handala with significantly greater exposure. This consideration plays a central role in the choice of target, as does the use of Israeli media outlets’ labeling on the X platform. It can therefore be argued that Handala prioritizes goals with higher media value in order to attract public attention in Israel, and increases its activity in parallel with security and political developments. An examination of how cyberattacks are publicized in Handala posts further underscores that the group’s activity is not random but is often carried out as part of targeted campaigns aimed at securing maximum exposure and achieving greatest a psychological effect. This understanding emphasizes the campaign-oriented nature of the group’s activities, within which managing public tensions is an integral part of strategy.

Results regarding primary targets indicate that the Israeli public is the main audience, with the goal of fostering a sense of ongoing vulnerability. The Israeli media serves both as a target audience and as a key distribution mechanism. The use of English, alongside framings such as “exposing the truth,” reflects s a deliberate attempt to appeal to a Western audience. In addition to its external target audiences, Handala also addresses local Iranian audiences. The activity in Persian, the emphasis on achievements, and the symbolic humiliation of Israel are intended to strengthen feelings of pride, power, and cohesion around the regime. This tactic of using different approaches toward different audiences also reinforces the findings that Handala’s communication strategy incorporates a clear understanding of the rhetoric to use in their posts. In conclusion, the findings indicate that Handala’s activity focuses more on psychological warfare than on damaging the systems they have penetrated. Their cyber-attack seems to be the tool they are using to gain more information about certain figures in order to cause stress and uncertainly among its target audiences but it is not meant to cause actual damage.

Conclusion

The current study sought to examine whether the activities of the Handala hacker group should be seen as an state-operated cyberterrorism, or as a use of cyber capabilities as a tool in the framework of psychological warfare. Based on a qualitative content analysis, the study’s findings emphasize that the Handala hacker group engages in state cyber activity; however, its focus is on waging psychological warfare against Iran’s enemies, primarily Israel, rather than on engaging in activities aimed at causing actual damage to infrastructure. However, this does not mean that Handala lacks these capabilities. As a state-backed actor, Handala may change its objectives in the future.

As for the sub-question concerning how the selection of targets and timing reflect Handala’s strategic goals, the findings of the study indicate that the shift toward focusing on public and political figures was primarily intended to generate greater awareness and coverage within Israel. At an earlier stage, the group attempted to achieve a similar effect through multiple attacks against various entities, with the aim of creating a broad sense of threat. However, when this strategy proved less effective, a change in the patterns of action was evident, a change that also yielded results. The group quickly gained widespread media exposure, focusing not necessarily on the attacks themselves, but on publishing information that had been obtained or was claimed to have been obtained, with the aim of polarizing public opinion in Israel. The careful timing of publication and of rhetoric is another key weapon in Handala’s toolkit. Preliminary publications, which may include campaign labeling, create a “promo” effect for future attacks, aiming to achieve psychological effect. Moreover, the gradual release of published content turns a one-off event into a continuous one, thereby prolonging the psychological effect and intensifying its cognitive impact to serve their strategic goal. Handala uses narratives to showcase superiority (branding of Handala hacking groups and rhetoric aimed at showing they can penetrate sensitive systems), narratives justifying their actions (supporting Palestinian resistance and exposing the “truth”), and narratives aimed at intimidation (use of timing and intimidation of Handala is everywhere). The group’s main target audiences are Western countries, primarily Israel, while appealing to opposition audiences and to audiences that will build support in the internal and external Iranian arena.

Overall, the research findings present a model of a hacker group operating in connection with state infrastructure and integrating cyber activity within a broad strategy of psychological warfare, primarily toward Israel, aimed at influencing consciousness. This model is similar to the patterns of action of other hacker groups operating in direct or indirect contact with Iran. In this case, it is clear that the cyberattack itself is used primarily as a tool for implementing psychological warfare, and not as a means of creating real and lasting damage to the adversary. The main contribution of the study is in emphasizing the need to understand the diversity of actors operating in cyberspace, and in recognizing that their identities, goals, and patterns of action may be dynamic and that they may not necessarily correspond to how they are officially presented. These findings are particularly relevant in the context of information warfare, highlighting the growing threat of cognitive influence on democratic states, the importance of public cognitive resilience and the need to encompass cognitive warfare within the scope of national security.

Disclosure Statement

No potential conflict of interest was reported by the author(s).

Notes

1 Avi Davidi, “Cyber as A Continuation of War By Other Means: Iranian “Handala” Activity, Special Report by the Jerusalem Institute for Strategy and Security (August 2025), https://jiss.org.il/en/davidi-cyber-as-the-continuation-of-war-by-other-means/.

2 US Department of Justice. “Justice Department Disrupts Iranian Cyber Enabled Psychological Operations”, Press Release (March 19, 2026), https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations.

3 Ibid.

4 Idan Dror and Hadar Eichler, “Handala Hack: What We Know About the Rising Threat Actor”, Check Point Report (July 16, 2024), https://cyberint.com/blog/threat-intelligence/handala-hack-what-we-know-about-the-rising-threat-actor/.

5 Check Point, ““Handala Hack” – Unveiling Group’s Modus Operandi”, Research Report (March 12, 2026), https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/.

6 KELA Cyber Intelligence Center (2026). The Handala Hack: Telegram Breach of Israeli Officials. Special Report (January 1, 2026), https://www.kelacyber.com/blog/handala-hack-telegram-breach-israeli-officials/.

7 Ibid.

8 Monroe Price, “Iran and The Soft War”. International Journal of Communication, 6, 239–256. https://ijoc.org/index.php/ijoc/article/download/1654/799/7024.

9 Daniel Haberfeld,” Iran’s Information Warfare During the December 2025 – January 2026 Protests and Its Continued Influence on Israel and the West”, Special Report, International Institute for Counter Terrorism (February 4, 2026), https://ict.org.il/irans-information-warfare-during-the-december-2025-january-2026-protests/.

10 Itay Haiminis, Iran’s Information Warfare. The Institute for National Security Studies (INSS), https://www.inss.org.il/wp-content/uploads/2019/10/Haiminis.pdf.

11 Nitzan Yasur & Danny Citrinowicz, Iranian Foreign Information Manipulation and Interference During the Swords of Iron War. Institute for National Security Studies. Special Report (November 12, 2024), https://www.inss.org.il/publication/iran-influence/.

12 Ron Schleifer and Gabriel Weimann, “Déjà Vu? Iranian PSYOP against Israel in the 2025 conflict”, Journal of the Middle East and Africa (2026, forthcoming).

13 Ibid.

14 Boaz Ben-David, Tchelet Bressler, Lia Ring, Ortal Shimon-Raz & Yuval Palgi, “Trauma Echoes: Factors Associated With Peritraumatic Distress and Anxiety Five Days Following Iranian Missile Attack on Israel. European Journal of Psychotraumatology, 16 (2025), 2446070, https://www.tandfonline.com/doi/full/10.1080/20008066.2024.2446070

15 Ari Ben Am, “Iranian Influence Operations Targeting Israel Since October 7”, Foundation for Defense of Democracies (FDD) Report (2025), https://www.fdd.org/analysis/2025/08/28/a-year-of-meming-dangerously-iranian-influence-operations-targeting-israel-since-october-7/.

16 Haiminins, op. cit.

17 Davidi, op.cit.

18 Cyber-Terrorism Desk, op.cit., p. 1.

20 Ibid.

21 Cyber-Terrorism Desk, “Bibi Gate: Handala Hack Team—A Mask for Iranian Psychological Warfare”, Special Report by the Cyber Desk, International Institute for Counter-Terrorism (2025, p. 5), https://ict.org.il/wp-content/uploads/2025/12/Download.pdf.

22 These citations appear in the Cyber-Terrorism Desk report, ibid.

23 KELA, op. cit.