Handala
Unknown Dormant
- Mentions
- 1
- First seen
- 23 Jul 2026
- Last seen
- 23 Jul 2026
Relevant to you · Affects your stack
- Technology:
- Siemens SIMATIC WinCC
- Threat focus:
- espionage / aptddos / hacktivismindustrial / ot espionage
- Sector / region:
- Manufacturing
Origin
Unattributed
Profile
Handala is an Iranian hacktivist group that, according to a US warning, targets industrial control systems (ICS) from Siemens, Schneider Electric, and Rockwell Automation. The group may be linked to Iranian state actors and focuses on critical infrastructure. The goal could be sabotage or espionage.
Affected vendors
SiemensSchneider ElectricRockwell Automation
Targeted sectors
Industrial Control SystemsCritical Infrastructure
Targeted regions
Worldwide