NEWS Iran has opened the HR department. Vacancy: spy, arsonist, a mercenary. Resume – in Telegram

pinkman

BOSS
Staff member
ADMIN
LEGEND
ULTIMATE
SUPREME
MEMBER
BFD Legacy
Joined
Feb 3, 2025
Messages
2,253
Reaction score
19,012
Deposit
0$
The Handala group has become from a team of activists into an Iranian intelligence network.
1780480655100.png
Iranian intelligence, according to Insikt Group, began using the well-known name Handala not only for cyber attacks, but also for threats in the real world. The brand, which was previously associated primarily with data leaks and attacks on Israeli organizations, now brings together networking, recruitment, surveillance, arson and attempts to put pressure on targets related to the United States and Israel.

Experts believe that the expansion of Handala is the Ministry of Intelligence of Iran. One-link to the Handala Hack Team now includes a new Handala Popular Resistance Front structure, as well as VIPU employation, MOISIRAN and Brave Israel. All these groups, according to Insikt Group, are promoting a similar scheme: through Telegram and other sites, they are looking for people who are ready to perform tasks against American and Israeli facilities for money.

The Handala Hack Team became visible after the start of the war between Israel and Hamas. The group presented itself as independent activists supporting Palestinian resistance and declared hacking from Israeli government agencies, law enforcement agencies, technology companies and critical infrastructure. Among the stated goals were also U.S. officials and the military.

The new phase is due to the emergence of the Handala Popular Resistance Front. On April 26, 2026, this structure reported on the arson of a car allegedly belonging to an employee of the Israeli internal security service Shin Bet. The published materials included links to the Handala Hack Team website and the VIPU employ, through which, according to Insikt Group, recruited performers.

VIPUPUDment has previously been associated with attempts to hire people outside Iran for espionage, arson, sabotage and attacks. The network focused primarily on the Israeli audience, but after the escalation of the conflict, it expanded geography and began to spread appeals in groups associated with Europe, the countries of the Persian Gulf, Australia, Latin America and English-speaking political communities.

MOISIRAN plays a separate role. This Telegram channel published materials that were called surveillance by Israeli military, intelligence officers, members of the unit 8200 and scientists associated with the nuclear sphere. Brave Israel, according to Insikt Group, could be an early prototype of such a recruiting network. In 2024, the channel offered money for graffiti, photos with given inscriptions and arson of cars in Israel.

The main danger of such a scheme is not in a separate group, but in the combination of different types of pressure under one recognizable name. Hacking can give personal data, addresses, correspondence or travel routes, and related to Handala networks can use this information to spy, intimidate or prepare attacks on objects and individuals.

For most organizations, the main risk is still associated with the Handala Hack Team cyberattacks. The group is known for publishing the stolen data, conducting devastating attacks and trying to create a sense of vulnerability to victims. But the Insikt Group warns that a bundling of cyber attacks with the recruitment of performers increases the threat to law enforcement agencies, military, intelligence agencies, energy, transport and scientific organizations in the region.

According to the forecast of Insikt Group, such operations can continue even with a ceasefire or a formal reduction in tension. Iranian structures have already used similar methods before the current war, and combining digital pressure, propaganda and physical threats under the Handala brand makes such campaigns more noticeably and more dangerous.
 
Top Bottom