Threat Actor Profile
High
Cybercriminal
Description
Not a Ransomware Group
Confidence Score
Tags
ransomware
ransomware.live
First Seen
Unknown
Last Updated
Unknown
Active Status
ActiveCreated
April 29, 2026
Indicators of Compromise
Loading IOCs…
IOC KQL for Sentinel
STIX Data
{'added_date': None,
'client': '2003264@sit.singaporetech.edu.sg',
'description': 'Not a Ransomware Group',
'firstseen': '2024-04-05T07:35:34+00:00',
'group': 'handala',
'has_negotiations': False,
'has_ransomnote': False,
'lastseen': '2026-04-07T10:21:49+00:00',
'locations': [{'available': True,
'fqdn': 'handala.to',
'slug': 'https://handala.to/',
'title': '',
'type': 'DLS'},
{'available': True,
'fqdn': 'handala-hack.tw',
'slug': 'http://handala-hack.tw',
'title': 'Security Verification',
'type': 'DLS'},
{'available': False,
'fqdn': 'handala-team.to',
'slug': 'http://handala-team.to',
'title': 'Error Response Page',
'type': 'DLS'},
{'available': False,
'fqdn': 'vmjfieomxhnfjba57sd6jjws2ogvowjgxhhfglsikqvvrnrajbmpxqqd.onion',
'slug': 'http://vmjfieomxhnfjba57sd6jjws2ogvowjgxhhfglsikqvvrnrajbmpxqqd.onion',
'title': '',
'type': 'DLS'},
{'available': True,
'fqdn': 'handala-hack.to',
'slug': 'https://handala-hack.to/',
'title': 'This Website Has Been Seized',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 0,
'tiaras_metadata': {'has_negotiations': False,
'has_ransomnote': False,
'locations': [{'available': True,
'fqdn': 'handala.to',
'slug': 'https://handala.to/',
'title': '',
'type': 'DLS'},
{'available': True,
'fqdn': 'handala-hack.tw',
'slug': 'http://handala-hack.tw',
'title': 'Security Verification',
'type': 'DLS'},
{'available': False,
'fqdn': 'handala-team.to',
'slug': 'http://handala-team.to',
'title': 'Error Response Page',
'type': 'DLS'},
{'available': False,
'fqdn': 'vmjfieomxhnfjba57sd6jjws2ogvowjgxhhfglsikqvvrnrajbmpxqqd.onion',
'slug': 'http://vmjfieomxhnfjba57sd6jjws2ogvowjgxhhfglsikqvvrnrajbmpxqqd.onion',
'title': '',
'type': 'DLS'},
{'available': True,
'fqdn': 'handala-hack.to',
'slug': 'https://handala-hack.to/',
'title': 'This Website Has Been Seized',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 0,
'ransomware_live_group': 'handala',
'tools': {},
'url': 'https://www.ransomware.live/group/handala',
'victims': 176,
'vulnerabilities': []},
'tiaras_source': 'ransomware.live',
'tools': {},
'ttps': [],
'url': 'https://www.ransomware.live/group/handala',
'victims': 176,
'vulnerabilities': []}