← Dispatches

TLP:CLEAR · 2026-03-12

Behind the Firewall: Inside Handala's Origin Server, Hidden Domains, and the Architecture They Built to Outlast Every Ban

Handala's DDoS-Guard protection has a hole in it. The www. subdomain was never routed through the CDN. Hitting the origin server directly — 185.208.156.82, Global-Data System IT Corporation, Zürich — returns a live WordPress installation with its REST API wide open. From there: a complete operational timeline dating to December 18, 2023, a predecessor domain (handala.cx) that predates the known infrastructure by seven months, a dedicated bounty platform (handala-redwanted.to) running Microsoft IIS on Windows Server in Amsterdam, a Telegram persona named Akhira, and a four-month operational blackout in 2025 that ended exactly when their n8n automation server came online. We went through the firewall. Here is what was behind it.

The Misconfiguration

DDoS-Guard protects handala-hack.to — its edge node at 185.178.208.137 (Rostov-na-Donu, Russia) terminates external connections and geoblocks by IP, blocking our server, blocking Tor exit nodes, blocking everything it classifies as non-civilian traffic.

The protection has one gap. www.handala-hack.to resolves to 185.208.156.82 — a separate IP that bypasses DDoS-Guard entirely. This is a standard DNS misconfiguration: the operator pointed the apex domain through DDoS-Guard but forgot the www. record. The origin server sits fully exposed.

RecordIPVia
handala-hack.to185.178.208.137DDoS-Guard edge (Rostov-na-Donu, Russia)
www.handala-hack.to185.208.156.82Direct to origin server

The TLS certificate on 185.208.156.82 covers *.handala-hack.to and handala-hack.to — issued by Let's Encrypt (R12), valid through March 17, 2026. Sending HTTP requests to the IP with Host: handala-hack.to returns the full site without challenge.

The Origin Server

185.208.156.82 — Zürich, Switzerland — AS42624, Global-Data System IT Corporation. LiteSpeed web server. WordPress 6.9.1. One identified plugin: top-bar.

The WordPress REST API (/wp-json/) is fully accessible without authentication. The xmlrpc.php endpoint is blocked (403). User enumeration via /wp-json/wp/v2/users returns one registered account:

FieldValue
WordPress user ID1
Usernamevie6c
Profile URLhttps://handala.cx

The profile URL is the first thread. handala.cx is not in prior public reporting. Every published analysis of Handala infrastructure references handala-hack.to and handala.to. The WordPress author profile points somewhere else entirely.

The Original Domain: handala.cx

handala.cx (Christmas Island TLD) is the original Handala leak site — predating handala-hack.to by seven months.

DomainFirst TLS CertificateNotes
handala.cxDecember 11, 2023Google Trust Services issuer (GTS CA 1P5)
handala-hack.toJuly 24, 2024Let's Encrypt

The first cert on handala.cx was issued by Google Trust Services — unusual for a threat actor, but consistent with a Google-managed hosting environment or Cloudflare-fronted origin. Subsequent renewals switched to Let's Encrypt and Sectigo. The domain now returns no DNS A record — it has been retired — but the WordPress operator profile still points to it, establishing it as the original operational identity.

The first post published to the WordPress installation (ID: 17, December 18, 2023) contains the original channel listing:

https://t.me/Handala_hack
https://t.me/Handala_Leak
https://t.me/Handala_backup
https://x.com/handala_hack

Three Telegram channels at launch. The x.com/handala_hack account — later banned August 21, 2024 — was operational from the December 2023 start.

The Complete Operations Timeline

The WordPress REST API returns all published posts in chronological order. This is the first complete public enumeration of Handala's operation history from origin, spanning December 2023 through March 2026:

Phase 1 — handala.cx (December 2023 – February 2025)

DateOperationTarget
2023-12-18First postAbout Handala / Telegram channels
2024-03-14Viber MessengerSource code + management panel, 740GB, 8 BTC asking price
2024-04-05Unit 8200 targetingSIGINT unit personnel files
2024-07-15Sheba Medical CenterIsrael's largest hospital
2024-07-26Innovalve Bio Medical3TB claimed, $300M valuation taunted
2024-08-22EPS TechMilitary source code leak
2024-09-23Benny GantzFormer defense minister, war cabinet member
2024-09-24Israel Defense MinisterPrivate photos
2024-09-26Foreign Affairs MinisterEmail archive
2024-09-28Soreq NRCIsrael's primary nuclear research center
2024-10-02Israel Prime MinisterEmail archive
2024-10-03Shin BetInternal Security Service
2024-09-19VidiscoIsraeli defense electronics manufacturer
2024-09-19Israeli Industrial Batteries (IIB)Industrial infrastructure
2024-10-06IIB data leakFollow-on release
2024-10-08Israeli Ambassador, GermanyEmail archive
2024-10-08Max Shop
2024-10-10Doscast
2024-10-28Agas
2024-10-30IM Cannabis
2024-11-03Elad MunicipalityLocal government
2024-11-21SSV Blockchain NetworkFinancial infrastructure
2024-11-24SilicomIsraeli networking hardware company
2024-12-03Harel Insurance / ShirbitFinancial sector
2024-12-16GNS CloudCloud infrastructure provider
2024-12-25ReutoneChristmas day operation
2024-12-30Allen Carr's Easyway
2025-01-20Zuk Group
2025-01-29Ministry of National Security
2025-02-02TosafIndustrial chemicals
2025-02-09Israel Police

Phase 2 — Operational Gap (February 9 – June 14, 2025)

Post IDs jump from 315 (February 9, 2025) to 320 (June 14, 2025) — a four-month operational hiatus. No published operations, no claimed victims. This gap aligns exactly with the period of post-X-ban restructuring: Handala lost its primary amplification channel (August 21, 2024), built the gramatikservicesapi.top n8n automation infrastructure (September 9, 2024), and spent the following months rebuilding operational cadence. They returned in June 2025 at significantly higher tempo.

Phase 3 — handala-hack.to resumed (June 2025 – March 2026)

DateOperationTarget
2025-06-14Israel fuel supply systemMulti-target campaign, 4 posts same day
2025-06-18Weizmann Institute of ScienceNobel Prize-level research institution
2025-06-23Shelter Locations in IsraelCivilian infrastructure targeting — coordinates disclosed
2025-07-08Iran InternationalLondon-based anti-regime Persian media — 2.5-year persistent access claimed; WhatsApp, Signal, internal files
2025-07-09Iran International staff doxxedIranian expat journalists' identities exposed; Mossad cooperation alleged
2025-07-10Yinon MagalIsraeli media personality and politician
2025-09-27Amos SpacecomIsraeli satellite operator; employee list released
2025-10-07HPR entity formalized + RedWanted launchedOrganizational restructuring announced
2025-10-18Saturday ReckoningStart of weekly Saturday personnel disclosure series
2025-10-19Commemoration of Reza AwadaHezbollah commander killed by Israel — ideological statement
2025-11-29Dr. Isaac GertzDescribed as "Chief Nuclear Architect of the Zionist Regime"
2025-11-29Unit 8200 personnelSIGINT corps members doxxed
2025-12-13Arrow / David's Sling engineersMissile defense system personnel doxxed
2025-12-17Operation OctopusNaftali Bennett — former Prime Minister — personal communications; 200,000-message archive
2025-12-28Tzachi BravermanNetanyahu cabinet chief of staff
2026-01-03Ayelet ShakedFormer Justice Minister, iPhone exfiltration, contact lists
2026-01-0315 SIGINT agents$50,000 RedWanted bounty per target
2026-01-18Avraham Hayyim / Mehrdad RahimiClaimed Mossad agent identity exposure
2026-01-21i24 ChannelIsraeli English-language TV news network
2026-02-19Sapir's CommanderIDF officer identity exposure
2026-02-25ClalitIsrael's largest healthcare organization
2026-03-07Jerusalem Water Supply423 GB exfiltrated; core infrastructure claimed crippled (via Handala Alert)
2026-03-08Israeli Weather StationsMilitary + civilian meteorological systems claimed wiped (via Handala Alert)
2026-03-0950 Senior IAF OfficersComplete dossiers of Israeli Air Force officers involved in bombing campaigns; linked to RedWanted (via Handala Alert)
2026-03-11Stryker Corporation200,000 devices wiped via Intune MDM — largest single-operation device count claimed

Total documented operations: 130+ since December 18, 2023. The above are selected high-significance entries. The full post archive on the origin server (REST API, unauthenticated) contains the complete record. June 2025 alone saw a burst of 20+ operations against Israeli companies as the group returned from its four-month hiatus at dramatically higher tempo.

Operations not yet on the main WordPress blog (sourced from handala-alert.to, the new media hub): Saudi Aramco, Sharjah National Oil Corporation (UAE), Israel Institute for National Security Studies (INSS), IDF Farsi social accounts. Dates unconfirmed from this source.

Post Timing: Operator Working Hours

Analysis of all 100 post timestamps (UTC) reveals operator working patterns:

UTC HourPost Count
08:009
10:008
12:0010
13:008
14:0013 (peak)
15:005

Peak activity window: 08:00–15:00 UTC. In Tehran (UTC+3:30), this maps to 11:30–18:30 local time — a standard Iranian working day. The distribution drops sharply after 16:00 UTC (19:30 Tehran), consistent with end-of-shift behavior. The n8n automation server uses Asia/Jerusalem timezone (UTC+2/+3), but operator posting patterns are consistent with an Iranian time zone, not an Israeli one. The Asia/Jerusalem timezone on the automation server likely reflects targeting focus — automating campaigns in Israeli business hours — rather than operator location.

The Tor Onion: A Placeholder

vmjfieomxhnfjba57sd6jjws2ogvowjgxhhfglsikqvvrnrajbmpxqqd.onion is reachable via Tor SOCKS5 proxy. It returns:

HTTP/1.1 200 OK
Server: nginx
Content-Length: 0
Last-Modified: Mon, 22 Jul 2024 12:11:00 GMT
ETag: "669e4c54-0"

The response body is empty. All enumerated paths return 404. The Last-Modified timestamp — July 22, 2024 — is two days before the first handala-hack.to TLS certificate was issued (July 24, 2024). The onion was provisioned as a blank nginx placeholder simultaneously with the clearnet infrastructure buildout. It exists to demonstrate Tor capability and provide a persistent hidden address, not to serve content.

DDoS-Guard blocks Tor exit nodes specifically. When accessing handala-hack.to via Tor, the __ddg9_ tracking cookie logs the exit node IP (observed: 185.220.101.47). The geoblocking is not country-based alone — it maintains an active Tor exit node blocklist.

The RedWanted Platform: handala-redwanted.to

handala-redwanted.to is a separate infrastructure deployment from the main WordPress site, discovered via post content referencing the domain.

PropertyValue
IP192.142.53.75
HostingAS214036, Ultahost, Inc. — Amsterdam, Netherlands
StackMicrosoft IIS/10.0 (Windows Server)
ProtocolHTTP only — no TLS certificate
Favicon sourcehandala-hack.to/wp-content/uploads/2025/07/ — links both sites

The Windows Server / IIS stack is the most operationally significant detail. The main site runs LiteSpeed on Linux. The automation server runs n8n on Ubuntu/Docker. RedWanted runs IIS on Windows. This indicates a different developer or team member built this application — someone working in a Windows environment, likely using ASP.NET or Node on Windows.

The platform is a custom application with Bootstrap 3 frontend and server-side filtering. Target categories as enumerated from the filter dropdown:

CategoryNotes
Elbit SystemIsrael's largest defense contractor
BIRD AeroSystemsAirborne EW and self-protection systems
Iron DomeAir defense system engineers
Israel Air ForceIAF personnel
Weizmann InstituteScientific research institution
Israel Ministry of Defense
UCAV/UAV IndustryDrone warfare technology
NSO GroupIsraeli spyware developer
Patriot Missile SystemUS air defense system
David's Sling SystemMulti-tier missile defense
ELTA SystemsIAI subsidiary — radar, EW, SIGINT
Israel Sea ForceNaval forces
RafaelDefense manufacturer (SPIKE, Iron Dome)
SoreqNuclear research center
Arrow Weapon SystemBallistic missile defense
IAIIsrael Aerospace Industries
Unit 8200SIGINT intelligence corps
C4I SystemsCommand, control, communications
Amos SpacecomIsraeli satellite operator
AmanMilitary intelligence directorate
Haifa AcHaifa Academic institutions (Technion / University of Haifa)
Indoor Robotics LtdIsraeli civilian indoor drone company — extends targeting to civilian technology sector

The inclusion of Patriot Missile System is significant: this extends Handala's declared targeting beyond Israeli entities to US defense infrastructure. The NSO Group category indicates the group tracks both Israeli defense contractors and Israeli intelligence software vendors.

Platform profiles use AI-assisted generation — verbose, threatening first-person surveillance narratives built from LinkedIn and public career data. Each profile ends with a reward amount (typically $30,000–$50,000) payable in cryptocurrency, with a contact link for tip submission.

The Akhira Identity

@HPRNEW on Telegram — the HPR INTELLIGENCE announcement account — displays the name "Akhira" (آخرة). The name translates from Arabic as *the Hereafter* or *the Afterlife* — the Islamic concept of the world after death. This is a persona or operator handle, not a channel name. The Telegram page returns "You can contact @HPRNEW right away" — indicating a personal account or bot, not a public broadcast channel, consistent with the account functioning as a direct contact point for tip submission and operator communication.

Live probing of the WordPress origin server identified three additional accounts not previously documented in public reporting:

AccountPlatformNotes
@Handala_RedX/TwitterEmbedded in WordPress theme social links block — dedicated account for the RedWanted bounty platform
@Handala_newsX/Twitter"Sunset of the Lions" — announced January 25, 2026; fourth X presence post-ban
t.me/HANDALA_HPR2Telegram811 subscribers; active as of March 11, 2026; amplified the Stryker operation

The account proliferation reflects a deliberate resilience strategy: maintain multiple parallel presences so that any single ban does not eliminate reach. The original @Handala_Hack was banned August 21, 2024. @HPRNEW followed. @Handala_Red and @Handala_news were built in parallel. Each account serves a distinct function: @HPRNEW for general operations, @Handala_Red for the bounty platform, @Handala_news for media amplification.

The Exposed Database

PostgreSQL is internet-exposed on port 5432 at 64.176.169.27 (gramatikservicesapi.top, the n8n automation server). The server responds to connection requests and presents SCRAM-SHA-256 authentication:

Response: SCRAM-SHA-256\x00

The database is not open — authentication is enforced. But its internet exposure is an additional misconfiguration: a properly secured n8n deployment should bind PostgreSQL to 127.0.0.1 only. This server has PostgreSQL accessible on any interface, protected only by the password.

Handala Alert: The Expanding Infrastructure

The WordPress origin server contains a post (January 3, 2026, ID 607) announcing a new operational division: Handala Alert, described as the "media and operational arm of HPR." A live domain — handala-alert.to — was registered for this division.

PropertyValue
Domainhandala-alert.to
IP82.38.63.237
HostingAS214036, Ultahost, Inc. — Falkenberg, Sweden
StackMicrosoft IIS/10.0 (Windows Server) — same stack as handala-redwanted.to
Last-ModifiedMarch 10, 2026 (active, updated 2 days before this writing)

The Swedish hosting (Ultahost, AS214036) mirrors the infrastructure pattern seen across other Handala assets — low-profile European VPS providers that avoid major hosting ASNs. The Microsoft IIS/Windows stack matches handala-redwanted.to exactly, indicating the same developer built both platforms.

Handala Alert operates as a news aggregator and media hub: it publishes operation announcements, links to third-party coverage, and serves as the release point for operations that have not yet been published to the main WordPress blog. The March 2026 operations documented in the timeline above (Jerusalem water supply, weather stations, 50 IAF officers) appeared on handala-alert.to days before the main site. The site also links to two internal documents: handala-briefing-1.pdf and handala-briefing-2.pdf — both returning 403 as of this writing.

The declared mandate of Handala Alert includes: media support for allied resistance groups, partisan operations inside Israel, recruitment inside Israeli territory, intelligence acquisition, and support for anti-regime groups abroad. The last category — "support for anti-authoritarian groups abroad" — marks an explicit expansion of scope beyond Israeli targets.

Infrastructure Map: The Full Picture

DomainIPHostingStackFirst Seen
handala.cx (offline)UnknownWordPressDec 11, 2023
handala-hack.to (via DDoS-Guard)185.178.208.137DDoS-Guard, RussiaEdge nodeJul 24, 2024
handala-hack.to (origin)185.208.156.82AS42624, Zürich CHWP 6.9.1 + LiteSpeedJul 24, 2024
handala.to103.224.212.206Trellian parkingFingerprintJS redirectActive
handala-redwanted.to192.142.53.75AS214036, Amsterdam NLIIS/10.0, WindowsDec 2025
gramatikservicesapi.top64.176.169.27AS20473 Vultrn8n 1.61.0 + PostgreSQLSep 9, 2024
handala-alert.to82.38.63.237AS214036, Ultahost, SwedenMicrosoft-HTTPAPI/2.0, WindowsJan 3, 2026
Tor onionnginx (blank)Jul 22, 2024

Intercept Cell Research is a Cipher Cortex research program. Hooked Scams is a scam investigation series from Intercept Cell Research.