{"id":9630,"date":"2026-01-03T10:03:40","date_gmt":"2026-01-03T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/03\/handala-hackers-targeted-israeli-officials-by-compromising-telegram-accounts\/"},"modified":"2026-01-03T10:03:40","modified_gmt":"2026-01-03T10:03:40","slug":"handala-hackers-targeted-israeli-officials-by-compromising-telegram-accounts","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/03\/handala-hackers-targeted-israeli-officials-by-compromising-telegram-accounts\/","title":{"rendered":"Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts"},"content":{"rendered":"<p>    Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In December 2025, the Iranian-linked hacking group Handala claimed to have fully compromised the mobile devices of two prominent Israeli political figures. <\/p>\n<p>However, detailed analysis by Kela cyber intelligence researchers revealed a more limited scope\u2014the breaches targeted Telegram accounts specifically, not complete device access. <\/p>\n<p>The group claimed to have breached former Prime Minister Naftali Bennett\u2019s iPhone 13 during Operation Octopus, releasing contact lists, photos, videos, and approximately 1,900 chat conversations. <\/p>\n<p>Shortly after, they claimed similar access to Tzachi Braverman\u2019s device, the Israeli Chief of Staff. Despite these dramatic claims, the actual breach exposed critical gaps in account security rather than device-level compromise.<\/p>\n<p>Kela analysts conducted <a href=\"https:\/\/cybersecuritynews.com\/digital-forensics-in-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">forensic examination<\/a> of the leaked materials and identified that most of the exposed conversations were empty contact cards automatically generated by Telegram during synchronization. <\/p>\n<p>Only about 40 conversations contained actual messages, with even fewer showing substantial exchanges. All exposed contacts linked to active Telegram accounts, confirming the data originated from Telegram itself. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrgqVnT-mjcNlaFZTVQKTxfCkbNLpMtfTSubKOzt2uM-dSWxxJbbgDCFpanERxajpsRvjVEuN01CtJQcB4YPQQPkaZK0AkYs7Nl4MXUMFPTz_v39V174T9KcwSEb1yAiKx2dCcgFC6tyWi_GiiRlf2Bramzuzm0O7h4A2Xl-wyfjv-EPcLF8cTx1ZxZkU\/s16000\/Contacts%2520were%2520linked%2520to%2520active%2520Telegram%2520%28Source%2520-%2520Kela%29.webp?ssl=1\" alt=\"Contacts were linked to active Telegram (Source - Kela)\"><figcaption class=\"wp-element-caption\">Contacts were linked to active Telegram (Source \u2013 Kela)<\/figcaption><\/figure>\n<\/div>\n<p>Kela researchers and analysts <a href=\"https:\/\/www.kelacyber.com\/blog\/handala-hack-telegram-breach-israeli-officials\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the incident highlighted serious vulnerabilities in session management and account security practices, even on encrypted messaging platforms.<\/p>\n<p>Understanding the infection and account takeover mechanism reveals how Handala compromised these accounts without full device access. <\/p>\n<p>The group likely employed multiple attack vectors including SIM swapping, where attackers assume control of the victim\u2019s phone number to receive login verification codes. <\/p>\n<p>They could also exploit SS7 protocol weaknesses in telecommunications infrastructure to intercept SMS messages at the network level. Additionally, Handala may have utilized sophisticated phishing campaigns that captured one-time passwords through fake login pages or <a href=\"https:\/\/cybersecuritynews.com\/why-secure-qr-code-scanning-matters-in-a-cybersecurity-first-world\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious QR codes<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-session-hijacking\">\n<strong>Session hijacking<\/strong> <\/h2>\n<p>Session hijacking represented another probable vector, where attackers copied the tdata folder from Telegram Desktop\u2014the authentication file containing active session data that grants full account access when restored elsewhere, bypassing OTP and multi-factor authentication entirely.<\/p>\n<p>The group\u2019s operational approach also included harvesting OTP codes through multiple techniques: triggering verification via voice calls, extracting codes from voicemail by exploiting unchanged default PINs, or impersonating Telegram support to socially engineer staff into disclosing credentials. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjZywEikDEfxOoxzhiqfYV1o4VOLQHgu7CgOkal6hpVYPLN3mIOF7XKJjWWeM8ToGf2Atcg9MqsxAlSFr2gdG_XY5uC-ltSEAISjSh8RjGTn1GGSoMh_Te-94ErF07LfBNql_bFLxVfdt3icQmN_VjvU4Wo4EnG_-pwStc0vskXBZ8GLVz-n4xHuSjN1qA\/s16000\/Leaked%2520data%2520%28Source%2520-%2520Kela%29.webp?ssl=1\" alt=\"Leaked data (Source - Kela)\"><figcaption class=\"wp-element-caption\">Leaked data (Source \u2013 Kela)<\/figcaption><\/figure>\n<\/div>\n<p>Telegram\u2019s default settings significantly amplified these risks. The cloud password feature remains optional and disabled by default, meaning possession of an OTP alone provides complete account access. <\/p>\n<p>Standard chats lack end-to-end encryption, storing data on Telegram servers as cloud chats rather than locally, expanding the attack surface considerably.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjqSTdwzsSqrEsECMlhn1POTTMekCv8MyazKJfKPbpfLIoO0fma4EzDTI_rtgxVBzpmvqbW-bQRApbIVi2tF_k09l6XxAdyrIWc8PjLzYAC2couiwm1QLCk1GReIycvv_h82L43cIHh8RzRMNZpactvzIQ1Y9YnUgB_ajaDgqjVlK-qTLoiiT6hP9bWqhc\/s16000\/Handala%2520post%2520on%2520cybercrime%2520platform%2520BreachForums%2520%28Source%2520-%2520Kela%29.webp?ssl=1\" alt=\"Handala post on cybercrime platform BreachForums (Source - Kela)\"><figcaption class=\"wp-element-caption\">Handala post on cybercrime platform BreachForums (Source \u2013 Kela)<\/figcaption><\/figure>\n<\/div>\n<p>Handala first emerged in December 2023, establishing presence across multiple cybercrime forums and operating various Telegram channels and social media accounts. <\/p>\n<p>Their operations primarily targeted Israeli companies and organizations, consistently demonstrating support for Iran and Palestinian causes throughout their <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a>, indicating state-sponsored or state-sympathetic motivations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/handala-hackers-targeted-israeli-officials\/\">Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/handala-hackers-targeted-israeli-officials\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts In December 2025, the Iranian-linked hacking group Handala claimed to have fully compromised the mobile devices of two prominent Israeli political figures. However, detailed analysis by Kela cyber intelligence researchers revealed a more limited scope\u2014the breaches targeted Telegram accounts specifically, not complete device access. The group [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9630","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9630"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9630"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9630\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}