Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts
In December 2025, the hacking group Handala, linked to Iran, claimed to have compromised the mobile devices of two Israeli political figures. However, analysis by Kela cyber intelligence researchers indicated that the breaches were limited to Telegram…
In December 2025, the hacking group Handala, linked to Iran, claimed to have compromised the mobile devices of two Israeli political figures. However, analysis by Kela cyber intelligence researchers indicated that the breaches were limited to Telegram accounts, rather than full device access.
The group alleged that they breached former Prime Minister Naftali Bennett's iPhone 13, releasing contact lists, photos, videos, and approximately 1,900 chat conversations. They later claimed similar access to Tzachi Braverman's device, the Israeli Chief of Staff. Despite these claims, the actual breach revealed vulnerabilities in account security rather than device-level compromise.
Kela's forensic examination of the leaked materials showed that most exposed conversations were empty contact cards generated by Telegram during synchronization. Only about 40 conversations contained actual messages, with even fewer showing substantial exchanges. All exposed contacts were linked to active Telegram accounts, confirming the data source.
The incident highlighted vulnerabilities in session management and account security, even on encrypted messaging platforms. The infection mechanism likely involved multiple attack vectors, such as SIM swapping and exploiting SS7 protocol weaknesses in telecommunications infrastructure. Additionally, sophisticated phishing campaigns may have captured one-time passwords through fake login pages or malicious QR codes.
In December 2025, the hacking group Handala, linked to Iran, claimed to have compromised the mobile devices of two Israeli political figures.
Session hijacking was another probable attack vector, involving the copying of the tdata folder from Telegram Desktop. This authentication file contains active session data that can grant full account access when restored elsewhere, bypassing OTP and multi-factor authentication.
The group potentially harvested OTP codes through various techniques, such as triggering verification via voice calls, extracting codes from voicemail by exploiting unchanged default PINs, or impersonating Telegram support to socially engineer staff into disclosing credentials.
Telegram's default settings increased these risks. The cloud password feature is optional and disabled by default, allowing OTP possession to provide complete account access. Standard chats lack end-to-end encryption, storing data on Telegram servers rather than locally, thus expanding the attack surface.
Handala first emerged in December 2023, establishing presence across multiple cybercrime forums and operating various Telegram channels. Their operations have primarily targeted Israeli companies and organizations, demonstrating support for Iran and Palestinian causes.
Based on reporting by Cyber Security News.




