← All reports

DTI Releases Deep Dive on MOIS-Linked Cyber Ecosystem Tracking Handala and Homeland Justice Campaigns

Science & ResearchApr 18, 2026score 0.653 posts · 0 replies across 2 instances
DomainTools Intelligence (DTI) published detailed research mapping the evolution of the MOIS-linked cyber ecosystem. The analysis specifically tracks activities from the 2022 Albania attacks through hypothesized incidents up to 2026, covering elements related to 'Handala' and 'Homeland Justice'. Users are circulating the research, with @neurovagrant noting its significant expansion beyond prior analysis of 'Handala and related MOIS personas,' spurred by high user demand concerning Incident Response (IR) threat actors and underground intelligence 'whispernets.' @DomainTools emphasized the timeline, covering events from Albania to the 2026 Stryker incident. @gayint promoted the intelligence, specifically pointing to its CTI (Cyber Threat Intelligence) indicators. The entire collection is functioning as a concerted promotion for this single, advanced threat intelligence piece. The focus is singular: disseminating the deep analysis on the MOIS-linked cyber activities tied to 'Handala' and geopolitics.

Key points

SUPPORT
The research covers the MOIS-linked cyber ecosystem's evolution, spanning from the 2022 Albania attacks to a hypothetical 2026 Stryker incident.
Strong emphasis placed on the comprehensive timeline detailed by @DomainTools.
SUPPORT
The publication was accelerated due to intense user questioning regarding Incident Response (IR) threat actors and underground intelligence trends.
According to @neurovagrant, user inquiry volume forced the release of the material.
SUPPORT
The intelligence package is framed as highly specialized, containing actionable CTI indicators.
This specificity was noted by @gayint when tagging the research with #CTI.
SUPPORT
The subject matter connects to 'Handala' and 'Homeland Justice' personas, referencing geopolitical conflict indicators.
Multiple posts reference this core set of aliases and associated campaigns.
MIXED
One user provided a highly cryptic reference, potentially indicating an internal community signal regarding the leak's nature.
The hashtag #GAYINT appended by @gayint warrants attention as an outlier signal.

Source posts

@[email protected]
I know everyone's hungering for more cyber reads on Friday afternoon, so we've published a long read on Handala and related MOIS personas, expanding greatly on the shorter post from April 6. We were originally going to keep this one closely held, but the number of questions we're fielding about IR threat actors, and some trends in current whispernets, convinced us to publish it instead. #threatintel #cybersecurity #infosec https://dti.domaintools.com/research/mois-linked-moist-grasshopper-homeland-justice-karmabelow80-handala-hackers-campaigns-and-evolution
2 boosts · 0 favs · 0 replies · Apr 17, 2026
#threatintel#cybersecurity#infosec
@[email protected]
New DTI Research: The evolution of the MOIS-linked cyber ecosystem (Handala/Homeland Justice) from the 2022 Albania attacks to the 2026 Stryker incident🛡️🇮🇷 Full research and analysis:https://dti.domaintools.com/research/mois-linked-moist-grasshopper-homeland-justice-karmabelow80-handala-hackers-campaigns-and-evolution #ThreatIntel #Handala #Cybersecurity #Iran
1 boosts · 0 favs · 0 replies · Apr 17, 2026
#iran#cybersecurity#handala#threatintel
@[email protected]
💅 https://dti.domaintools.com/research/mois-linked-moist-grasshopper-homeland-justice-karmabelow80-handala-hackers-campaigns-and-evolution #GAYINT #CTI #threatIntel
10 boosts · 0 favs · 4 replies · Apr 18, 2026
#gayint#cti#threatintel