APT / THREAT GROUP💰 FINANCIAL
homeland
1
aliases
Intelligence Profile
homeland — tracked by MISP Galaxy (ransomware).
Threat Analysis
homeland is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of financial.
Financially motivated threat actors like homeland prioritize monetary gain through methods such as ransomware deployment, banking trojans, cryptocurrency theft, BEC scams, or credential harvesting for resale on underground markets.
Intelligence Reports Mentioning homeland
DHS confirms hackers breached HSIN info-sharing platform
BleepingComputer· Jul 1, 2026
DHS chief says president has met with likely CISA nominee; agency plans to hire 600
The Record· Jun 25, 2026
An ICE Firearms Trainer Was Involved in At Least 4 Deadly Shootings
Wired Security· May 18, 2026
Government to Scrutinize Instructure Over Canvas Disruption, Data Breach
SecurityWeek· May 13, 2026
US govt seeks Instructure testimony on massive Canvas cyberattack
BleepingComputer· May 12, 2026
DHS Demanded Google Surrender Data on Canadian’s Activity, Location Over Anti-ICE Posts
Wired Security· May 4, 2026
ICE Is Paying the Salaries of This Town’s Entire Police Force
Wired Security· Mar 24, 2026
“Handala Hack” – Unveiling Group’s Modus Operandi
Check Point Research· Mar 12, 2026
External References
Quick Facts
TypeAPT / Threat Group
Motivation💰 financial
Aliases1
Also Known As
homeland
DLS Infrastructure
● ONLINEhomelandjustice.ru
Research Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.