ATT&CKGroupsVOID MANTICORE

VOID MANTICORE

G1055

Threat group.View on attack.mitre.org

About this group

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.

Techniques used63

Procedure examples63

TechniqueProcedure example
T1003.001
LSASS Memory

VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.

T1005
Data from Local System

VOID MANTICORE has collected cached data and files from within the victim environment.

T1021.001
Remote Desktop Protocol

VOID MANTICORE has used RDP to move laterally within the victim environment.

T1027.015
Compression

VOID MANTICORE has compressed their payloads by leveraging zip files.

T1036.004
Masquerade Task or Service

VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts.

T1036.005
Match Legitimate Resource Name or Location

VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram.

T1041
Exfiltration Over C2 Channel

VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.

T1047
Windows Management Instrumentation

VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.

T1059.001
PowerShell

VOID MANTICORE has utilized PowerShell to execute malware in victim environments.

T1059.006
Python

VOID MANTICORE has utilized Python scripts to execute its malicious payloads.

T1071.001
Web Protocols

VOID MANTICORE has utilized HTTPS for communication to C2 domains.

T1072
Software Deployment Tools

VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.

T1074
Data Staged

VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2.

T1078
Valid Accounts

VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions.

T1078.002
Domain Accounts

VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access.

View all 63 procedure examples

Software0

None recorded.

Campaigns1

References4

  1. Check Point VOID MANTICORE Handala Hack March 2026 Open source
    Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.
  2. DOJ FBI Handala Hack March 2026 Open source
    DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.
  3. Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026 Open source
    DomainTools Investigations. (2026, April 6). Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment. Retrieved April 20, 2026.
  4. Palo Alto VOID MANTICORE Iran Cyber Threats March 2026 Open source
    Justin Moore. (2026, March 16). Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization. Retrieved April 20, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.