Threat group.View on attack.mitre.org
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`. |
| T1005 Data from Local System |
VOID MANTICORE has collected cached data and files from within the victim environment. |
| T1021.001 Remote Desktop Protocol |
VOID MANTICORE has used RDP to move laterally within the victim environment. |
| T1027.015 Compression |
VOID MANTICORE has compressed their payloads by leveraging zip files. |
| T1036.004 Masquerade Task or Service |
VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts. |
| T1036.005 Match Legitimate Resource Name or Location |
VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram. |
| T1041 Exfiltration Over C2 Channel |
VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications. |
| T1047 Windows Management Instrumentation |
VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`. |
| T1059.001 PowerShell |
VOID MANTICORE has utilized PowerShell to execute malware in victim environments. |
| T1059.006 Python |
VOID MANTICORE has utilized Python scripts to execute its malicious payloads. |
| T1071.001 Web Protocols |
VOID MANTICORE has utilized HTTPS for communication to C2 domains. |
| T1072 Software Deployment Tools |
VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune. |
| T1074 Data Staged |
VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2. |
| T1078 Valid Accounts |
VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions. |
| T1078.002 Domain Accounts |
VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.