ATT&CKReferencesCheck Point VOID MANTICORE Handala Hack March 2026

Check Point VOID MANTICORE Handala Hack March 2026

Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupVOID MANTICORE

VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.

T1021.001
Remote Desktop Protocol
GroupVOID MANTICORE

VOID MANTICORE has used RDP to move laterally within the victim environment.

T1047
Windows Management Instrumentation
GroupVOID MANTICORE

VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.

T1078
Valid Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions.

T1078.002
Domain Accounts
GroupVOID MANTICORE

VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access.

T1087.002
Domain Account
GroupVOID MANTICORE

VOID MANTICORE has utilized ADRecon to enumerate the active directory environment.

T1105
Ingress Tool Transfer
GroupVOID MANTICORE

VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.

T1110
Brute Force
GroupVOID MANTICORE

VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure.

T1133
External Remote Services
GroupVOID MANTICORE

VOID MANTICORE has leveraged public facing VPN infrastructure to gain initial access to victim environments.

T1199
Trusted Relationship
GroupVOID MANTICORE

VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.

T1219.002
Remote Desktop Software
GroupVOID MANTICORE

VOID MANTICORE has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once.

T1484.001
Group Policy Modification
GroupVOID MANTICORE

VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.

T1485
Data Destruction
GroupVOID MANTICORE

VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.

T1486
Data Encrypted for Impact
GroupVOID MANTICORE

VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.

T1490
Inhibit System Recovery
GroupVOID MANTICORE

VOID MANTICORE has deleted virtual machines directly from the virtualization platform.

T1552.002
Credentials in Registry
GroupVOID MANTICORE

VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM.

T1561.002
Disk Structure Wipe
GroupVOID MANTICORE

VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files.

T1572
Protocol Tunneling
GroupVOID MANTICORE

VOID MANTICORE has used tunneling tools to facilitate destructive attacks on compromised devices.

T1583.003
Virtual Private Server
GroupVOID MANTICORE

VOID MANTICORE has utilized VPS solutions for C2.

T1583.006
Web Services
GroupVOID MANTICORE

VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure.

T1585.001
Social Media Accounts
GroupVOID MANTICORE

VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.

T1588.002
Tool
GroupVOID MANTICORE

VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.

T1686.003
Windows Host Firewall
GroupVOID MANTICORE

VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.