Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupVOID MANTICORE | VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`. |
| T1021.001 Remote Desktop Protocol |
GroupVOID MANTICORE | VOID MANTICORE has used RDP to move laterally within the victim environment. |
| T1047 Windows Management Instrumentation |
GroupVOID MANTICORE | VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`. |
| T1078 Valid Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions. |
| T1078.002 Domain Accounts |
GroupVOID MANTICORE | VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access. |
| T1087.002 Domain Account |
GroupVOID MANTICORE | VOID MANTICORE has utilized ADRecon to enumerate the active directory environment. |
| T1105 Ingress Tool Transfer |
GroupVOID MANTICORE | VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website. |
| T1110 Brute Force |
GroupVOID MANTICORE | VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure. |
| T1133 External Remote Services |
GroupVOID MANTICORE | VOID MANTICORE has leveraged public facing VPN infrastructure to gain initial access to victim environments. |
| T1199 Trusted Relationship |
GroupVOID MANTICORE | VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access. |
| T1219.002 Remote Desktop Software |
GroupVOID MANTICORE | VOID MANTICORE has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once. |
| T1484.001 Group Policy Modification |
GroupVOID MANTICORE | VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file. |
| T1485 Data Destruction |
GroupVOID MANTICORE | VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them. |
| T1486 Data Encrypted for Impact |
GroupVOID MANTICORE | VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts. |
| T1490 Inhibit System Recovery |
GroupVOID MANTICORE | VOID MANTICORE has deleted virtual machines directly from the virtualization platform. |
| T1552.002 Credentials in Registry |
GroupVOID MANTICORE | VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM. |
| T1561.002 Disk Structure Wipe |
GroupVOID MANTICORE | VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files. |
| T1572 Protocol Tunneling |
GroupVOID MANTICORE | VOID MANTICORE has used tunneling tools to facilitate destructive attacks on compromised devices. |
| T1583.003 Virtual Private Server |
GroupVOID MANTICORE | VOID MANTICORE has utilized VPS solutions for C2. |
| T1583.006 Web Services |
GroupVOID MANTICORE | VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure. |
| T1585.001 Social Media Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures. |
| T1588.002 Tool |
GroupVOID MANTICORE | VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities. |
| T1686.003 Windows Host Firewall |
GroupVOID MANTICORE | VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.