DomainTools Investigations. (2026, April 6). Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment. Retrieved April 20, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
GroupVOID MANTICORE | VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications. |
| T1078 Valid Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions. |
| T1098 Account Manipulation |
GroupVOID MANTICORE | VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access. |
| T1110.001 Password Guessing |
GroupVOID MANTICORE | VOID MANTICORE has conducted password guessing to gain initial access. |
| T1110.004 Credential Stuffing |
GroupVOID MANTICORE | VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments. |
| T1119 Automated Collection |
GroupVOID MANTICORE | VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems. |
| T1204.002 Malicious File |
GroupVOID MANTICORE | VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance. |
| T1566 Phishing |
GroupVOID MANTICORE | VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector. |
| T1583.001 Domains |
GroupVOID MANTICORE | VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations. |
| T1583.006 Web Services |
GroupVOID MANTICORE | VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure. |
| T1585.001 Social Media Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures. |
| T1588.001 Malware |
GroupVOID MANTICORE | VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.