VOID MANTICORE

MITRE ATT&CK: G1055 View on attack.mitre.org

Aliases: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, Red Sandstorm, DUNE, Storm-0842, VOID MANTICORE, Void Manticore

First seen
2022-06-01 00:00:00
Origin
IR
Primary motivation
sabotage
Sophistication
advanced
Resource level
government
Actor type
Espionage, Information Operations, Sabotage
Profile updated
2026-07-07 11:51:59

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical

Targeted regions: country_code:al country_code:il country_code:us

Context

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.

Detection coverage

  • 1000 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Password Guessing (attack-pattern)
  • Automated Collection (attack-pattern)
  • Disk Content Wipe (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Phishing (attack-pattern)
  • Gather Victim Identity Information (attack-pattern)
  • Financial Theft (attack-pattern)
  • Web Service (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Group Policy Modification (attack-pattern)
  • Hidden Window (attack-pattern)
  • Domains (attack-pattern)
  • Audio Capture (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Remote Email Collection (attack-pattern)
  • Data Staged (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Compression (attack-pattern)
  • Impersonation (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Selective Exclusion (attack-pattern)
  • Domain Account (attack-pattern)
  • Malware (attack-pattern)

Reports & references

  • services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
  • CrowdStrike — Banished Kitten (report)
  • research.checkpoint.com — Bad Karma No Justice Void Manticore Destructive Activities In Israel (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G1055 (report)
  • dti.domaintools.com — Handala Mois Linked Cyber Influence Ecosystem Threat Intelligence Assessment (report)
  • research.checkpoint.com — Handala Hack Unveiling Groups Modus Operandi (report)
  • Palo Alto Unit 42 — Evolution Of Iran Cyber Threats (report)
  • justice.gov — Dl (report)
  • sophos.com — Cobalt Mystique (report)

Attributed from

  • HomeLand Justice (campaign)

External references