VOID MANTICORE
MITRE ATT&CK: G1055 View on attack.mitre.org
Aliases: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, Red Sandstorm, DUNE, Storm-0842, VOID MANTICORE, Void Manticore
- First seen
- 2022-06-01 00:00:00
- Origin
- IR
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage, Information Operations, Sabotage
- Profile updated
- 2026-07-07 11:51:59
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical
Targeted regions: country_code:al country_code:il country_code:us
Context
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.
Detection coverage
- 1000 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Password Guessing (attack-pattern)
- Automated Collection (attack-pattern)
- Disk Content Wipe (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Phishing (attack-pattern)
- Gather Victim Identity Information (attack-pattern)
- Financial Theft (attack-pattern)
- Web Service (attack-pattern)
- PowerShell (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Group Policy Modification (attack-pattern)
- Hidden Window (attack-pattern)
- Domains (attack-pattern)
- Audio Capture (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Remote Email Collection (attack-pattern)
- Data Staged (attack-pattern)
- Domain Accounts (attack-pattern)
- Compression (attack-pattern)
- Impersonation (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Selective Exclusion (attack-pattern)
- Domain Account (attack-pattern)
- Malware (attack-pattern)
Reports & references
- services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
- CrowdStrike — Banished Kitten (report)
- research.checkpoint.com — Bad Karma No Justice Void Manticore Destructive Activities In Israel (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G1055 (report)
- dti.domaintools.com — Handala Mois Linked Cyber Influence Ecosystem Threat Intelligence Assessment (report)
- research.checkpoint.com — Handala Hack Unveiling Groups Modus Operandi (report)
- Palo Alto Unit 42 — Evolution Of Iran Cyber Threats (report)
- justice.gov — Dl (report)
- sophos.com — Cobalt Mystique (report)
Attributed from
- HomeLand Justice (campaign)
External references
- mitre-attack — G1055
- BANISHED KITTEN
- Red Sandstorm
- Handala Hack
- Homeland Justice
- Karma
- COBALT MYSTIQUE
- Karmabelow80
- Check Point VOID MANTICORE Handala Hack March 2026
- DOJ FBI Handala Hack March 2026
- Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026
- Palo Alto VOID MANTICORE Iran Cyber Threats March 2026
- Sophos VOID MANTICORE COBALT MYSTIQUE other Names April 2026
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy