VOID MANTICORE
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including [HomeLand Justice](https://attack.mitre.org/campaigns/C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
Properties
- stix_id
- intrusion-set--ebd7ce77-c9ba-4fba-bb28-58296ac66559
- type
- intrusion-set
MITRE ATT&CK Techniques (50)
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, enc
An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to cap
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this techn
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.(Citation: Trend
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense
Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand,
Adversaries may use compression to obfuscate their payloads or files. Compressed file formats such as ZIP, gzip, 7z, and RAR can compress and archive
Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasio
Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information th
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and networ
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to
Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and net
Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large n
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in fol
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense E
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresse
Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their op
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications chan
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, an
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own fina
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety o
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of e
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be display
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.(Citati
Campaigns (1)
[HomeLand Justice](https://attack.mitre.org/campaigns/C0038) was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Alba
Explore this actor's full graph with Ninja Signal