Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors VOID MANTICORE

Also known as: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, Red Sandstorm, DUNE, Storm-0842

Description

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including (LinkByld: C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026) VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

Goals & Targeting

Targeted Sectors

Government
Healthcare
Pharmaceutical
Telecommunications
Education
Media
Non profit

AI Analysis

· 1 week ago

Executive Summary

VOID MANTICORE is a cyber threat group linked to Iran's Ministry of Intelligence and Security (MOIS), active since mid-2022. The group conducts destructive operations, including wiper attacks and hack-and-leak campaigns, targeting government, healthcare, pharmaceutical, telecommunications, education, media, and non-profit sectors. Operating under aliases such as COBALT MYSTIQUE and Handala Hack, VOID MANTICORE has been involved in significant attacks against entities in Albania, Israel, and the United States.

Goals & Targeting

VOID MANTICORE's strategic objectives appear to align with broader Iranian intelligence interests, likely focusing on data collection, disruption of critical infrastructure, and undermining geopolitical opponents. The targeting profile reflects a focus on sectors that hold sensitive information or have operational continuity critical to national security, such as government agencies, healthcare systems, telecommunications networks, and defense contractors. The group's geographic targeting includes countries with strategic significance to Iran, particularly those involved in regional conflicts or with significant influence over Iranian interests.

Enhanced Description

VOID MANTICORE is a state-sponsored cyber threat group attributed to Iran's Ministry of Intelligence and Security (MOIS). The group has demonstrated a high level of sophistication, employing both destructive and espionage-focused tactics. Known for its wiper attacks and hack-and-leak campaigns, VOID MANTICORE primarily targets critical infrastructure, government entities, and private sector organizations across multiple countries. The group operates under several aliases, including COBALT MYSTIQUE, Handala Hack, Karma, and others, reflecting its adaptive nature in operations. Recent activities include a March 2026 attack against Stryker Corporation. VOID MANTICORE is also linked to Scarred Manticore, another cyber threat group, which provides initial access operations before VOID MANTICORE's active engagement. The group's operations often involve significant disruptive and damaging impacts on its targets.

Key Capabilities

  • State-sponsored cyberattacks
  • Wiper malware deployment
  • Hack-and-leak operations
  • Destructive data wiping techniques
  • Collaboration with other APT groups (e.g., Scarred Manticore)
  • Use of advanced persistent threat tactics

MITRE ATT&CK Tactics

Data Destruction
Disruption Operations
Lateral Movement
Credential Access
Defense Evasion
Discovery
Exfiltration
Impact

ATT&CK Techniques

T1560.001
T1490
T1113
T1087.002
T1561.001
T1110.001
T1027.015
T1213.002
T1123
T1133
T1036.005
T1005
T1119
T1552.002
T1003.001
T1041
T1059.001
T1679
T1098
T1588.002
T1114.002
T1486
T1078.002
T1059.006
T1071.001
T1651
T1021.001
T1078.004
T1047
T1561.002
T1082
T1589
T1484.001
T1657
T1072
T1547.001
T1564.003
T1684.001
T1219.002
T1485
T1059.006

Software / Tooling

Wiper malware
State-sponsored hacking tools
Custom attack frameworks

Campaigns & Victims

VOID MANTICORE has demonstrated a steady operational tempo, with campaigns targeting high-value assets in critical sectors. The group's ability to adapt personas and maintain persistence highlights its capability for long-term operations. Notable past operations include attacks against Stryker Corporation and other entities in the U.S., Israel, and Albania. The group's collaboration with Scarred Manticore underscores a possible network of threat actors under Iranian intelligence control.

IOC Patterns

  • Spear-phishing emails targeting specific organizations
  • C2 communication using encrypted protocols
  • Presence of wiper malware on infected systems
  • Unusual account activity in targeted networks
  • Destruction of system data through known wiping techniques

Recommended Actions

  • Implement robust email filtering to detect spear-phishing attempts.
  • Monitor for unusual network traffic and process behavior indicative of wiper malware.
  • Regularly back up critical systems and test restoration processes to mitigate data loss from wiper attacks.
  • Enhance incident response capabilities to detect and respond to APT activities promptly.
  • Conduct regular security audits, focusing on known TTPs associated with VOID MANTICORE.

Suggested Tags

APT
Cyber Espionage
State-Sponsored
Critical Infrastructure
Wiper Malware

Confidence Assessment

High confidence in VOID MANTICORE's state-sponsored nature and operational capabilities, based on multiple intelligence sources. However, gaps exist in understanding specific toolsets and exact geographic targeting patterns.

ATT&CK Techniques

Collection
9 techniques
Command & Control
5 techniques
Credential Access
5 techniques
Execution
6 techniques
Impact
6 techniques
Persistence
3 techniques
Resource Development
9 techniques
Stealth
9 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Check Point VOID MANTICORE Handala Hack March 2026 — Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.
  2. DOJ FBI Handala Hack March 2026 — DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.
  3. Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026 — DomainTools Investigations. (2026, April 6). Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment. Retrieved April 20, 2026.
  4. Palo Alto VOID MANTICORE Iran Cyber Threats March 2026 — Justin Moore. (2026, March 16). Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization. Retrieved April 20, 2026.
  5. Sophos VOID MANTICORE COBALT MYSTIQUE other Names April 2026 — Sophos. (2026, April 20). Iran COBALT MYSTIQUE. Retrieved April 20, 2026.

Intel Summary

63

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
Government Targeting
Wiper / Destructive
APT
Cyber Espionage
State-Sponsored
Wiper Malware

Details

MITRE ID
G1055
Type
Unknown
Country of Origin
I
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--ebd7ce77-c9ba-4fba-bb28-58296ac66559
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.