Also known as: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, Red Sandstorm, DUNE, Storm-0842
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including (LinkByld: C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026) VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
Targeted Sectors
Executive Summary
VOID MANTICORE is a cyber threat group linked to Iran's Ministry of Intelligence and Security (MOIS), active since mid-2022. The group conducts destructive operations, including wiper attacks and hack-and-leak campaigns, targeting government, healthcare, pharmaceutical, telecommunications, education, media, and non-profit sectors. Operating under aliases such as COBALT MYSTIQUE and Handala Hack, VOID MANTICORE has been involved in significant attacks against entities in Albania, Israel, and the United States.
Goals & Targeting
VOID MANTICORE's strategic objectives appear to align with broader Iranian intelligence interests, likely focusing on data collection, disruption of critical infrastructure, and undermining geopolitical opponents. The targeting profile reflects a focus on sectors that hold sensitive information or have operational continuity critical to national security, such as government agencies, healthcare systems, telecommunications networks, and defense contractors. The group's geographic targeting includes countries with strategic significance to Iran, particularly those involved in regional conflicts or with significant influence over Iranian interests.
Enhanced Description
VOID MANTICORE is a state-sponsored cyber threat group attributed to Iran's Ministry of Intelligence and Security (MOIS). The group has demonstrated a high level of sophistication, employing both destructive and espionage-focused tactics. Known for its wiper attacks and hack-and-leak campaigns, VOID MANTICORE primarily targets critical infrastructure, government entities, and private sector organizations across multiple countries. The group operates under several aliases, including COBALT MYSTIQUE, Handala Hack, Karma, and others, reflecting its adaptive nature in operations. Recent activities include a March 2026 attack against Stryker Corporation. VOID MANTICORE is also linked to Scarred Manticore, another cyber threat group, which provides initial access operations before VOID MANTICORE's active engagement. The group's operations often involve significant disruptive and damaging impacts on its targets.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
VOID MANTICORE has demonstrated a steady operational tempo, with campaigns targeting high-value assets in critical sectors. The group's ability to adapt personas and maintain persistence highlights its capability for long-term operations. Notable past operations include attacks against Stryker Corporation and other entities in the U.S., Israel, and Albania. The group's collaboration with Scarred Manticore underscores a possible network of threat actors under Iranian intelligence control.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in VOID MANTICORE's state-sponsored nature and operational capabilities, based on multiple intelligence sources. However, gaps exist in understanding specific toolsets and exact geographic targeting patterns.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
63
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
14
Tactics