FORENSIA

THREAT_ACTOR · G1055

VOID MANTICORE

Also known as: VOID MANTICORE, COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, Red Sandstorm

Profile

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.

MITRE ATT&CK ↗

Techniques

63 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1005 Data from Local SystemT1021.001 Remote Desktop ProtocolT1027.015 CompressionT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1041 Exfiltration Over C2 ChannelT1047 Windows Management InstrumentationT1059.001 PowerShellT1059.006 PythonT1071.001 Web ProtocolsT1072 Software Deployment ToolsT1074 Data StagedT1078 Valid AccountsT1078.002 Domain AccountsT1078.004 Cloud AccountsT1082 System Information DiscoveryT1087.002 Domain AccountT1098 Account ManipulationT1102 Web ServiceT1105 Ingress Tool TransferT1110 Brute ForceT1110.001 Password GuessingT1110.004 Credential StuffingT1113 Screen CaptureT1114.002 Remote Email CollectionT1119 Automated CollectionT1123 Audio CaptureT1125 Video CaptureT1133 External Remote ServicesT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1204.002 Malicious FileT1213.002 SharepointT1219.002 Remote Desktop SoftwareT1484.001 Group Policy ModificationT1485 Data DestructionT1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1547.001 Registry Run Keys / Startup FolderT1552.002 Credentials in RegistryT1560.001 Archive via UtilityT1561.001 Disk Content WipeT1561.002 Disk Structure WipeT1564.003 Hidden WindowT1566 PhishingT1572 Protocol TunnelingT1583.001 DomainsT1583.003 Virtual Private ServerT1583.004 ServerT1583.006 Web ServicesT1585.001 Social Media AccountsT1585.002 Email AccountsT1587.001 MalwareT1588.001 MalwareT1588.002 ToolT1589 Gather Victim Identity InformationT1595.002 Vulnerability ScanningT1651 Cloud Administration CommandT1657 Financial TheftT1679 Selective ExclusionT1684.001 ImpersonationT1686.003 Windows Host Firewall

Related corpus activity

10,459 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to VOID MANTICORE.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-11837cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2025-0921cve852
cve-2013-3307cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2016-5681cve852
cve-2025-66478cve852
cve-2026-22584cve852
cve-2021-27076cve851
cve-2025-68670cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2020-22658cve852
cve-2022-47945cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,459.