G1055: VOID MANTICORE
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).[1] Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.[1][2] VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.[1][3] VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.[4]
Security context for executives and security teams
G1055: VOID MANTICORE describes [VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Thre...
Executive priority
G1055: VOID MANTICORE is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1055: VOID MANTICORE by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1055: VOID MANTICORE appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
VOID MANTICORE
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).[1] Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.[1][2] VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.[1][3] VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.[4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1113 | Screen Capture | VOID MANTICORE has captured screen content during an active Zoom session.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1110.001 | Password GuessingSub-technique | VOID MANTICORE has conducted password guessing to gain initial access.[4] |
| Enterprise | T1119 | Automated Collection | VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems.[4] |
| Enterprise | T1561.001 | Disk Content WipeSub-technique | VOID MANTICORE has utilized a disk wiping utility to facilitate destructive actions on victim servers.[3] VOID MANTICORE has also utilized legitimate remote disk wiping commands.CitationSPECOPS Outpost24 Handala Hack Stryker March 2026 |
| Enterprise | T1486 | Data Encrypted for Impact | VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.[1][3] |
| Enterprise | T1566 | Phishing | VOID MANTICORE has emailed victims threatening messages.[3] VOID MANTICORE has used phishing as an initial access vector.[4] |
| Enterprise | T1589 | Gather Victim Identity Information | VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1657 | Financial Theft | VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion.CitationSPECOPS Outpost24 Handala Hack Stryker March 2026[3] VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency.[3] |
| Enterprise | T1102 | Web Service | VOID MANTICORE has utilized Telegram API for C2.[3]CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1059.001 | PowerShellSub-technique | VOID MANTICORE has utilized PowerShell to execute malware in victim environments.[3]CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1047 | Windows Management Instrumentation | VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.[1] |
| Enterprise | T1484.001 | Group Policy ModificationSub-technique | VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.[1] |
| Enterprise | T1564.003 | Hidden WindowSub-technique | VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1583.001 | DomainsSub-technique | VOID MANTICORE has registered domains for messaging purposes.CitationSPECOPS Outpost24 Handala Hack Stryker March 2026 VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion.[3]CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex.[3] VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.[4] |
| Enterprise | T1123 | Audio Capture | VOID MANTICORE has gathered audio during a Zoom session.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1190 | Exploit Public-Facing Application | VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604.[3] |
| Enterprise | T1114.002 | Remote Email CollectionSub-technique | VOID MANTICORE has gathered victim email-content from victim servers.[3] |
| Enterprise | T1074 | Data Staged | VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1078.002 | Domain AccountsSub-technique | VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access.[1] |
| Enterprise | T1027.015 | CompressionSub-technique | VOID MANTICORE has compressed their payloads by leveraging zip files.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1684.001 | ImpersonationSub-technique | VOID MANTICORE has impersonated individuals familiar to the victim and technical support associated with social messaging services.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications.[3]CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1679 | Selective Exclusion | VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1087.002 | Domain AccountSub-technique | VOID MANTICORE has utilized ADRecon to enumerate the active directory environment.[1] |
| Enterprise | T1588.001 | MalwareSub-technique | VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.[4] |
| Enterprise | T1490 | Inhibit System Recovery | VOID MANTICORE has deleted virtual machines directly from the virtualization platform.[1] |
| Enterprise | T1072 | Software Deployment Tools | VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions.CitationSPECOPS Outpost24 Handala Hack Stryker March 2026[2] VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.CitationSPECOPS Outpost24 Handala Hack Stryker March 2026[2] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.[1] |
| Enterprise | T1651 | Cloud Administration Command | VOID MANTICORE has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices.[2] |
| Enterprise | T1583.003 | Virtual Private ServerSub-technique | VOID MANTICORE has utilized VPS solutions for C2.[1] |
| Enterprise | T1583.006 | Web ServicesSub-technique | VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity.[1]CitationSPECOPS Outpost24 Handala Hack Stryker March 2026 VOID MANTICORE has also leveraged Starlink internet services.[1] VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure.[4] |
| Enterprise | T1686.003 | Windows Host FirewallSub-technique | VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host.[1] |
| Enterprise | T1552.002 | Credentials in RegistrySub-technique | VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM.[1] |
| Enterprise | T1213.002 | SharepointSub-technique | VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data.[3] |
| Enterprise | T1219.002 | Remote Desktop SoftwareSub-technique | VOID MANTICORE has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once.[1] |
| Enterprise | T1595.002 | Vulnerability ScanningSub-technique | VOID MANTICORE has scanned victim environments for susceptibility to vulnerability exploitation.[3] |
| Enterprise | T1561.002 | Disk Structure WipeSub-technique | VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files.[1] |
| Enterprise | T1583.004 | ServerSub-technique | VOID MANTICORE has leveraged backend servers within Iran.[3] |
| Enterprise | T1105 | Ingress Tool Transfer | VOID MANTICORE has deployed additional payloads from dedicated C2 servers.[1][3]CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 VOID MANTICORE has also downloaded legitimate tools and software from publicly available services.[1] VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.[1] |
| Enterprise | T1082 | System Information Discovery | VOID MANTICORE has gathered system information and disseminated it back to C2.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1078.004 | Cloud AccountsSub-technique | VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.[2] VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment.CitationSEC 8-K Stryker Corporation Filing Handala Hack March 2026 |
| Enterprise | T1133 | External Remote Services | VOID MANTICORE has leveraged public facing VPN infrastructure to gain initial access to victim environments.[1] |
| Enterprise | T1588.002 | ToolSub-technique | VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.[1] |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | VOID MANTICORE has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1204.002 | Malicious FileSub-technique | VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file.[3]CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.[4] |
| Enterprise | T1005 | Data from Local System | VOID MANTICORE has collected cached data and files from within the victim environment.CitationSPECOPS Outpost24 Handala Hack Stryker March 2026[3]CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1098 | Account Manipulation | VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.[4]CitationSEC 8K Palo Alto Statement Stryker Corp Handala March 2026 |
| Enterprise | T1125 | Video Capture | VOID MANTICORE has collected video from compromised victim devices.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1572 | Protocol Tunneling | VOID MANTICORE has used tunneling tools to facilitate destructive attacks on compromised devices.[1] |
| Enterprise | T1587.001 | MalwareSub-technique | VOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper.[3] |
| Enterprise | T1585.002 | Email AccountsSub-technique | VOID MANTICORE has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’.[3] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | VOID MANTICORE has utilized HTTPS for communication to C2 domains.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1199 | Trusted Relationship | VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.[1] |
| Enterprise | T1110.004 | Credential StuffingSub-technique | VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments.[4] |
| Enterprise | T1585.001 | Social Media AccountsSub-technique | VOID MANTICORE has created Telegram Accounts.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram.[1]CitationSPECOPS Outpost24 Handala Hack Stryker March 2026[3] VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.[4] |
| Enterprise | T1485 | Data Destruction | VOID MANTICORE has conducted data wiping attacks on compromised systems.[1]CitationSPECOPS Outpost24 Handala Hack Stryker March 2026[3][2] VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.[1][3] |
| Enterprise | T1078 | Valid Accounts | VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure.[1] VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.[4] VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions.[1] |
| Enterprise | T1110 | Brute Force | VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure.[1] |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1059.006 | PythonSub-technique | VOID MANTICORE has utilized Python scripts to execute its malicious payloads.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | VOID MANTICORE has stored collected data in a password protected compressed file prior to exfiltration.CitationFBI IC3 Flash VOID MANTICORE Handala Hack March 2026 |
| Enterprise | T1041 | Exfiltration Over C2 Channel | VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.[4] |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | VOID MANTICORE has used RDP to move laterally within the victim environment.[1] |
Groups, software, and campaigns
C0038: HomeLand Justice
HomeLand Justice was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for HomeLand Justice was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including HEXANE who probed victim infrastructure.[1][2][3] A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.[3]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | 9b0115e951c5… | ||
| 19.1 | 1.0 | Older bundle | 3196289b91d0… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Check Point VOID MANTICORE Handala Hack March 2026
Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.
Open source URL - [2]Palo Alto VOID MANTICORE Iran Cyber Threats March 2026
Justin Moore. (2026, March 16). Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization. Retrieved April 20, 2026.
Open source URL - [3]DOJ FBI Handala Hack March 2026
DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.
Open source URL - [4]Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026
DomainTools Investigations. (2026, April 6). Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment. Retrieved April 20, 2026.
Open source URL - [5]BANISHED KITTEN
(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
- [6]COBALT MYSTIQUE
(Citation: Sophos VOID MANTICORE COBALT MYSTIQUE other Names April 2026)
- [7]Handala Hack
(Citation: DOJ FBI Handala Hack March 2026)
- [8]Homeland Justice
(Citation: DOJ FBI Handala Hack March 2026)
- [9]Karma
(Citation: DOJ FBI Handala Hack March 2026)
- [10]Karmabelow80
(Citation: Sophos VOID MANTICORE COBALT MYSTIQUE other Names April 2026)
- [11]Red Sandstorm
(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
- [12]Sophos VOID MANTICORE COBALT MYSTIQUE other Names April 2026
Sophos. (2026, April 20). Iran COBALT MYSTIQUE. Retrieved April 20, 2026.
Open source URL - [13]mitre-attackG1055Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
