Overview 1 indicators
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including (LinkByld: C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.
| domain | 1 | G1055-domain.txt |
Techniques 63 ATT&CK
Open in ATT&CK Navigator → or download the layer (63 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1005 Data from Local System
- T1021.001 Remote Desktop Protocol
- T1027.015 Compression
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1047 Windows Management Instrumentation
- T1059.001 PowerShell
- T1059.006 Python
- T1071.001 Web Protocols
- T1072 Software Deployment Tools
- T1074 Data Staged
- T1078 Valid Accounts
- T1078.002 Domain Accounts
- T1078.004 Cloud Accounts
- T1082 System Information Discovery
- T1087.002 Domain Account
- T1098 Account Manipulation
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1110 Brute Force
- T1110.001 Password Guessing
- T1110.004 Credential Stuffing
- T1113 Screen Capture
- T1114.002 Remote Email Collection
- T1119 Automated Collection
- T1123 Audio Capture
- T1125 Video Capture
- T1133 External Remote Services
- T1190 Exploit Public-Facing Application
- T1199 Trusted Relationship
- T1204.002 Malicious File
- T1213.002 Sharepoint
- T1219.002 Remote Desktop Software
- T1484.001 Group Policy Modification
- T1485 Data Destruction
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1547.001 Registry Run Keys / Startup Folder
- T1552.002 Credentials in Registry
- T1560.001 Archive via Utility
- T1561.001 Disk Content Wipe
- T1561.002 Disk Structure Wipe
- T1564.003 Hidden Window
- T1566 Phishing
- T1572 Protocol Tunneling
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1583.004 Server
- T1583.006 Web Services
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1587.001 Malware
- T1588.001 Malware
- T1588.002 Tool
- T1589 Gather Victim Identity Information
- T1595.002 Vulnerability Scanning
- T1651 Cloud Administration Command
- T1657 Financial Theft
- T1679 Selective Exclusion
- T1684.001 Impersonation
- T1686.003 Windows Host Firewall
Principal sources 15 reports
Ranked by how many of this actor's indicators each report brought in.
- 1x.com/ClearskySec/status/1960296933295104369
- 1apt.etda.or.th/cgi-bin/showcard.cgi?g=HomeLand%20Justi…
- 1picussecurity.com/resource/blog/cisa-alert-aa22-264a-iran…
- 1dreamgroup.com/blog-cti
- 1dreamgroup.com/wp-content/uploads/2025/08/Dream_CTI_An…
- 1virustotal.com/gui/file/02ccc4271362b92a59e6851ac6d5d2…
- 1virustotal.com/gui/file/1883db6de22d98ed00f8719b11de5b…
- 1virustotal.com/gui/file/1c16b271c0c4e277eb3d1a7795d474…
Timeline 1 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/ClearskySec/status/1960296933295104369 · apt.etda.or.th/cgi-bin/showcard.cgi?g=HomeLand%20Justi… · picussecurity.com/resource/blog/cisa-alert-aa22-264a-iran… · dreamgroup.com/blog-cti · dreamgroup.com/wp-content/uploads/2025/08/Dream_CTI_An… · virustotal.com/gui/file/02ccc4271362b92a59e6851ac6d5d2… · virustotal.com/gui/file/1883db6de22d98ed00f8719b11de5b… · virustotal.com/gui/file/1c16b271c0c4e277eb3d1a7795d474… · virustotal.com/gui/file/2c92c7bf2d6574f9240032ec6adee7… · virustotal.com/gui/file/3ac8283916547c50501eed8e7c3a77… · virustotal.com/gui/file/3d6f69cc0330b302ddf4701bbc956b… · virustotal.com/gui/file/76fa8dca768b64aefedd85f7d0a33c… · virustotal.com/gui/file/80e9105233f9d93df753a43291c2ab… · virustotal.com/gui/file/b2c52fde1301a3624a9ceb995f2de4… · virustotal.com/gui/file/f0ba41ce46e566f83db1ba3fc762fd…
screenai.online
Further reading 21
- attack.mitre.org/groups/G1055
- dti.domaintools.com/research/handala-mois-linked-cyber-infl…
- research.checkpoint.com/2026/handala-hack-unveiling-groups-modu…
- unit42.paloaltonetworks.com/evolution-of-iran-cyber-threats
- justice.gov/opa/media/1431956/dl?inline
- sophos.com/en-us/threat-profiles/cobalt-mystique
- virustotal.com/gui/file/3ac8283916547c50501eed8e7c3a77…
- virustotal.com/gui/file/1c16b271c0c4e277eb3d1a7795d474…
- virustotal.com/gui/file/f0ba41ce46e566f83db1ba3fc762fd…
- apt.etda.or.th/cgi-bin/showcard.cgi?g=HomeLand%20Justi…
- virustotal.com/gui/file/1883db6de22d98ed00f8719b11de5b…
- virustotal.com/gui/file/80e9105233f9d93df753a43291c2ab…
- virustotal.com/gui/file/02ccc4271362b92a59e6851ac6d5d2…
- dreamgroup.com/wp-content/uploads/2025/08/Dream_CTI_An…
- dreamgroup.com/blog-cti
- virustotal.com/gui/file/b2c52fde1301a3624a9ceb995f2de4…
- picussecurity.com/resource/blog/cisa-alert-aa22-264a-iran…
- virustotal.com/gui/file/76fa8dca768b64aefedd85f7d0a33c…
- x.com/ClearskySec/status/1960296933295104369
- virustotal.com/gui/file/2c92c7bf2d6574f9240032ec6adee7…
- virustotal.com/gui/file/3d6f69cc0330b302ddf4701bbc956b…