← All actors Recent activity

VOID MANTICORE G1055

BANISHEDKITTEN · aa22-264a · banished kitten · homeland justice · karma · red sandstorm · storm-0842 · void manticore

Indicators
1
Source reports
15
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02

Overview 1 indicators

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including (LinkByld: C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.

domain1G1055-domain.txt

Techniques 63 ATT&CK

Open in ATT&CK Navigator → or download the layer (63 techniques, layer 4.5)

Principal sources 15 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 1 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. or earlier 1 domainthis year

    x.com/ClearskySec/status/1960296933295104369 · apt.etda.or.th/cgi-bin/showcard.cgi?g=HomeLand%20Justi… · picussecurity.com/resource/blog/cisa-alert-aa22-264a-iran… · dreamgroup.com/blog-cti · dreamgroup.com/wp-content/uploads/2025/08/Dream_CTI_An… · virustotal.com/gui/file/02ccc4271362b92a59e6851ac6d5d2… · virustotal.com/gui/file/1883db6de22d98ed00f8719b11de5b… · virustotal.com/gui/file/1c16b271c0c4e277eb3d1a7795d474… · virustotal.com/gui/file/2c92c7bf2d6574f9240032ec6adee7… · virustotal.com/gui/file/3ac8283916547c50501eed8e7c3a77… · virustotal.com/gui/file/3d6f69cc0330b302ddf4701bbc956b… · virustotal.com/gui/file/76fa8dca768b64aefedd85f7d0a33c… · virustotal.com/gui/file/80e9105233f9d93df753a43291c2ab… · virustotal.com/gui/file/b2c52fde1301a3624a9ceb995f2de4… · virustotal.com/gui/file/f0ba41ce46e566f83db1ba3fc762fd…

    screenai.online

Further reading 21