THREATOPS Actor Dossier
LIVE ← Dashboard

VOID MANTICORE

G10556 reports
aliases · VOID MANTICORE · COBALT MYSTIQUE · Handala Hack · Homeland Justice · Karma · Karmabelow80 · BANISHED KITTEN · Red Sandstorm
Export dossier:
6
Reports
11
Techniques
9
Tactics
9
Countries
64%
Hunt coverage
8
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1491 (Defacement), T1589.001 (Credentials), T1204.002 (Malicious File).
  • Primary targeting: IR, US, IL, UA.
  • Activity accelerating: 3 report(s) in last 30d vs 1 prior (+200%).
  • Hunt coverage 64% of 11 observed techniques (4 gap(s)).
  • Assessment confidence: medium (61).

Activity & trend

AcceleratingLast 30d: 3 vs 1 prior (+200%)· first reported 2026-06-02 · last 2026-09-17
2
7d
3
30d
5
90d
6
All
0.4
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

Targeting gained
DERUUA
Targeting lost
ESILIN

Overview

Analyst triage
Intelligence summary

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including (LinkByld: C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026) VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected