VOID MANTICORE
G10556 reportsAnalyst assessment — key judgments
- Signature techniques: T1491 (Defacement), T1589.001 (Credentials), T1204.002 (Malicious File).
- Primary targeting: IR, US, IL, UA.
- Activity accelerating: 3 report(s) in last 30d vs 1 prior (+200%).
- Hunt coverage 64% of 11 observed techniques (4 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
Movement — last 30 days
Overview
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including (LinkByld: C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026) VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
ATT&CK technique matrix
- T1491 · Defacementconf 703
- T1589.001 · Credentialsconf 652
- T1204.002 · Malicious Fileconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1574.014 · AppDomainManagerconf 601
- T1684 · Social Engineeringconf 601
- T1087.004 · Cloud Accountconf 601
- T1136.003 · Cloud Accountconf 601
- T1684.001 · Impersonationconf 601
- AML.T0073 · Impersonationconf 601
- T1590.005 · IP Addressesconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|