VOID MANTICORE

APT / StateG1055 ↗
Origin🇮🇷 Irã
Techniques (MITRE ATT&CK)63
SourceMITRE ATT&CK
0
Also known as:BANISHED KITTENCOBALT MYSTIQUEHandala HackHomeland JusticeKarmaKarmabelow80Red Sandstorm

About the group

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity83
Impact: High
T1190T1047T1098T1003.001T1005T1041ENTRYInitial accessExploitPublic-Facing App…EXECExecutionWindows ManagementInstrumentationPERSPersistenceAccountManipulationCREDCredential accessLSASS MemoryCOLLCollectionData from LocalSystemEXFILExfiltrationExfiltration OverC2 ChannelIMPACTImpactData Destruction

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 3

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

VOID MANTICORE uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →