VOID MANTICORE

APT / EstatalG1055 ↗
Origen🇮🇷 Irã
Técnicas (MITRE ATT&CK)63
FuenteMITRE ATT&CK
0
También conocido como:BANISHED KITTENCOBALT MYSTIQUEHandala HackHomeland JusticeKarmaKarmabelow80Red Sandstorm

Sobre el grupo

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.

Cadena de ataque

Escenario plausible montado a partir de las técnicas reales del grupo, ordenadas por las fases de un ataque. Cada etapa muestra cómo suele actuar el grupo.

Severidad del arsenal83
Impacto: Alto
T1190T1047T1098T1003.001T1005T1041ENTRYAcceso inicialExploitPublic-Facing App…EXECEjecuciónWindows ManagementInstrumentationPERSPersistenciaAccountManipulationCREDAcceso a credencialesLSASS MemoryCOLLRecolecciónData from LocalSystemEXFILExfiltraciónExfiltration OverC2 ChannelIMPACTImpactoData Destruction

Cadena ilustrativa derivada de las técnicas documentadas en MITRE ATT&CK — no representa un ataque específico ya ocurrido. La severidad resume el arsenal conocido (cobertura de la cadena, CVEs en explotación activa, técnicas).

Vulnerabilidades explotadas 3

CVEs que este grupo es conocido por explotar, según MITRE ATT&CK. Ordenadas por gravedad real.

El grupo VOID MANTICORE usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →