>samit_hota
Back to adversary profiles

Threat Actor Dossier

VOID MANTICORE (G1055): Iran's Destructive Cyber Arm

G1055

Also tracked as COBALT MYSTIQUE · Handala Hack · Homeland Justice · Karma · Karmabelow80 · BANISHED KITTEN · Red Sandstorm · 15 sectors targeted

Threat level
CRITICAL
Status
ACTIVE
Origin
Iran
Motivation
Political · Ideological
Samit Hota·
Target Sectors
Government, Critical Infrastructure, Private Sector, Telecommunications, Energy, Finance, Healthcare, IT, Defense, NGOs, Media, Education, Transportation, Airlines, Maritime
Associated Malware
BiBi Wiper, Cl Wiper, No-Justice, Hatef Wiper, Radthief, NetBird, Karma Shell, Advanced Port Scanner, Mimikatz, Impacket, VeraCrypt, CaddyWiper, ZeroCleare
#threat-actor#g1055

Overview

VOID MANTICORE (G1055), also tracked under aliases like COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, and Red Sandstorm, is a significant Iranian threat group. This actor is assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS), reflecting state-sponsored objectives rather than purely criminal motivations. Active since at least mid-2022, VOID MANTICORE specializes in destructive cyber operations, frequently combining wiper attacks with hack-and-leak campaigns to achieve its geopolitical goals.

The group’s motivation is primarily political and ideological, deeply rooted in supporting Palestinian resistance and retaliating against entities perceived as adversaries to Iran or supporters of Israel. This includes raising awareness for the Palestinian cause, punishing Israeli and Western institutions, and engaging in psychological warfare to influence public opinion. VOID MANTICORE’s operations aim to inflict both technical damage and reputational harm, leveraging public announcements and social media to amplify the psychological impact of their attacks.

VOID MANTICORE often targets government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States, with a recent expansion to other regional adversaries and NATO-aligned nations. The group has notably collaborated with Scarred Manticore (also known as Storm-861 or OilRig), with indications of a “handoff” model where Scarred Manticore may establish initial access for espionage purposes, followed by VOID MANTICORE conducting destructive activities. This collaboration highlights a coordinated approach within Iranian cyber operations.

Tactics & Techniques

VOID MANTICORE employs a range of straightforward yet effective tactics, techniques, and procedures (TTPs), often relying on hands-on operations using publicly available tools and “living-off-the-land” techniques.

Initial access frequently involves exploiting public-facing vulnerabilities in web servers, VPN gateways, and unpatched applications, such as CVE-2019-0604 in Microsoft SharePoint. The group also leverages phishing campaigns, sometimes delivering malicious attachments disguised as legitimate fixes, to harvest credentials. Supply chain attacks targeting IT and service providers have been observed to obtain credentials, often through compromised VPN accounts, with brute-force attempts from commercial VPN nodes.

Once inside, VOID MANTICORE establishes persistence using .aspx webshells (e.g., pickers.aspx, error4.aspx, ClientBin.aspx), Windows batch files, and previously compromised Domain Administrator credentials. They perform extensive host and network reconnaissance, using tools like Advanced Port Scanner and leveraging PowerShell cmdlets (New-MailboxSearch, Get-Recipient) for discovery.

Lateral movement is typically achieved using Remote Desktop Protocol (RDP) and Server Message Block (SMB). The group also deploys NetBird, an open-source tool, to create a mesh network for tunneling traffic and facilitating control of compromised devices, especially to reach internal hosts that are not directly accessible.

Defense evasion is a key pre-impact step. VOID MANTICORE disables Windows Defender and other endpoint detection and response (EDR) solutions, deletes Windows events and application logs, and uses tools with legitimate code signing certificates to blend in. They masquerade malicious payloads and tools to resemble legitimate applications like Pictory, KeePass, WhatsApp, and Telegram, or rename their wipers to appear innocuous (e.g., GoXML.exe, cl.exe).

Command and control (C2) is often established via HTTP/S channels routed through compromised servers, leveraging VPN and proxy infrastructure in Eastern Europe and the Middle East, and utilizing cloud hosting providers to mask infrastructure changes. The Handala persona has also used Telegram channels for C2 and to claim responsibility for attacks.

For impact, VOID MANTICORE primarily focuses on destructive data wiping and hack-and-leak operations. They use various methods for data destruction, including custom wipers, legitimate remote disk wiping commands, abuse of built-in remote wipe or factory reset commands (e.g., via Microsoft Intune), and manual deletion of files, shared drives, and virtual machines. Data exfiltration precedes leaks, with stolen information posted on data leak sites for financial and political extortion. They have also engaged in Distributed Denial of Service (DDoS) attacks and ransomware-style pressure tactics.

Notable Campaigns

VOID MANTICORE has conducted several high-profile campaigns under its various aliases, often timing them with geopolitical events.

Homeland Justice (Albania, 2022): This persona was used for disruptive cyber campaigns against Albanian government networks in July and September 2022. These operations combined ransomware, wiper malware, and data leak operations. Initial access was gained as early as May 2021, allowing threat actors to maintain persistence and exfiltrate sensitive information for approximately 14 months before launching destructive attacks. The campaign was framed as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania, leading to the cancellation of a planned conference. A second wave of attacks followed in September 2022 after public attribution to Iran and the severing of diplomatic ties. Targets included Albanian e-government systems and the Total Information Management System (TIMS) of the state police, disrupting public services and border controls.

Karma / Karma Below (Israel, active since at least October 2023): This persona targets Israeli organizations with destructive attacks using wipers and ransomware. These campaigns align with state-sponsored threats following the start of the Israel-Hamas war.

Handala Hack (Israel, U.S., and regional, late 2023 - present): This is the group’s current primary persona, named after a Palestinian cartoon character symbolizing resistance. Handala Hack emerged in late 2023, escalating activity after the October 7, 2023, Hamas attacks. Operations under this persona have targeted Israeli, U.S., and regional infrastructure, often with a pro-Palestinian agenda.

  • March 2024: Claimed to hack and deface DRS RADA, an Israeli tactical radar company.
  • June 2024: Claimed a ransomware attack on Ma’agan Michael Kibbutz in Israel, exfiltrating 22GB of data and sending warning SMS messages.
  • July 2024: Distributed a destructive wiper payload disguised as a recovery fix for a global CrowdStrike IT outage.
  • February 2026: Claimed compromises of an Israeli energy exploration company, Israeli civilian healthcare systems, and Jordan’s fuel systems.
  • March 2026: Launched a “RedWanted” website listing individuals and organizations supporting Israel. The most prominent incident was a major wiper attack against Stryker Corporation, a U.S. medical device manufacturer. This attack, reportedly in retaliation for an alleged school bombing in Iran, disrupted Stryker’s global networks, manufacturing, and shipping, wiping thousands of employee devices, possibly by abusing Microsoft Intune. Handala also claimed to have breached the personal email of FBI Director Kash Patel and published over 300 emails in March 2026.
  • July 2024: Claimed a cyber-attack against Zerto, a subsidiary of Hewlett Packard Enterprise, allegedly exfiltrating and deleting 51 terabytes of data.

Associated Malware & Tools

VOID MANTICORE leverages a mix of custom malware, commodity tools, and legitimate software for its operations.

Their custom arsenal includes several destructive wipers:

  • BiBi Wiper: Used in attacks targeting Israeli organizations under the Karma persona, named after Israeli Prime Minister Benjamin Netanyahu.
  • Cl Wiper / No-Justice: Bespoke wipers observed in operations. The cl.exe variant was seen during the Homeland Justice campaign.
  • Hatef wiper: Associated with the Handala persona.
  • AI-assisted PowerShell wiper: Used to delete user directories and drop a handala.gif file, part of multi-stage wiping efforts.
  • MBR-based wipers: Such as handala.exe, distributed via Group Policy logon scripts and scheduled tasks.
  • ZeroCleare variants: A destructive malware deployed during the Homeland Justice campaign against Albania.
  • CaddyWiper variants and Atena: Other wiper-style malware disguised as ransomware.

For information gathering and data theft, they have used:

  • Rhadamanthys (Radthief) stealer: A commercial infostealer sold on darknet forums, leveraged by the Handala persona.

The group extensively uses publicly available offensive security tools and legitimate utilities:

  • NetBird: An open-source tool for creating zero-trust mesh networks and tunneling traffic.
  • Karma Shell: A custom webshell, often masquerading as an error page, capable of listing directories, creating processes, uploading files, and managing services.
  • Advanced Port Scanner, Mimikatz, Impacket, Metasploit, SharpHound: Used for reconnaissance, credential dumping, and lateral movement.
  • PowerShell and Python scripts: Utilized for executing malicious payloads, discovery, and automated actions.
  • VeraCrypt: Used for disk encryption as a destructive method.
  • Microsoft Intune: Abused to issue remote wipe commands to managed devices, as seen in the Stryker attack.
  • comsvcs.dll via rundll32.exe: For dumping LSASS credentials.
  • Commercial VPN services and open-source software: For obfuscating their activities and initial access.

Current Status

VOID MANTICORE remains an active and evolving threat actor, consistently pursuing ideologically and politically motivated cyber operations. Recent activity in March 2026, including the attack on Stryker Corporation and the claimed breach of FBI Director Kash Patel’s personal email, confirms their ongoing operations and willingness to target high-profile U.S. entities.

The group continues to refine its capabilities, with observed advancements in operational security, including the use of proxy infrastructure and transient command and control utilities. While the core TTPs, combining destructive wiping with hack-and-leak campaigns, remain consistent, they have shown adaptability by incorporating propaganda techniques and coordinating information operations with technical attacks to maximize impact.

VOID MANTICORE’s reliance on a “handoff” model with more sophisticated actors like Scarred Manticore ensures continued access to high-value targets. Their engagement with the cybercrime ecosystem, leveraging commercial tools like the Rhadamanthys infostealer, allows them to enhance operational capabilities and complicate attribution. The group’s expansion of targeting beyond traditional regional adversaries to include Western organizations with ties to Israel underscores a growing and persistent threat to a broader range of sectors and geographies. Organizations should anticipate continued destructive campaigns, data exfiltration, and influence operations from VOID MANTICORE.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call