VOID MANTICORE
Also tracked as COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, BANISHED KITTEN, Red Sandstorm
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.
- Known attack methods
- 63
- Motive
- Sabotage
- First seen
- 2021
- Last seen
- 2022-09
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 2 used
Resource Development
9 techniques · 4 used
Initial Access
11 techniques · 3 used
Execution
20 techniques · 5 used
Persistence
22 techniques · 3 used
Privilege Escalation
13 techniques
Stealth
30 techniques · 6 used
Defense Impairment
18 techniques · 2 used
Credential Access
17 techniques · 3 used
Discovery
34 techniques · 2 used
Lateral Movement
9 techniques · 1 used
Collection
17 techniques · 9 used
Command and Control
18 techniques · 5 used
Exfiltration
9 techniques · 1 used
Impact
15 techniques · 5 used