Void Manticore — APT Profile
Void Manticore is an Iranian MOIS-linked APT conducting destructive wiper attacks against Israeli organizations. Leaks data via Karma persona. Extended operations to Albania as Homeland Justice. Uses custom wipers and web shells. Coordinates with Scarred Manticore for initial access.Also tracked as
Karma, Homeland Justice, Tremor Pulse, DEV-0842, Storm-0842, G1055
Tools & malware
- BiBi Wiper Wiper
- CHIMNEYSWEEP backdoor
- Cl Wiper Wiper
- Cl Wiper (cl.exe) wiper
- Custom Web Shells Webshell
- Karma Shell web-shell
- Mimikatz credential-theft
- No-Justice (NACL.exe / LowEraser) wiper
- No-Justice Wiper Wiper
- Plink tunneling-utility
- RawDisk driver
- RevSocks tunneling-utility
- ROADSWEEP (GoXml.exe) ransomware
- ZeroCleare wiper
Vendor research
- Pro-Iranian Hacker Group Targeting Albania with No-Justice Wiper Malware The Hacker News
- Void Manticore (G1055) MITRE ATT&CK
- Wiper malware found in analysis of Iran-linked attacks on Albanian institutions The Record (Recorded Future News)
- Iranian State Actors Conduct Cyber Operations Against the Government of Albania (Alert AA22-264A) CISA / FBI
- Microsoft investigates Iranian attacks against the Albanian government Microsoft
- Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization Justin Moore
- “Handala Hack” – Unveiling Group’s Modus Operandi Check Point Research
- Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to DOJ/FBI
- Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment DomainTools Investigations
- Iran COBALT MYSTIQUE Sophos
- Bad Karma, No Justice: Void Manticore Destructive Activities Check Point
- Iranian Threat Group Conducts Destructive Attacks Against Israeli Organizations Unit 42
- Storm-842 (Void Manticore) Threat Profile Microsoft