Void Manticore (Storm-0842) is an MOIS-affiliated Iranian actor that conducts destructive wiper attacks paired with hack-and-leak influence operations, running public personas including Homeland Justice, Karma, and — currently — Handala Hack against Israeli and U.S. targets.
Void Manticore, tracked by Microsoft as Storm-0842, has operated on behalf of Iran's MOIS since at least mid-2022. Rather than quiet espionage, its mission is disruption and psychological effect: it combines data-wiping with hack-and-leak campaigns amplified through fabricated hacktivist personas, blurring the line between state operation and 'hacktivism.'
The group's tradecraft includes custom and off-the-shelf wipers, manual on-keyboard destruction, and abuse of legitimate management tooling to maximize impact. Check Point documented significant victimology overlap with Scarred Manticore, with a deliberate handoff in which Scarred Manticore establishes access and Void Manticore executes the destructive phase.
MENA targeting centers on Israel, where the Karma / Karma Below and Handala Hack personas have claimed wiper attacks and leaks against Israeli organizations; the group also ran the Homeland Justice persona against Albanian government infrastructure and has extended operations to U.S. entities.
Void Manticore is highly active into 2026. Under the Handala Hack persona it claimed a destructive March 11, 2026 attack on medical-technology firm Stryker Corporation — weaponizing compromised administrator accounts and the Microsoft Intune MDM platform to issue mass remote-wipe commands, alongside large-scale data-leak claims. The attack, assessed as retaliatory following U.S.–Israeli strikes on Iran that began February 28, 2026, illustrates the group's continued fusion of destructive impact and information operations.