◇ SIGN IN
← all actors
apt

Void Manticore (Storm-0842)

activehigh confidence
APT / State-sponsored
Storm-0842Handala HackHomeland JusticeKarmaKarma BelowBANISHED KITTENCOBALT MYSTIQUERed Sandstorm
Attribution
Iran — Ministry of Intelligence and Security (MOIS)
Origin
Iran
First seen
2022
Last active
2026
Motivation
Sabotage
Confidence
high
MENA targeting
Israel
Sectors
Government, critical infrastructure (destructive ops)
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Israel (Government, critical infrastructure (destructive ops) sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Void Manticore (Storm-0842) is an MOIS-affiliated Iranian actor that conducts destructive wiper attacks paired with hack-and-leak influence operations, running public personas including Homeland Justice, Karma, and — currently — Handala Hack against Israeli and U.S. targets.

History

Void Manticore, tracked by Microsoft as Storm-0842, has operated on behalf of Iran's MOIS since at least mid-2022. Rather than quiet espionage, its mission is disruption and psychological effect: it combines data-wiping with hack-and-leak campaigns amplified through fabricated hacktivist personas, blurring the line between state operation and 'hacktivism.'

The group's tradecraft includes custom and off-the-shelf wipers, manual on-keyboard destruction, and abuse of legitimate management tooling to maximize impact. Check Point documented significant victimology overlap with Scarred Manticore, with a deliberate handoff in which Scarred Manticore establishes access and Void Manticore executes the destructive phase.

MENA targeting centers on Israel, where the Karma / Karma Below and Handala Hack personas have claimed wiper attacks and leaks against Israeli organizations; the group also ran the Homeland Justice persona against Albanian government infrastructure and has extended operations to U.S. entities.

Void Manticore is highly active into 2026. Under the Handala Hack persona it claimed a destructive March 11, 2026 attack on medical-technology firm Stryker Corporation — weaponizing compromised administrator accounts and the Microsoft Intune MDM platform to issue mass remote-wipe commands, alongside large-scale data-leak claims. The attack, assessed as retaliatory following U.S.–Israeli strikes on Iran that began February 28, 2026, illustrates the group's continued fusion of destructive impact and information operations.

Notable campaigns

2022
Homeland Justice (Albania)
Wiper and hack-and-leak operations against Albanian government systems under a fabricated hacktivist persona.
2024
Karma / Karma Below (Israel)
Destructive wiper attacks and leaks against Israeli organizations, with access handed off from Scarred Manticore.
2026
Handala Hack — Stryker attack
Intune-abusing mass remote-wipe against medtech firm Stryker with 12PB data-leak claims, assessed as retaliatory.