Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has accessed victim’s public facing SharePoint servers and exfiltrated data.(Citation: DOJ FBI Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has collected cached data and files from within the victim environment.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has captured screen content during an active Zoom session.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered audio during a Zoom session.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has staged compressed files in specified locations prior to exfiltration over C2.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered victim email-content from victim servers.(Citation: DOJ FBI Handala Hack March 2026)
Useful?
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
Curated links to related activity — not this actor's alias list. Claimed personas are marked unverified; overlap / subgroup edges describe a related but distinct cluster, never the same actor.
Operates persona (claim)
Handala Hackunverified claimhigh confidencesource ↗Void Manticore (MOIS, G1055) conducts destructive wiper + hack-and-leak operations behind the adversary-asserted "Handala Hack" hacktivist persona; the persona is a front, not a distinct actor.
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has collected video from compromised victim devices.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has stored collected data in a password protected compressed file prior to exfiltration.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized HTTPS for communication to C2 domains.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized Telegram API for C2.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used tunneling tools to facilitate destructive attacks on compromised devices.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted password guessing to gain initial access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted brute-force attempts against organizational VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized credential stuffing attacks to obtain initial access to victim environments.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) had exported credentials from registry hives to include those stored in HKLM.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has disabled Windows Defender protections to allow for follow-on activities within the compromised host.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized ADRecon to enumerate the active directory environment.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered system information and disseminated it back to C2.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](ht
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.(Citation: Check Point VOID MANTICORE Ha
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 202
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized Python scripts to execute its malicious payloads.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted data wiping attacks on compromised systems.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: Palo Alto
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOI
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized a disk wiping utility to facilitate destructive actions on victim servers.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also utilized legitimate remote disk wiping commands.
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deleted virtual machines directly from the virtualization platform.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has emailed victims threatening messages.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used phishing as an initial access vector.(Citation: Domain Tools Handala Hack Karma Homeland Justi
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604.(Citation: DOJ FBI Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used RDP to move laterally within the victim environment.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged public facing VPN infrastructure to gain initial access to victim environments.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS A
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has scanned victim environments for susceptibility to vulnerability exploitation.(Citation: DOJ FBI Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized custom-malware and wipers to include BiBi Wiper.(Citation: DOJ FBI Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’.(Citation: DOJ FBI Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has registered domains for messaging purposes.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created typosquatted domains and sub-domains in attempts to avoid detection
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized VPS solutions for C2.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Telegram Accounts.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on socia
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has obtained access to commercial VPN services to launch malicious activity.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026) [VOID MANTICORE](https://attack.mitre.org/gr
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to manageme
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has masqueraded as commonly used programs and services on Windows hosts.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also co
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has avoided interacting with specific directories in order to reduce the likelihood of detection.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has masqueraded malicious payloads to resemble legitimate applications.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has lever
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has impersonated individuals familiar to the victim and technical support associated with social messaging services.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has compressed their payloads by leveraging zip files.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
ATT&CK Campaigns
1 attributed · MITRE ATT&CK
MITRE ATT&CK campaigns attributed to this actor's group (G1055) — named, time-bounded operations with their own technique sets. Sourced from MITRE ATT&CK.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Void Manticore (Storm-0842)'s activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 29 techniques
Conditional AccessT1110.004significantConditional AccessT1078.004significantAntimalwareT1036significantIdentity Secure ScoreT1110partialIdentity Secure ScoreT1110.001partialPassword PolicyT1078significantPassword PolicyT1110.001significantPassword PolicyT1110.004partialPassword ProtectionT1110.001partialID ProtectionT1098significantID ProtectionT1110partialID ProtectionT1110.001partialIdentity Secure ScoreT1078minimalIdentity Secure ScoreT1078.002minimalIdentity Secure ScoreT1078.004partialRole Based Access ControlT1199partialMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1078.004significantMultifactor AuthenticationT1098minimalPassword ProtectionT1110.004partialPrivileged Identity ManagementT1078minimalPrivileged Identity ManagementT1078.004partialAdvanced Anti-Phishing T1566partialDefender for Cloud AppsT1213.002partialRole Based Access ControlT1087minimalRole Based Access ControlT1098partialRole Based Access ControlT1651partialMail Flow RulesT1114significantAnti-SpoofingT1566significantIdentity Secure ScoreT1552minimalAntimalwareT1204.002significantMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.001partialPrivileged Identity ManagementT1098significantPrivileged Identity ManagementT1651significantConditional AccessT1213minimalConditional AccessT1213.002partialMail Flow RulesT1114.002significantDefender for Cloud AppsT1119partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1213minimalDefender for Cloud AppsT1219significantAntimalwareT1204significantIdentity Secure ScoreT1110.004partialConditional AccessT1078minimalConditional AccessT1074minimalID ProtectionT1110.004partialAntimalwareT1059significantAntimalwareT1059.001significantAntimalwareT1059.006significantAdvanced Anti-Phishing T1566.001partialAntiSpamT1566significantAntiSpamT1566.001significantMultifactor AuthenticationT1110significantAntimalwareT1566significantInformation ProtectionT1119significantAntimalwareT1566.001significantRole Based Access ControlT1059minimalRole Based Access ControlT1078minimalRole Based Access ControlT1213partialRole Based Access ControlT1213.002partialMultifactor AuthenticationT1110.001significantMultifactor AuthenticationT1110.004significantPassword ProtectionT1078partialPassword ProtectionT1110partialConditional AccessT1110significantConditional AccessT1110.001significantAudit SolutionsT1078partialAudit SolutionsT1078.004partialAudit SolutionsT1114partialAudit SolutionsT1213partialAudit SolutionsT1213.002partialAntimalwareT1027significantAnti-PhishingT1566significantAnti-PhishingT1566.001significantRole Based Access ControlT1078.004partialRole Based Access ControlT1484partialAudit SolutionsT1552partialPasswordless AuthenticationT1110significantPasswordless AuthenticationT1110.001significantPasswordless AuthenticationT1110.004significantPassword PolicyT1110partialPasswordless AuthenticationT1078.004significant
Quarantine PoliciesT1566significantQuarantine PoliciesT1566.001significantIncident ResponseT1078minimalIncident ResponseT1110minimalIncident ResponseT1110.001minimalZero Hour Auto PurgeT1036significantAutomated Investigation and ResponseT1114significantID ProtectionT1078.004significantID ProtectionT1110minimalZero Hour Auto PurgeT1204significantAdvanced Anti-Phishing T1566.001partialZero Hour Auto PurgeT1204.002significantIncident ResponseT1564minimalIncident Response
Countermeasures · D3FEND
Defensive techniques that counter Void Manticore (Storm-0842)'s TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.