handala
Group profile
Not a Ransomware Group
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.002Valid Accounts: Domain Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.004Valid Accounts: Cloud Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)
T1133External Remote Services
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged public facing VPN infrastructure to gain initial access to victim environments.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1190Exploit Public-Facing Application
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604.(Citation: DOJ FBI Handala Hack March 2026)
T1199Trusted Relationship
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1566Phishing
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has emailed victims threatening messages.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used phishing as an initial access vector.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
Execution
T1047Windows Management Instrumentation
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1059.001Command and Scripting Interpreter: PowerShell
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized PowerShell to execute malware in victim environments.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1059.006Command and Scripting Interpreter: Python
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized Python scripts to execute its malicious payloads.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1072Software Deployment Tools
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026)
T1204.002User Execution: Malicious File
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1651Cloud Administration Command
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026)
Persistence
T1078Valid Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.002Valid Accounts: Domain Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.004Valid Accounts: Cloud Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)
T1098Account Manipulation
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)(Citation: SEC 8K Palo Alto Statement Stryker Corp Handala March 2026)
T1133External Remote Services
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged public facing VPN infrastructure to gain initial access to victim environments.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
Privilege Escalation
T1078Valid Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.002Valid Accounts: Domain Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.004Valid Accounts: Cloud Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)
T1098Account Manipulation
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)(Citation: SEC 8K Palo Alto Statement Stryker Corp Handala March 2026)
T1484.001Domain or Tenant Policy Modification: Group Policy Modification
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
Stealth
T1027.015Obfuscated Files or Information: Compression
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has compressed their payloads by leveraging zip files.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1036.004Masquerading: Masquerade Task or Service
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has masqueraded as commonly used programs and services on Windows hosts.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1036.005Masquerading: Match Legitimate Resource Name or Location
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has masqueraded malicious payloads to resemble legitimate applications.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1078Valid Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.002Valid Accounts: Domain Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1078.004Valid Accounts: Cloud Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)
T1564.003Hide Artifacts: Hidden Window
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1679Selective Exclusion
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has avoided interacting with specific directories in order to reduce the likelihood of detection.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1684.001Social Engineering: Impersonation
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has impersonated individuals familiar to the victim and technical support associated with social messaging services.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
Credential Access
T1003.001OS Credential Dumping: LSASS Memory
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1110Brute Force
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted brute-force attempts against organizational VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1110.001Brute Force: Password Guessing
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted password guessing to gain initial access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1110.004Brute Force: Credential Stuffing
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized credential stuffing attacks to obtain initial access to victim environments.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1552.002Unsecured Credentials: Credentials in Registry
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) had exported credentials from registry hives to include those stored in HKLM.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
Discovery
T1082System Information Discovery
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered system information and disseminated it back to C2.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1087.002Account Discovery: Domain Account
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized ADRecon to enumerate the active directory environment.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
Lateral Movement
T1021.001Remote Services: Remote Desktop Protocol
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used RDP to move laterally within the victim environment.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1072Software Deployment Tools
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026)
Collection
T1005Data from Local System
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has collected cached data and files from within the victim environment.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1074Data Staged
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has staged compressed files in specified locations prior to exfiltration over C2.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1113Screen Capture
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has captured screen content during an active Zoom session.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1114.002Email Collection: Remote Email Collection
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered victim email-content from victim servers.(Citation: DOJ FBI Handala Hack March 2026)
T1119Automated Collection
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1123Audio Capture
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered audio during a Zoom session.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1125Video Capture
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has collected video from compromised victim devices.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1213.002Data from Information Repositories: Sharepoint
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has accessed victim’s public facing SharePoint servers and exfiltrated data.(Citation: DOJ FBI Handala Hack March 2026)
T1560.001Archive Collected Data: Archive via Utility
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has stored collected data in a password protected compressed file prior to exfiltration.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
Exfiltration
T1041Exfiltration Over C2 Channel
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
Command and Control
T1071.001Application Layer Protocol: Web Protocols
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized HTTPS for communication to C2 domains.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1102Web Service
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized Telegram API for C2.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1105Ingress Tool Transfer
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deployed additional payloads from dedicated C2 servers.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also downloaded legitimate tools and software from publicly available services.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1219.002Remote Access Tools: Remote Desktop Software
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1572Protocol Tunneling
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used tunneling tools to facilitate destructive attacks on compromised devices.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
Impact
T1485Data Destruction
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted data wiping attacks on compromised systems.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)
T1486Data Encrypted for Impact
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)
T1490Inhibit System Recovery
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deleted virtual machines directly from the virtualization platform.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1561.001Disk Wipe: Disk Content Wipe
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized a disk wiping utility to facilitate destructive actions on victim servers.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also utilized legitimate remote disk wiping commands.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)
T1561.002Disk Wipe: Disk Structure Wipe
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1657Financial Theft
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also sold stolen data to prospective buyers for cryptocurrency.(Citation: DOJ FBI Handala Hack March 2026)
Resource Development
T1583.001Acquire Infrastructure: Domains
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has registered domains for messaging purposes.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1583.003Acquire Infrastructure: Virtual Private Server
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized VPS solutions for C2.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1583.004Acquire Infrastructure: Server
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged backend servers within Iran.(Citation: DOJ FBI Handala Hack March 2026)
T1583.006Acquire Infrastructure: Web Services
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has obtained access to commercial VPN services to launch malicious activity.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also leveraged Starlink internet services.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used operator-controlled Telegram bots and channels as C2 infrastructure.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1585.001Establish Accounts: Social Media Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Telegram Accounts.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1585.002Establish Accounts: Email Accounts
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’.(Citation: DOJ FBI Handala Hack March 2026)
T1587.001Develop Capabilities: Malware
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized custom-malware and wipers to include BiBi Wiper.(Citation: DOJ FBI Handala Hack March 2026)
T1588.001Obtain Capabilities: Malware
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)
T1588.002Obtain Capabilities: Tool
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
Reconnaissance
T1589Gather Victim Identity Information
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)
T1595.002Active Scanning: Vulnerability Scanning
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has scanned victim environments for susceptibility to vulnerability exploitation.(Citation: DOJ FBI Handala Hack March 2026)
Defense Impairment
T1484.001Domain or Tenant Policy Modification: Group Policy Modification
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
T1686.003Disable or Modify System Firewall: Windows Host Firewall
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has disabled Windows Defender protections to allow for follow-on activities within the compromised host.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)
Recent victims
showing 50 of 175| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2026-04-01 | S St. Joseph County | Government & Defense | US |
| 2026-04-02 | P PSK WIND’s Defense Networks Fall to Handala Hack | Energy & Utilities | |
| 2026-04-02 | P Passover Wiped Clean: 22TB of Data Gone from 14 Companies | Not Found | |
| 2026-04-03 | P Publication of Photos and Personal Details of IranWire’s Traitorous Members | Other | |
| 2026-04-04 | 5 50 Senior Unit 9900 Officers Exposed | Government & Defense | |
| 2026-04-05 | H Handala Hack Strikes 27 Companies for Minab’s Innocents | Not Found | |
| 2026-04-06 | R Raz Zimmt’s Chats Leaked to the World | Not Found | |
| 2026-04-07 | E Exposing Israel’s Drone Queen: The Fall of Colonel Haimovich | Not Found | |
| 2026-03-31 | I IranWire | Technology | IR |
| 2026-03-28 | N North Country Business Products Breached: 2,680 POS Terminals Disabled Nationwide | Technology | US |
| 2026-03-28 | 4 4 Terabytes Wiped—Good Food Store Shut Down After Major Cyberattack | Retail & E-Commerce | US |
| 2026-03-29 | L Listen Closely, Gallant: Handala’s Eyes and Ears Are Everywhere | Not Found | |
| 2026-03-27 | K Kash Patel current director of the FBI | Government & Defense | |
| 2026-03-26 | L Lockheed Martin Employees Given 48 Hours to Respond: A Tight Deadline Looms | Manufacturing | US |
| 2026-03-20 | P Propaganda Chief and Former Mossad Deputy Exposed by Handala Hack | Not Found | |
| 2026-03-20 | O Official Statement by Handala Group in Response to Threats from the US and Its Allies | Not Found | |
| 2026-03-21 | A Architect of Warfare Exposed: Eran Ortal’s Hidden Strategies Now Public | Not Found | |
| 2026-03-22 | T The Slightest Aggression: Enemy Infrastructure Reduced to Ashes | Not Found | |
| 2026-03-23 | B Behind the Curtain: Full Details of Shin Bet’s Iran Desk Officers Released | Government & Defense | IL |
| 2026-03-24 | $ $50M Reward For Trump & Netanyahu | Not Found | |
| 2026-03-25 | F From Hunter to Hunted: Mossad’s Former Chief Falls into the Trap | Not Found | IL |
| 2026-03-18 | M Martyr Ali Larijani | Other | |
| 2026-03-17 | V Vahid Offline Members | Not Found | |
| 2026-03-17 | W Who is VahidOnline? | Technology | IR |
| 2026-03-17 | M Mossad’s Secret Treasury Exposed: 50,000 Confidential Emails Leaked | Government & Defense | IL |
| 2026-03-16 | S Stryker Hit by Unprecedented 12-Petabyte Data Wipe | Technology | US |
| 2026-03-16 | S Shock for Israeli Intelligence: 100,000 Classified Emails of Mossad’s Ex-Deputy Director S... | Government & Defense | IL |
| 2026-03-15 | L Laura Gilinski | Not Found | |
| 2026-03-14 | N No Place to Hide: Senior Navy Officers’ Identities Now Public | Government & Defense | |
| 2026-03-13 | T Tamir Hayman | Not Found | IL |
| 2026-03-13 | H Hebrew University of Jerusalem | Education | IL |
| 2026-03-12 | R Raz Zimmt (head of the Iran Desk at Israeli security institutes) | Government & Defense | IL |
| 2026-03-11 | Stryker Corporationstryker.com | Healthcare | US |
| 2026-03-11 | V Verifone | Technology | US |
| 2026-03-09 | F Full Access: Jerusalem’s Security Cameras in Handala’s Hands | Government & Defense | |
| 2026-03-09 | U Unprecedented Disclosure of 50 Senior Israeli Air Force Officers’ Information | Government & Defense | IL |
| 2026-03-08 | C Contact Handala | Not Found | PS |
| 2026-03-08 | I Israeli Weather Stations Crippled | Government & Defense | IL |
| 2026-03-07 | J Jerusalem Water Supply Facilities | Government & Defense | IL |
| 2026-03-07 | H Handala New Telegram | Not Found | |
| 2026-03-06 | I IDF in Farsi | Government & Defense | IR |
| 2026-03-06 | S Sanzer Hasidic community | Other | |
| 2026-03-05 | A Atlas Insurances Ltd | Financial Services | IL |
| 2026-03-04 | I Israel Institute for National Security Studies (INSS) | Government & Defense | IL |
| 2026-03-03 | A Aramco | Energy & Utilities | SA |
| 2026-03-03 | S Sharjah National Oil Corporation | Energy & Utilities | AE |
| 2026-03-02 | I Israel Opportunity Energy | Energy & Utilities | IL |
| 2026-02-25 | C Clalit: Israel’s Largest Healthcare Organization Falls to Cyber Resistance | Healthcare | IL |
| 2026-02-19 | T The General in the Shadows: Sapir’s Commander Exposed | Not Found | |
| 2026-01-25 | H Handala New Account – Sunset of the lions | Not Found |

