HackerFeeds
All ransomware groups

handala

175 tracked victims
·first seen 2024-04-05·last activity 2026-04-07

Group profile

Not a Ransomware Group

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.002Valid Accounts: Domain Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.004Valid Accounts: Cloud Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)

  • T1133External Remote Services

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged public facing VPN infrastructure to gain initial access to victim environments.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1190Exploit Public-Facing Application

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604.(Citation: DOJ FBI Handala Hack March 2026)

  • T1199Trusted Relationship

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1566Phishing

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has emailed victims threatening messages.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used phishing as an initial access vector.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

TA0002

Execution

  • T1047Windows Management Instrumentation

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1059.001Command and Scripting Interpreter: PowerShell

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized PowerShell to execute malware in victim environments.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1059.006Command and Scripting Interpreter: Python

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized Python scripts to execute its malicious payloads.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1072Software Deployment Tools

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026)

  • T1204.002User Execution: Malicious File

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1651Cloud Administration Command

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026)

TA0003

Persistence

  • T1078Valid Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.002Valid Accounts: Domain Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.004Valid Accounts: Cloud Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)

  • T1098Account Manipulation

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)(Citation: SEC 8K Palo Alto Statement Stryker Corp Handala March 2026)

  • T1133External Remote Services

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged public facing VPN infrastructure to gain initial access to victim environments.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

TA0004

Privilege Escalation

  • T1078Valid Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.002Valid Accounts: Domain Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.004Valid Accounts: Cloud Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)

  • T1098Account Manipulation

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)(Citation: SEC 8K Palo Alto Statement Stryker Corp Handala March 2026)

  • T1484.001Domain or Tenant Policy Modification: Group Policy Modification

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

TA0005

Stealth

  • T1027.015Obfuscated Files or Information: Compression

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has compressed their payloads by leveraging zip files.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1036.004Masquerading: Masquerade Task or Service

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has masqueraded as commonly used programs and services on Windows hosts.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1036.005Masquerading: Match Legitimate Resource Name or Location

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has masqueraded malicious payloads to resemble legitimate applications.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1078Valid Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged valid accounts to log into VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used compromised valid credentials to gain access to management infrastructure and enterprise control systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also validated and tested authentication using compromised credentials prior to malicious actions.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.002Valid Accounts: Domain Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used previously compromised Domain Administrator credentials to maintain persistent access.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1078.004Valid Accounts: Cloud Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune.(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also compromised existing accounts within the Microsoft Entra ID environment.(Citation: SEC 8-K Stryker Corporation Filing Handala Hack March 2026)

  • T1564.003Hide Artifacts: Hidden Window

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1679Selective Exclusion

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has avoided interacting with specific directories in order to reduce the likelihood of detection.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1684.001Social Engineering: Impersonation

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has impersonated individuals familiar to the victim and technical support associated with social messaging services.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1110Brute Force

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted brute-force attempts against organizational VPN infrastructure.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1110.001Brute Force: Password Guessing

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted password guessing to gain initial access.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1110.004Brute Force: Credential Stuffing

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized credential stuffing attacks to obtain initial access to victim environments.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1552.002Unsecured Credentials: Credentials in Registry

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) had exported credentials from registry hives to include those stored in HKLM.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

TA0007

Discovery

  • T1082System Information Discovery

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered system information and disseminated it back to C2.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1087.002Account Discovery: Domain Account

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized ADRecon to enumerate the active directory environment.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used RDP to move laterally within the victim environment.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1072Software Deployment Tools

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026)

TA0009

Collection

  • T1005Data from Local System

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has collected cached data and files from within the victim environment.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1074Data Staged

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has staged compressed files in specified locations prior to exfiltration over C2.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1113Screen Capture

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has captured screen content during an active Zoom session.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1114.002Email Collection: Remote Email Collection

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered victim email-content from victim servers.(Citation: DOJ FBI Handala Hack March 2026)

  • T1119Automated Collection

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1123Audio Capture

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered audio during a Zoom session.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1125Video Capture

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has collected video from compromised victim devices.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1213.002Data from Information Repositories: Sharepoint

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has accessed victim’s public facing SharePoint servers and exfiltrated data.(Citation: DOJ FBI Handala Hack March 2026)

  • T1560.001Archive Collected Data: Archive via Utility

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has stored collected data in a password protected compressed file prior to exfiltration.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

TA0010

Exfiltration

  • T1041Exfiltration Over C2 Channel

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

TA0011

Command and Control

  • T1071.001Application Layer Protocol: Web Protocols

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized HTTPS for communication to C2 domains.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1102Web Service

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized Telegram API for C2.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1105Ingress Tool Transfer

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deployed additional payloads from dedicated C2 servers.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also downloaded legitimate tools and software from publicly available services.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1219.002Remote Access Tools: Remote Desktop Software

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1572Protocol Tunneling

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used tunneling tools to facilitate destructive attacks on compromised devices.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

TA0040

Impact

  • T1485Data Destruction

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted data wiping attacks on compromised systems.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)

  • T1486Data Encrypted for Impact

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)

  • T1490Inhibit System Recovery

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deleted virtual machines directly from the virtualization platform.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1561.001Disk Wipe: Disk Content Wipe

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized a disk wiping utility to facilitate destructive actions on victim servers.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also utilized legitimate remote disk wiping commands.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)

  • T1561.002Disk Wipe: Disk Structure Wipe

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1657Financial Theft

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also sold stolen data to prospective buyers for cryptocurrency.(Citation: DOJ FBI Handala Hack March 2026)

TA0042

Resource Development

  • T1583.001Acquire Infrastructure: Domains

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has registered domains for messaging purposes.(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion.(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex.(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1583.003Acquire Infrastructure: Virtual Private Server

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized VPS solutions for C2.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1583.004Acquire Infrastructure: Server

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has leveraged backend servers within Iran.(Citation: DOJ FBI Handala Hack March 2026)

  • T1583.006Acquire Infrastructure: Web Services

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has obtained access to commercial VPN services to launch malicious activity.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also leveraged Starlink internet services.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has used operator-controlled Telegram bots and channels as C2 infrastructure.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1585.001Establish Accounts: Social Media Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created Telegram Accounts.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: SPECOPS Outpost24 Handala Hack Stryker March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1585.002Establish Accounts: Email Accounts

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’.(Citation: DOJ FBI Handala Hack March 2026)

  • T1587.001Develop Capabilities: Malware

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has utilized custom-malware and wipers to include BiBi Wiper.(Citation: DOJ FBI Handala Hack March 2026)

  • T1588.001Obtain Capabilities: Malware

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

  • T1588.002Obtain Capabilities: Tool

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

TA0043

Reconnaissance

  • T1589Gather Victim Identity Information

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026)

  • T1595.002Active Scanning: Vulnerability Scanning

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has scanned victim environments for susceptibility to vulnerability exploitation.(Citation: DOJ FBI Handala Hack March 2026)

TA0112

Defense Impairment

  • T1484.001Domain or Tenant Policy Modification: Group Policy Modification

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

  • T1686.003Disable or Modify System Firewall: Windows Host Firewall

    [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has disabled Windows Defender protections to allow for follow-on activities within the compromised host.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)

Recent victims

showing 50 of 175
DateWebsite / victimSectorCountry
2026-04-01
S
St. Joseph County
Government & DefenseUS
2026-04-02
P
PSK WIND’s Defense Networks Fall to Handala Hack
Energy & Utilities
2026-04-02
P
Passover Wiped Clean: 22TB of Data Gone from 14 Companies
Not Found
2026-04-03
P
Publication of Photos and Personal Details of IranWire’s Traitorous Members
Other
2026-04-04
5
50 Senior Unit 9900 Officers Exposed
Government & Defense
2026-04-05
H
Handala Hack Strikes 27 Companies for Minab’s Innocents
Not Found
2026-04-06
R
Raz Zimmt’s Chats Leaked to the World
Not Found
2026-04-07
E
Exposing Israel’s Drone Queen: The Fall of Colonel Haimovich
Not Found
2026-03-31
I
IranWire
TechnologyIR
2026-03-28
N
North Country Business Products Breached: 2,680 POS Terminals Disabled Nationwide
TechnologyUS
2026-03-28
4
4 Terabytes Wiped—Good Food Store Shut Down After Major Cyberattack
Retail & E-CommerceUS
2026-03-29
L
Listen Closely, Gallant: Handala’s Eyes and Ears Are Everywhere
Not Found
2026-03-27
K
Kash Patel current director of the FBI
Government & Defense
2026-03-26
L
Lockheed Martin Employees Given 48 Hours to Respond: A Tight Deadline Looms
ManufacturingUS
2026-03-20
P
Propaganda Chief and Former Mossad Deputy Exposed by Handala Hack
Not Found
2026-03-20
O
Official Statement by Handala Group in Response to Threats from the US and Its Allies
Not Found
2026-03-21
A
Architect of Warfare Exposed: Eran Ortal’s Hidden Strategies Now Public
Not Found
2026-03-22
T
The Slightest Aggression: Enemy Infrastructure Reduced to Ashes
Not Found
2026-03-23
B
Behind the Curtain: Full Details of Shin Bet’s Iran Desk Officers Released
Government & DefenseIL
2026-03-24
$
$50M Reward For Trump & Netanyahu
Not Found
2026-03-25
F
From Hunter to Hunted: Mossad’s Former Chief Falls into the Trap
Not FoundIL
2026-03-18
M
Martyr Ali Larijani
Other
2026-03-17
V
Vahid Offline Members
Not Found
2026-03-17
W
Who is VahidOnline?
TechnologyIR
2026-03-17
M
Mossad’s Secret Treasury Exposed: 50,000 Confidential Emails Leaked
Government & DefenseIL
2026-03-16
S
Stryker Hit by Unprecedented 12-Petabyte Data Wipe
TechnologyUS
2026-03-16
S
Shock for Israeli Intelligence: 100,000 Classified Emails of Mossad’s Ex-Deputy Director S...
Government & DefenseIL
2026-03-15
L
Laura Gilinski
Not Found
2026-03-14
N
No Place to Hide: Senior Navy Officers’ Identities Now Public
Government & Defense
2026-03-13
T
Tamir Hayman
Not FoundIL
2026-03-13
H
Hebrew University of Jerusalem
EducationIL
2026-03-12
R
Raz Zimmt (head of the Iran Desk at Israeli security institutes)
Government & DefenseIL
2026-03-11
stryker.com
Stryker Corporationstryker.com
HealthcareUS
2026-03-11
V
Verifone
TechnologyUS
2026-03-09
F
Full Access: Jerusalem’s Security Cameras in Handala’s Hands
Government & Defense
2026-03-09
U
Unprecedented Disclosure of 50 Senior Israeli Air Force Officers’ Information
Government & DefenseIL
2026-03-08
C
Contact Handala
Not FoundPS
2026-03-08
I
Israeli Weather Stations Crippled
Government & DefenseIL
2026-03-07
J
Jerusalem Water Supply Facilities
Government & DefenseIL
2026-03-07
H
Handala New Telegram
Not Found
2026-03-06
I
IDF in Farsi
Government & DefenseIR
2026-03-06
S
Sanzer Hasidic community
Other
2026-03-05
A
Atlas Insurances Ltd
Financial ServicesIL
2026-03-04
I
Israel Institute for National Security Studies (INSS)
Government & DefenseIL
2026-03-03
A
Aramco
Energy & UtilitiesSA
2026-03-03
S
Sharjah National Oil Corporation
Energy & UtilitiesAE
2026-03-02
I
Israel Opportunity Energy
Energy & UtilitiesIL
2026-02-25
C
Clalit: Israel’s Largest Healthcare Organization Falls to Cyber Resistance
HealthcareIL
2026-02-19
T
The General in the Shadows: Sapir’s Commander Exposed
Not Found
2026-01-25
H
Handala New Account – Sunset of the lions
Not Found