Threadlinqs IntelligenceStart free

Threat actorIranTracked since 2026-03

Handala Hack

Also known as:VOID MANTICORE - G1055KarmaKarmaBelow80

As of 2026-07-14, Handala Hack is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning threat intel, apt. Also known as VOID MANTICORE - G1055, Karma, KarmaBelow80. ATT&CK coverage spans 79 techniques across 15 tactics in 5 of 5 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1485 (Data Destruction), T1003 (OS Credential Dumping).

Tracked threats
54 critical · 1 medium
First seen
2026-03-12
Last seen
2026-07-14
ATT&CK techniques
79across 5 of 5 threats
Related CVEs
0None referenced
Attribution
IranNation or origin
Nation: Iran · 5 tracked threat(s) · Categories: THREAT_INTEL, APT

Activity timeline

Handala Hack appears in 5 tracked threats between and ; the busiest month was 2026-03 with 4 reports.

ATT&CK techniques observed

79 techniques observed across 5 of 5 tracked threats · Impact (12), Command and Control (8), Execution (7), Stealth (formerly Defense Evasion) (7), Discovery (6), Persistence (6)
  • T1059 Command and Scripting Interpreter — Executionobserved in 5 of 5 tracked threats
  • T1485 Data Destruction — Impactobserved in 5 of 5 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 4 of 5 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 4 of 5 tracked threats
  • T1053 Scheduled Task/Job — Executionobserved in 4 of 5 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 4 of 5 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 4 of 5 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 4 of 5 tracked threats
  • T1561 Disk Wipe — Impactobserved in 4 of 5 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 5 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
  • T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 3 of 5 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 5 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 3 of 5 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 5 tracked threats

Tracked threats