# Handala Hack

> As of 2026-07-14, Handala Hack is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning threat intel, apt. Also known as VOID MANTICORE - G1055, Karma, KarmaBelow80. ATT&CK coverage spans 79 techniques across 15 tactics in 5 of 5 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1485 (Data Destruction), T1003 (OS Credential Dumping).

- **Nation:** Iran
- **Tracked threats:** 5
- **Categories:** THREAT_INTEL, APT
- **Also known as:** VOID MANTICORE - G1055, Karma, KarmaBelow80
- **As of:** 2026-07-14

## ATT&CK techniques observed

79 techniques observed across 5 of 5 tracked threats. Tactics: Impact (12), Command and Control (8), Execution (7), Stealth (formerly Defense Evasion) (7), Discovery (6), Persistence (6).

- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 5 of 5 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 5 of 5 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 4 of 5 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 4 of 5 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Execution — observed in 4 of 5 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 4 of 5 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 4 of 5 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 4 of 5 tracked threats
- [T1561](https://intel.threadlinqs.com/technique/T1561) Disk Wipe — Impact — observed in 4 of 5 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 5 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1037](https://intel.threadlinqs.com/technique/T1037) Boot or Logon Initialization Scripts — Persistence — observed in 3 of 5 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 5 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 5 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 5 tracked threats

## Tracked threats

- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)](https://intel.threadlinqs.com/threat/TL-2026-1309) — MEDIUM
- [Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation](https://intel.threadlinqs.com/threat/TL-2026-0268) — CRITICAL
- [Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)](https://intel.threadlinqs.com/threat/TL-2026-0237) — CRITICAL
- [Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack](https://intel.threadlinqs.com/threat/TL-2026-0220) — CRITICAL
- [Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign](https://intel.threadlinqs.com/threat/TL-2026-0215) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Handala%20Hack
