Threadlinqs IntelligenceStart free

Threat actorIranTracked since 2026-03

Void Manticore

Also known as:BANISHED KITTENCOBALT MYSTIQUEHandala HackHomeland JusticeKarmaKarmabelow80Red SandstormHandala Hack TeamStorm-0842Storm-1084ATK51Boggy Serpens

As of 2026-09-09, Void Manticore is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning ics scada, threat intel, apt. Also known as BANISHED KITTEN, COBALT MYSTIQUE, Handala Hack, Homeland Justice. ATT&CK coverage spans 82 techniques across 16 tactics in 6 of 6 tracked threats. Most-observed techniques: T1485 (Data Destruction), T1003 (OS Credential Dumping), T1059 (Command and Scripting Interpreter).

Tracked threats
64 critical · 1 high · 1 medium
First seen
2026-03-12
Last seen
2026-09-09
ATT&CK techniques
82across 6 of 6 threats
Related CVEs
1Referenced by its activity
Attribution
IranNation or origin
Nation: Iran · 6 tracked threat(s) · Categories: ICS_SCADA, THREAT_INTEL, APT

Activity timeline

Void Manticore appears in 6 tracked threats between and ; the busiest month was 2026-03 with 4 reports.

ATT&CK techniques observed

82 techniques observed across 6 of 6 tracked threats · Impact (12), Command and Control (8), Execution (7), Stealth (formerly Defense Evasion) (7), Credential Access (6), Discovery (6)
  • T1485 Data Destruction — Impactobserved in 6 of 6 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 5 of 6 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 5 of 6 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 5 of 6 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 4 of 6 tracked threats
  • T1053 Scheduled Task/Job — Executionobserved in 4 of 6 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 6 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 4 of 6 tracked threats
  • T1484 Domain or Tenant Policy Modification — Privilege Escalationobserved in 4 of 6 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 4 of 6 tracked threats
  • T1561 Disk Wipe — Impactobserved in 4 of 6 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 6 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 6 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
  • T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 3 of 6 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Void Manticore activity