Activity timeline
Void Manticore appears in 6 tracked threats between and ; the busiest month was 2026-03 with 4 reports.
ATT&CK techniques observed
- T1485 Data Destruction — Impactobserved in 6 of 6 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 5 of 6 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 5 of 6 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 5 of 6 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 4 of 6 tracked threats
- T1053 Scheduled Task/Job — Executionobserved in 4 of 6 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 4 of 6 tracked threats
- T1087 Account Discovery — Discoveryobserved in 4 of 6 tracked threats
- T1484 Domain or Tenant Policy Modification — Privilege Escalationobserved in 4 of 6 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 4 of 6 tracked threats
- T1561 Disk Wipe — Impactobserved in 4 of 6 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 6 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 6 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
- T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 3 of 6 tracked threats
Tracked threats
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes PoultryHIGH
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)MEDIUM
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker CorporationCRITICAL
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)CRITICAL
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker AttackCRITICAL
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater CampaignCRITICAL