# Void Manticore

> As of 2026-09-09, Void Manticore is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning ics scada, threat intel, apt. Also known as BANISHED KITTEN, COBALT MYSTIQUE, Handala Hack, Homeland Justice. ATT&CK coverage spans 82 techniques across 16 tactics in 6 of 6 tracked threats. Most-observed techniques: T1485 (Data Destruction), T1003 (OS Credential Dumping), T1059 (Command and Scripting Interpreter).

- **Nation:** Iran
- **Tracked threats:** 6
- **Categories:** ICS_SCADA, THREAT_INTEL, APT
- **Also known as:** BANISHED KITTEN, COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma, Karmabelow80, Red Sandstorm, Handala Hack Team, Storm-0842, Storm-1084, ATK51, Boggy Serpens
- **As of:** 2026-09-09

## ATT&CK techniques observed

82 techniques observed across 6 of 6 tracked threats. Tactics: Impact (12), Command and Control (8), Execution (7), Stealth (formerly Defense Evasion) (7), Credential Access (6), Discovery (6).

- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 6 of 6 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 5 of 6 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 5 of 6 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 5 of 6 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 4 of 6 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Execution — observed in 4 of 6 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 6 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 4 of 6 tracked threats
- [T1484](https://intel.threadlinqs.com/technique/T1484) Domain or Tenant Policy Modification — Privilege Escalation — observed in 4 of 6 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 4 of 6 tracked threats
- [T1561](https://intel.threadlinqs.com/technique/T1561) Disk Wipe — Impact — observed in 4 of 6 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 4 of 6 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 6 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 6 tracked threats
- [T1037](https://intel.threadlinqs.com/technique/T1037) Boot or Logon Initialization Scripts — Persistence — observed in 3 of 6 tracked threats

## Tracked threats

- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry](https://intel.threadlinqs.com/threat/TL-2026-2420) — HIGH
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)](https://intel.threadlinqs.com/threat/TL-2026-1309) — MEDIUM
- [Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation](https://intel.threadlinqs.com/threat/TL-2026-0268) — CRITICAL
- [Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)](https://intel.threadlinqs.com/threat/TL-2026-0237) — CRITICAL
- [Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack](https://intel.threadlinqs.com/threat/TL-2026-0220) — CRITICAL
- [Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign](https://intel.threadlinqs.com/threat/TL-2026-0215) — CRITICAL

## Related CVEs

1 CVE referenced by tracked Void Manticore activity.

- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Void%20Manticore
