« Todas las amenazas

Grupo APTMITRE G1055

VOID MANTICORE

También conocido como: banished kitten, cobalt mystique, handala hack, homeland justice, karma, karmabelow80, red sandstorm

[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including [HomeLand Justice](https://attack.mitre.org/campaigns/C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

Víctimas en los últimos 90 días0

Países más afectados

Sin datos todavía.

Sectores más afectados

Sin datos todavía.

Mitigaciones prioritarias

Mitigaciones de MITRE ATT&CK que cubren más técnicas de las que usa este grupo.

  1. Gestión de cuentas de usuario (16 técnicas cubiertas)
  2. Autenticación multifactor (13 técnicas cubiertas)
  3. Gestión de cuentas privilegiadas (12 técnicas cubiertas)
  4. Formación de usuarios (10 técnicas cubiertas)
  5. Políticas de contraseñas (9 técnicas cubiertas)
  6. Prevención de ejecución (8 técnicas cubiertas)
  7. Auditoría (8 técnicas cubiertas)
  8. Segmentación de red (6 técnicas cubiertas)

Técnicas MITRE ATT&CK

T1113 · Screen CaptureT1110.001 · Password GuessingT1119 · Automated CollectionT1561.001 · Disk Content WipeT1486 · Data Encrypted for ImpactT1566 · PhishingT1589 · Gather Victim Identity InformationT1657 · Financial TheftT1102 · Web ServiceT1059.001 · PowerShellT1047 · Windows Management InstrumentationT1484.001 · Group Policy ModificationT1564.003 · Hidden WindowT1583.001 · DomainsT1123 · Audio CaptureT1190 · Exploit Public-Facing ApplicationT1114.002 · Remote Email CollectionT1074 · Data StagedT1078.002 · Domain AccountsT1027.015 · CompressionT1684.001 · ImpersonationT1036.005 · Match Legitimate Resource Name or LocationT1679 · Selective ExclusionT1087.002 · Domain AccountT1588.001 · MalwareT1490 · Inhibit System RecoveryT1072 · Software Deployment ToolsT1003.001 · LSASS MemoryT1651 · Cloud Administration CommandT1583.003 · Virtual Private ServerT1583.006 · Web ServicesT1686.003 · Windows Host FirewallT1552.002 · Credentials in RegistryT1213.002 · SharepointT1219.002 · Remote Desktop SoftwareT1595.002 · Vulnerability ScanningT1561.002 · Disk Structure WipeT1583.004 · ServerT1105 · Ingress Tool TransferT1082 · System Information DiscoveryT1078.004 · Cloud AccountsT1133 · External Remote ServicesT1588.002 · ToolT1547.001 · Registry Run Keys / Startup FolderT1204.002 · Malicious FileT1005 · Data from Local SystemT1098 · Account ManipulationT1125 · Video CaptureT1572 · Protocol TunnelingT1587.001 · MalwareT1585.002 · Email AccountsT1071.001 · Web ProtocolsT1199 · Trusted RelationshipT1110.004 · Credential StuffingT1585.001 · Social Media AccountsT1485 · Data DestructionT1078 · Valid AccountsT1110 · Brute ForceT1036.004 · Masquerade Task or ServiceT1059.006 · Python

Víctimas recientes

Sin datos todavía.

Las reivindicaciones las publican los propios grupos criminales y no están verificadas hasta que la organización o la prensa las confirman. Los nombres de personas físicas (autónomos, profesionales individuales) se anonimizan conforme al RGPD. Nunca enlazamos a sitios de filtración ni a datos robados. Para solicitar la retirada o anonimización de una entrada, contacte con el administrador del sitio.

Fuentes: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.