MOIS-affiliated Iranian APT group known for destructive wiper attacks and influence operations.
Analyst brief
Void Manticore is an MOIS-affiliated Iranian APT group known for destructive wiper attacks and influence operations. They primarily target government entities and critical infrastructure in Israel, Albania, and the broader Middle East. Their key TTPs include phishing for initial access, lateral movement via RDP, credential dumping from LSASS memory, and deploying custom wipers such as the BiBi wiper combined with manual file deletion. Defenders should focus on detecting manual file deletion activity, anomalous RDP connections, and monitor for data leaks and amplification through online personas like 'Karma' and 'Homeland Justice'.
Void Manticore
COBALT MYSTIQUEHandala HackHomeland Justice
unknown
Void Manticore is an Iranian APT group affiliated with MOIS, known for conducting destructive wiping attacks and influence operations. They collaborate with Scarred Manticore, sharing targets and conducting disruptive operations using custom wipers. Void Manticore's TTPs involve manual file deletion, lateral movement via RDP, and the deployment of custom wipers like the BiBi wiper. The group utilizes online personas like 'Karma' and 'Homeland Justice' to leak information and amplify the impact of their attacks.