Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1055
MITRE ATT&CK Group

VOID MANTICORE (G1055)

COBALT MYSTIQUEHandala HackHomeland JusticeKarmaKarmabelow80BANISHED KITTENRed Sandstorm
ShareXLinkedInRedditHN

[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: Palo Alto VOID MANTICORE Iran Cyber Threats March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including [HomeLand Justice](https://attack.mitre.org/campaigns/C0038) in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.(Citation: Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026)

▪Techniques used (63)

T1113Screen CaptureT1110.001Password GuessingT1119Automated CollectionT1561.001Disk Content WipeT1486Data Encrypted for ImpactT1566PhishingT1589Gather Victim Identity InformationT1657Financial TheftT1102Web ServiceT1059.001PowerShellT1047Windows Management InstrumentationT1484.001Group Policy ModificationT1564.003Hidden WindowT1583.001DomainsT1123Audio CaptureT1190Exploit Public-Facing ApplicationT1114.002Remote Email CollectionT1074Data StagedT1078.002Domain AccountsT1027.015CompressionT1684.001ImpersonationT1036.005Match Legitimate Resource Name or LocationT1679Selective ExclusionT1087.002Domain AccountT1588.001MalwareT1490Inhibit System RecoveryT1072Software Deployment ToolsT1003.001LSASS MemoryT1651Cloud Administration CommandT1583.003Virtual Private ServerT1583.006Web ServicesT1686.003Windows Host FirewallT1552.002Credentials in RegistryT1213.002SharepointT1219.002Remote Desktop SoftwareT1595.002Vulnerability ScanningT1561.002Disk Structure WipeT1583.004ServerT1105Ingress Tool TransferT1082System Information DiscoveryT1078.004Cloud AccountsT1133External Remote ServicesT1588.002ToolT1547.001Registry Run Keys / Startup FolderT1204.002Malicious FileT1005Data from Local SystemT1098Account ManipulationT1125Video CaptureT1572Protocol TunnelingT1587.001MalwareT1585.002Email AccountsT1071.001Web ProtocolsT1199Trusted RelationshipT1110.004Credential StuffingT1585.001Social Media AccountsT1485Data DestructionT1078Valid AccountsT1110Brute ForceT1036.004Masquerade Task or ServiceT1059.006PythonT1560.001Archive via UtilityT1041Exfiltration Over C2 ChannelT1021.001Remote Desktop Protocol
G1055on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.