DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupVOID MANTICORE | VOID MANTICORE has collected cached data and files from within the victim environment. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram. |
| T1059.001 PowerShell |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell to execute malware in victim environments. |
| T1102 Web Service |
GroupVOID MANTICORE | VOID MANTICORE has utilized Telegram API for C2. |
| T1105 Ingress Tool Transfer |
GroupVOID MANTICORE | VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website. |
| T1114.002 Remote Email Collection |
GroupVOID MANTICORE | VOID MANTICORE has gathered victim email-content from victim servers. |
| T1190 Exploit Public-Facing Application |
GroupVOID MANTICORE | VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604. |
| T1204.002 Malicious File |
GroupVOID MANTICORE | VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance. |
| T1213.002 Sharepoint |
GroupVOID MANTICORE | VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data. |
| T1485 Data Destruction |
GroupVOID MANTICORE | VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them. |
| T1486 Data Encrypted for Impact |
GroupVOID MANTICORE | VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts. |
| T1561.001 Disk Content Wipe |
GroupVOID MANTICORE | VOID MANTICORE has utilized a disk wiping utility to facilitate destructive actions on victim servers. VOID MANTICORE has also utilized legitimate remote disk wiping commands. |
| T1566 Phishing |
GroupVOID MANTICORE | VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector. |
| T1583.001 Domains |
GroupVOID MANTICORE | VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations. |
| T1583.004 Server |
GroupVOID MANTICORE | VOID MANTICORE has leveraged backend servers within Iran. |
| T1585.001 Social Media Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures. |
| T1585.002 Email Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’. |
| T1587.001 Malware |
GroupVOID MANTICORE | VOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper. |
| T1595.002 Vulnerability Scanning |
GroupVOID MANTICORE | VOID MANTICORE has scanned victim environments for susceptibility to vulnerability exploitation. |
| T1657 Financial Theft |
GroupVOID MANTICORE | VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion. VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.