ATT&CKReferencesDomain Tools Handala Hack Karma Homeland Justice MOIS April 2026

Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026

DomainTools Investigations. (2026, April 6). Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment. Retrieved April 20, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
GroupVOID MANTICORE

VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.

T1078
Valid Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions.

T1098
Account Manipulation
GroupVOID MANTICORE

VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.

T1110.001
Password Guessing
GroupVOID MANTICORE

VOID MANTICORE has conducted password guessing to gain initial access.

T1110.004
Credential Stuffing
GroupVOID MANTICORE

VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments.

T1119
Automated Collection
GroupVOID MANTICORE

VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems.

T1204.002
Malicious File
GroupVOID MANTICORE

VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.

T1566
Phishing
GroupVOID MANTICORE

VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector.

T1583.001
Domains
GroupVOID MANTICORE

VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.

T1583.006
Web Services
GroupVOID MANTICORE

VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure.

T1585.001
Social Media Accounts
GroupVOID MANTICORE

VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.

T1588.001
Malware
GroupVOID MANTICORE

VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.