ATT&CKReferencesPalo Alto VOID MANTICORE Iran Cyber Threats March 2026

Palo Alto VOID MANTICORE Iran Cyber Threats March 2026

Justin Moore. (2026, March 16). Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization. Retrieved April 20, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1072
Software Deployment Tools
GroupVOID MANTICORE

VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.

T1078.004
Cloud Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment.

T1485
Data Destruction
GroupVOID MANTICORE

VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.

T1651
Cloud Administration Command
GroupVOID MANTICORE

VOID MANTICORE has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.