ATT&CKReferencesFBI IC3 Flash VOID MANTICORE Handala Hack March 2026

FBI IC3 Flash VOID MANTICORE Handala Hack March 2026

FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. Retrieved April 20, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupVOID MANTICORE

VOID MANTICORE has collected cached data and files from within the victim environment.

T1027.015
Compression
GroupVOID MANTICORE

VOID MANTICORE has compressed their payloads by leveraging zip files.

T1036.004
Masquerade Task or Service
GroupVOID MANTICORE

VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts.

T1036.005
Match Legitimate Resource Name or Location
GroupVOID MANTICORE

VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram.

T1059.001
PowerShell
GroupVOID MANTICORE

VOID MANTICORE has utilized PowerShell to execute malware in victim environments.

T1059.006
Python
GroupVOID MANTICORE

VOID MANTICORE has utilized Python scripts to execute its malicious payloads.

T1071.001
Web Protocols
GroupVOID MANTICORE

VOID MANTICORE has utilized HTTPS for communication to C2 domains.

T1074
Data Staged
GroupVOID MANTICORE

VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2.

T1082
System Information Discovery
GroupVOID MANTICORE

VOID MANTICORE has gathered system information and disseminated it back to C2.

T1102
Web Service
GroupVOID MANTICORE

VOID MANTICORE has utilized Telegram API for C2.

T1105
Ingress Tool Transfer
GroupVOID MANTICORE

VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.

T1113
Screen Capture
GroupVOID MANTICORE

VOID MANTICORE has captured screen content during an active Zoom session.

T1123
Audio Capture
GroupVOID MANTICORE

VOID MANTICORE has gathered audio during a Zoom session.

T1125
Video Capture
GroupVOID MANTICORE

VOID MANTICORE has collected video from compromised victim devices.

T1204.002
Malicious File
GroupVOID MANTICORE

VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.

T1547.001
Registry Run Keys / Startup Folder
GroupVOID MANTICORE

VOID MANTICORE has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.

T1560.001
Archive via Utility
GroupVOID MANTICORE

VOID MANTICORE has stored collected data in a password protected compressed file prior to exfiltration.

T1564.003
Hidden Window
GroupVOID MANTICORE

VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.

T1583.001
Domains
GroupVOID MANTICORE

VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.

T1585.001
Social Media Accounts
GroupVOID MANTICORE

VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.

T1589
Gather Victim Identity Information
GroupVOID MANTICORE

VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.

T1679
Selective Exclusion
GroupVOID MANTICORE

VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection.

T1684.001
Impersonation
GroupVOID MANTICORE

VOID MANTICORE has impersonated individuals familiar to the victim and technical support associated with social messaging services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.