Threat intelligence
- Suspected origin
- Iran
- First seen
- 2022-01-01 00:00:00
- Motivation
- Sabotage and destruction
- TLP
- WHITE
(ClearSky) On September 23rd, 2022, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) jointly released an advisory analyzing a wave of cyber-attacks targeting the Government of Albania. The group, identifying as 'HomeLand Justice,' was attributed as an Iranian state threat actor.
Homeland Justice launched its first campaign on July 15th, 2022, targeting Albanian e-government systems right before a planned conference of Iranian opposition group Mojahedin-e Khalq (Persian:مجاهدین ِ خلق), also known as MEK - a well-known Iranian group seeking to replace the current regime in Iran. The conference was cancelled following the attack. In September 2022, the actor launched a second campaign targeting Albanian border crossings. On December 24th, 2023, the actor publicized the current campaign, described in this blog, targeting Albanian infrastructure and government organizations.
(Check Point) Void Manticore, linked to the Iranian Ministry of Intelligence and Security (MOIS), executes destructive wiping attacks alongside influence operations.
Operating under various online personas, notably Homeland Justice for Albania and Karma for Israel, Void Manticore targets different regions with tailored attacks.
Overlaps exist between Void Manticore and Scarred Manticore (OilRig, APT 34, Helix Kitten, Chrysene) targets, suggesting coordinated efforts and a systematic handoff of victims in MOIS.
Utilizing five distinct methods, including custom wipers for Windows and Linux, Void Manticore disrupts operations through file deletion and shared drive manipulation.
Also known as
Banished KittenCOBALT MYSTIQUEHandala HackHomeland JusticeKarmaKarmabelow80Red SandstormStorm-0842Void Manticore
Vulnerabilities exploited
MITRE ATT&CK techniques
T1005 Data from Local SystemT1074 Data StagedT1113 Screen CaptureT1119 Automated CollectionT1123 Audio CaptureT1125 Video CaptureT1102 Web ServiceT1105 Ingress Tool TransferT1572 Protocol TunnelingT1110 Brute ForceT1082 System Information DiscoveryT1047 Windows Management InstrumentationT1072 Software Deployment ToolsT1651 Cloud Administration CommandT1041 Exfiltration Over C2 ChannelT1485 Data DestructionT1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1657 Financial TheftT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1566 PhishingT1098 Account ManipulationT1133 External Remote ServicesT1589 Gather Victim Identity InformationT1078 Valid AccountsT1679 Selective Exclusion
Coverage 3
threat-intel
British, American, and Dutch intelligence agencies have issued a warning about a spyware tool, dubbed CHOSEN BRICK, being used by Iranian state-sponsored hackers to target individuals perceived as threats to the Iranian…

threat-intel
Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a…

threat-intel
This analysis from Palo Alto Unit 42 assesses the significant cyber threat landscape surrounding the 2026 FIFA World Cup, highlighting the expanded attack surface created by the event's scale and complexity. The report i…
