216.73.216.6

Void Manticore Destructive Activities in Israel

· Published 20/05/2024 16:35 · Modified 21/05/2024 16:07

Export JSON

Essential information

Published
20/05/2024 16:35
Modified
21/05/2024 16:07
Tags
2024-05-20 bibi wiper cl wiper destructive hacktivism iran leaks wipers
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 2 malware, 2 others

Description

This analysis details the operations carried out by the Iranian threat actor Void Manticore, also known as Storm-842, against Israeli organizations. The group utilizes various techniques, including custom for Windows and Linux, manual file deletion, and partition table corruption. Their activities involve leaking exfiltrated data through online personas like 'Karma' and are characterized by politically charged messaging, such as naming their after Israeli Prime Minister Benjamin Netanyahu. Void Manticore's operations exhibit coordination with another Iranian actor, Scarred Manticore (Storm-861), suggesting target handoffs between the two groups.

External references