Actors Insights|Latest update30/07/2026

Void Manticore

Named by Check PointSuspected state sponsor: Islamic Republic of Iran

Void Manticore is an Iranian MOIS-linked threat actor active since at least 2022, documented by Check Point Research in 2024. The group conducts destructive wiper attacks against Albanian and Israeli targets, deploying custom wiper malware including Cl Wiper and No-Justice (LowEraser) alongside the BiBi wiper. Void Manticore operates under the hacktivist personas Homeland Justice — responsible for attacks against Albanian government infrastructure in 2022 and 2023 — and Karma, used in wiper campaigns against Israeli organizations following the October 2023 Hamas-Israel conflict. Microsoft tracks the same cluster as Storm-842. Check Point documented a coordinated handoff model with the Scarred Manticore cluster, in which Void Manticore receives pre-established access from other Iranian operators before deploying destructive payloads.

First Seen:Jun 2022
Last Seen:Mar 2026
Indexed Reports:2
Public IOCs:27
also known as:
Void Manticore (Check Point)

Targeted Regions

Albania
AL
Albania
Albania
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Israel
IL
Israel
Israel
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023Nov 2026

Targeted Sectors

Government Agencies and ServicesDefenseEnergyHealthcareTelecommunication

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.