Void Manticore
Named by Check PointSuspected state sponsor: Islamic Republic of IranVoid Manticore is an Iranian MOIS-linked threat actor active since at least 2022, documented by Check Point Research in 2024. The group conducts destructive wiper attacks against Albanian and Israeli targets, deploying custom wiper malware including Cl Wiper and No-Justice (LowEraser) alongside the BiBi wiper. Void Manticore operates under the hacktivist personas Homeland Justice — responsible for attacks against Albanian government infrastructure in 2022 and 2023 — and Karma, used in wiper campaigns against Israeli organizations following the October 2023 Hamas-Israel conflict. Microsoft tracks the same cluster as Storm-842. Check Point documented a coordinated handoff model with the Scarred Manticore cluster, in which Void Manticore receives pre-established access from other Iranian operators before deploying destructive payloads.
Targeted Regions
AlbaniaAlbania
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
IsraelIsrael
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Oct 2023 ~ May 2024
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.