Threats Feed|Storm-842|Last Updated 30/07/2026|AuthorCertfa Radar|Publish Date27/12/2024

Storm-842: Iranian Cyberattacks on Albania and Israel’s Critical Systems

  • Actor Motivations: Disinformation,Exfiltration,Sabotage
  • Attack Vectors: Ransomware,Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Storm-842 (Void Manticore), linked to Iran’s Ministry of Intelligence and Security (MOIS), has conducted destructive cyberattacks targeting Albania and Israel. Using wiper malware and influence campaigns, the group disrupted Albanian e-government and border systems, targeting sectors like government and infrastructure, while aligning attacks with geopolitical events such as opposition conferences. Operations include exploiting vulnerabilities, deploying web shells, and credential harvesting, often in coordination with Scarred Manticore. The attacks incorporate ransomware-style encryptors, disk wipers, and data leaks through personas like “Homeland Justice” and “Karma,” showcasing a blend of technical and psychological tactics.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionAlbania
Verified
RegionIsrael
Verified

FAQs

Storm-842 (Void Manticore) Cyberattacks

An Iranian cyber threat group conducted a series of highly destructive attacks against government and regional infrastructure. The attackers used specialized software to wipe computer systems and simultaneously ran public influence campaigns to leak stolen information.

The attacks were executed by Storm-842, also known as Void Manticore, which is directly tied to Iran's Ministry of Intelligence and Security (MOIS). The group claims responsibility for these attacks using fake regional personas, specifically "Homeland Justice" in Albania and "Karma" in Israel.

The group's primary goals are technical destruction and psychological warfare. By deleting critical data, disabling networked storage, and leaking sensitive files online, they aim to create chaos, sow public distrust, and undermine targeted governments.

The attacks severely impacted critical national infrastructure, successfully disrupting digital government portals and border management systems. The group's specialized malware is capable of destroying both Windows and Linux computer systems, giving them a broad range of potential impact.

The group specifically targeted the government of Albania and entities within Israel. A major focus of their Albanian campaign was to disrupt political events, specifically forcing the cancellation of a conference held by the Iranian opposition group MEK.

The attack relies on a tag-team approach where a separate hacking group breaks into the network and steals data first. Once the data is stolen, they hand control over to Void Manticore, who deploys custom software to permanently delete files, ruin hard drives, and crash the systems.

The targeted entities represent geopolitical adversaries of the Iranian government. By attacking these specific nations and disrupting opposition groups like the MEK, the attackers serve Iran's broader strategic and diplomatic interests.

Organizations should immediately update their software to fix unpatched systems and carefully monitor their internet-facing servers. It is also essential to secure employee credentials and restrict remote access tools to block the attackers' preferred entry methods.

This is a highly targeted threat rather than a widespread issue affecting the general public. The group methodically selects its victims based on regional politics and coordinates its operations to align with specific Iranian geopolitical goals.

About Affiliation
Storm-842
Storm-842 is Microsoft's designation for an Iranian MOIS-linked threat actor also tracked as Void Manticore, operating under the hacktivist personas Homeland Justice and Karma. The group is primarily known for destructive wiper attacks, deploying custom wiper malware including Cl Wiper, No-Justice (LowEraser), and BiBi against Albania and Israel. In July 2022, Storm-842 deployed ransomware followed by wiper malware against the Albanian government, causing widespread disruption to public services; the attack was retaliation for Albania hosting the Mujahedin-e Khalq (MEK) opposition group. Subsequent waves of attacks struck Albanian organizations in September 2022 and December 2023 under the Homeland Justice banner. After the outbreak of the Israel-Hamas war in October 2023, the group pivoted to attacking Israeli organizations under the Karma persona using the BiBi wiper, which bears technical similarities to the wipers deployed against Albania. Microsoft's investigation identified four distinct Iranian actor groups participating in the Albania operation, with Storm-842 responsible for the final deployment of destructive payloads after earlier actors completed initial access and data exfiltration.
View Storm-842's Insights