Iranian hackers with multiple faces wreak havoc in Albania and Israel

Published:

spot_img

Check Point Research Exposes Iranian Threat Actor Void Manticore’s Tactics

Iranian Threat Actor Conducts Destructive Wiping Attacks and Influence Operations

A recent report by Check Point Research has uncovered a series of destructive wiping attacks and influence operations conducted by an Iranian threat actor affiliated with the Ministry of Intelligence and Security (MOIS). Known as Void Manticore, this threat actor has been targeting countries like Israel and Albania with sophisticated cyberattacks.

Void Manticore is known for adopting various online personas, such as “Homeland Justice” and “Karma,” to carry out its operations in different regions. The threat actor’s tactics involve a dual approach, combining data destruction with psychological warfare to maximize the impact of its attacks.

According to researchers, Void Manticore utilizes custom wipers for both Windows and Linux systems to disrupt operations through file deletion and shared drive manipulation. The group’s tactics are relatively straightforward yet effective, targeting critical files and partition tables to render data inaccessible.

Furthermore, the report highlights the coordination between Void Manticore and another threat actor, Scarred Manticore, in targeting victims. Scarred Manticore is responsible for initial access and data exfiltration, while Void Manticore executes the destructive phase of the operation, amplifying the scale and impact of the attacks.

The overlap in attacks against Israel and Albania suggests a systematic victim targeting strategy by MOIS. Void Manticore’s recent deployment of the BiBi Wiper, named after Israel’s Prime Minister Benjamin Netanyahu, showcases the group’s evolving and sophisticated techniques in cyber warfare.

As cyber threats continue to evolve, it is crucial for organizations and governments to stay vigilant and implement robust cybersecurity measures to protect against such malicious actors.

spot_img

Related articles

Recent articles

Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part...

Romania’s Land Registry Agency Works to Restore Services Following Cyberattack Disruption

A cyberattack has disrupted Romania's digital land registry systems, as reported by the National Agency for Cadastre and Land Registration (ANCPI). The agency confirmed...

CVE-2026-56164 and CVE-2026-56155 in Microsoft SharePoint and Active Directory Patches Released Amid Active Exploitation Concerns

On July 20, 2026, Microsoft released critical patches addressing two vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting SharePoint Server and Active Directory Federation Services, respectively. These...

Abbott Laboratories Investigates Dual Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories is currently investigating two significant cybersecurity incidents affecting its Cancer Diagnostics and Core Laboratory diagnostics businesses. The first incident involves unauthorized access...