Iranian hackers with multiple faces wreak havoc in Albania and Israel

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Check Point Research Exposes Iranian Threat Actor Void Manticore’s Tactics

Iranian Threat Actor Conducts Destructive Wiping Attacks and Influence Operations

A recent report by Check Point Research has uncovered a series of destructive wiping attacks and influence operations conducted by an Iranian threat actor affiliated with the Ministry of Intelligence and Security (MOIS). Known as Void Manticore, this threat actor has been targeting countries like Israel and Albania with sophisticated cyberattacks.

Void Manticore is known for adopting various online personas, such as “Homeland Justice” and “Karma,” to carry out its operations in different regions. The threat actor’s tactics involve a dual approach, combining data destruction with psychological warfare to maximize the impact of its attacks.

According to researchers, Void Manticore utilizes custom wipers for both Windows and Linux systems to disrupt operations through file deletion and shared drive manipulation. The group’s tactics are relatively straightforward yet effective, targeting critical files and partition tables to render data inaccessible.

Furthermore, the report highlights the coordination between Void Manticore and another threat actor, Scarred Manticore, in targeting victims. Scarred Manticore is responsible for initial access and data exfiltration, while Void Manticore executes the destructive phase of the operation, amplifying the scale and impact of the attacks.

The overlap in attacks against Israel and Albania suggests a systematic victim targeting strategy by MOIS. Void Manticore’s recent deployment of the BiBi Wiper, named after Israel’s Prime Minister Benjamin Netanyahu, showcases the group’s evolving and sophisticated techniques in cyber warfare.

As cyber threats continue to evolve, it is crucial for organizations and governments to stay vigilant and implement robust cybersecurity measures to protect against such malicious actors.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

NovaCookies Phishing Toolkit Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

Cybersecurity researchers have unveiled a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is designed to redirect Microsoft 365 sign-ins while capturing authenticated sessions....

Cybercriminals Leak Grand Theft Auto VI Footage, Prompting Legal Action from Take-Two Interactive

Grand Theft Auto VI, anticipated as the game event of the decade, faced a major setback last week when a cybercriminal leaked gameplay footage...

Cybersecurity Patch Window Collapses, Urging New Control Strategies for Risk Management

For decades, cybersecurity defenders have relied on a straightforward model: when a vulnerability is disclosed, security teams assess exposure, test fixes, deploy patches, and...

Tehran-linked hackers shut down UK power plant in recent cyber attack

A recent cyber attack attributed to hackers linked to the Iranian regime has resulted in the shutdown of a small power plant in the...