Iranian hackers with multiple faces wreak havoc in Albania and Israel

Published:

spot_img

Check Point Research Exposes Iranian Threat Actor Void Manticore’s Tactics

Iranian Threat Actor Conducts Destructive Wiping Attacks and Influence Operations

A recent report by Check Point Research has uncovered a series of destructive wiping attacks and influence operations conducted by an Iranian threat actor affiliated with the Ministry of Intelligence and Security (MOIS). Known as Void Manticore, this threat actor has been targeting countries like Israel and Albania with sophisticated cyberattacks.

Void Manticore is known for adopting various online personas, such as “Homeland Justice” and “Karma,” to carry out its operations in different regions. The threat actor’s tactics involve a dual approach, combining data destruction with psychological warfare to maximize the impact of its attacks.

According to researchers, Void Manticore utilizes custom wipers for both Windows and Linux systems to disrupt operations through file deletion and shared drive manipulation. The group’s tactics are relatively straightforward yet effective, targeting critical files and partition tables to render data inaccessible.

Furthermore, the report highlights the coordination between Void Manticore and another threat actor, Scarred Manticore, in targeting victims. Scarred Manticore is responsible for initial access and data exfiltration, while Void Manticore executes the destructive phase of the operation, amplifying the scale and impact of the attacks.

The overlap in attacks against Israel and Albania suggests a systematic victim targeting strategy by MOIS. Void Manticore’s recent deployment of the BiBi Wiper, named after Israel’s Prime Minister Benjamin Netanyahu, showcases the group’s evolving and sophisticated techniques in cyber warfare.

As cyber threats continue to evolve, it is crucial for organizations and governments to stay vigilant and implement robust cybersecurity measures to protect against such malicious actors.

spot_img

Related articles

Recent articles

OpenAI Flags Astra Model for Critical Cybersecurity Risks, Halting Development

OpenAI has raised alarms regarding its forthcoming AI model, Astra, which may pose a ‘critical’ cybersecurity risk. This assessment has led the company to...

Redomiciling to Dubai does not exempt firms from MiCA obligations, warns Relm official

Insurance gaps in director liability, custody, and wallets often surface only after crypto firms relocate, warns Relm’s global distribution chief. Dubai has become a focal...

Atlassian Rovo Vulnerability Allows Data Exfiltration from Jira and Confluence

Recent findings have revealed a vulnerability in Atlassian's Rovo assistant that allows attacker-controlled instructions to extract data from Jira and Confluence. This issue was...

Qilin Ransomware Claim: Stade Français Investigates Data Leak After Cyberattack

Qilin Ransomware Claim: Stade Français Paris has confirmed it was targeted by a cyberattack that disrupted its information systems. The club reported that it...