logo

The Face of Destruction: Inside Void Manticore’s ‘Handala Hack’ AI-Assisted Wiping Operations

ID: 2e4365fe-046a-5ee0-8f36-7a509cf382e4

STIX ID: report--2e4365fe-046a-5ee0-8f36-7a509cf382e4

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Handala Hack (Void Manticore), an MOIS‑linked Iranian APT, is carrying out destructive hack-and-leak and wiping campaigns against Israel and U.S. targets; researchers observed AI-assisted PowerShell wiping scripts, NetBird tunneling for persistence, RDP-based lateral movement and manual deletion of VMs/files, and disk encryption used to render systems inaccessible—mitigation advice includes enforcing MFA, restricting RDP, and maintaining offline immutable backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.