CSIDB logo
Threat actor

Void Manticore

Attribution profile

Type
Activist
Location
Iran
Known incidents
1 incident
First seen
2026-03-11
Last seen
2026-03-11
Updated
2026-08-01 12:21
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Void Manticore is the alias used by an Iran‑linked hacktivist group that has been observed in public reporting. The group’s geographic base is identified as Iran, though no further details about its infrastructure or headquarters are publicly available. It operates under a name that appears in threat‑intelligence feeds as a moniker for the activity set. Public sources consistently refer to the actor by this alias when describing its actions.

The group’s known activity has been directed at a medical technology company, indicating a focus on the healthcare sector. The objective expressed in the claimed responsibility statement was to disrupt order processing, manufacturing and shipping functions, which aligns with a disruptive rather than financially motivated aim. No public reporting attributes financial gain or espionage goals to this actor’s operations. The disruption caused operational delays that affected product deliveries and led to short‑term financial impacts for the victim.

Initial access in the observed incident was achieved through the use of compromised administrator credentials, which allowed the attackers to log into the victim’s Microsoft Intune endpoint management platform. Once inside Intune, the group executed a mass wipe command that removed data from tens of thousands of managed devices. The actors also claimed to have exfiltrated large volumes of data, although subsequent investigations found no evidence of actual data theft. The tooling style appears to rely on legitimate administrative tools rather than custom malware, reflecting a living‑off‑the‑land approach.

Attribution to Iran is based on the public description of the group as Iran‑linked, though no explicit state sponsorship has been confirmed in the sources. The activity is therefore characterized as a hacktivist operation with an Iranian nexus rather than a formally state‑directed campaign. The Stryker incident of March 11 2026 stands as the sole publicly reported operation attributed to Void Manticore in the available material. This event prompted U.S. cybersecurity agencies to issue advisories urging organizations to harden Intune configurations and enforce least‑privilege access controls.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB