Void Manticore

Threat Actor updated a month ago (2024-11-29T13:57:07.278Z)
Download STIX
Preview STIX
Void Manticore is a malicious software (malware) that has been associated with notable threat actors, including an Iranian actor operating in Israel and Albania. It's designed to exploit and damage computer systems, often infiltrating through suspicious downloads, emails, or websites. Once installed, it can steal personal information, disrupt operations, or even hold data for ransom. One of its distinctive features is the use of the Rhadamanthys stealer, a tool used to extract sensitive data from infected systems. The first known use of the Rhadamanthys stealer by Void Manticore was in a campaign tied to Handala, a persona linked to this malware. The campaign involved distributing the Rhadamanthys stealer under the pretense of an F5 update, marking the beginning of its continued deployment in subsequent campaigns. These campaigns typically impersonated Israeli and international companies, demonstrating a sophisticated approach to social engineering and targeted attacks. Throughout 2024, the activities of threat actors leveraging the Rhadamanthys stealer have been closely monitored, highlighting its association with nation-state threat actors like Iran's Void Manticore and the pro-Palestine group "Handala". In addition to phishing protections, organizations seeking to defend against these threats should be aware of another unique aspect of the campaign: a stealth feature known as CopyR(ight)hadamantys. This highlights the need for comprehensive cybersecurity strategies that address both common and unique threats.
Description last updated: 2024-11-07T04:01:55.078Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Rhadamanthys Malware is associated with Void Manticore. Rhadamanthys is a sophisticated and notorious malware, known for its ability to steal sensitive information. It has been utilized by various threat actors, including nation-state entities such as Iran's Void Manticore and the pro-Palestine group "Handala." Its deployment often involves phishing tactUnspecified
2
Source Document References
Information about the Void Manticore Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more