SYMBOLCOMMON_NAMEaka. SYNONYMS

Void Manticore  (Back to overview)


Void Manticore is an Iranian APT group affiliated with MOIS, known for conducting destructive wiping attacks and influence operations. They collaborate with Scarred Manticore, sharing targets and conducting disruptive operations using custom wipers. Void Manticore's TTPs involve manual file deletion, lateral movement via RDP, and the deployment of custom wipers like the BiBi wiper. The group utilizes online personas like 'Karma' and 'Homeland Justice' to leak information and amplify the impact of their attacks.


Associated Families
elf.bibi_linux win.bibi

References
2024-06-03CyfoxIdan Malihi
BiBi Wiper: A Malware Analysis Amidst the Israel-Hamas-ISIS Conflict
BiBi
2024-05-24Check Point Software Technologies LtdCheck Point Research
Bad Karma, No Justice: Void Manticore Destructive Activities in Israel
BiBi-Linux
2024-05-20CheckpointCheckpoint
Bad Karma, No Justice: Void Manticore Destructive Activities in Israel
Void Manticore
2023-11-11Security JoesSecurityJoes
Mission "Data Destruction": A Large-scale Data-Wiping Campaign Targeting Israel
BiBi-Linux
2023-11-10BlackberryDmitry Bestuzhev
BiBi Wiper Used in the Israel-Hamas War Now Runs on Windows
BiBi
2023-10-30Security JoesSecurityJoes
BiBi Wiper
BiBi-Linux BiBiGun

Credits: MISP Project