Karma Below is an Iranian state-linked cyber persona associated with Iran’s Ministry of Intelligence and Security (MOIS) and the broader cluster commonly tracked as Void Manticore. It is assessed to be operated by the same individuals behind the Handala and Homeland Justice personas and functions as part of a coordinated MOIS influence, cyber, and intimidation apparatus that presents itself as independent hacktivist activity while supporting state objectives. Karma Below has been linked to operations targeting Israel, including the Israeli government, and has been associated with deployment of destructive malware identified as the BiBi wiper. The persona has also been tied to infrastructure used to support attacks and publish stolen information from victims in the United States and other countries. Within the broader MOIS-linked ecosystem, related personas have conducted hack-and-leak operations, destructive attacks, psychological operations, and data publication intended to intimidate adversaries and amplify political messaging. Karma Below is best understood as one operational brand within a larger Iranian intelligence-linked network that includes Handala Hack Team and Homeland Justice. This cluster has been publicly associated with aliases and tracking names including Void Manticore, TAG-145, Red Sandstorm, and Banished Kitten. The network has targeted Israeli entities, Iranian dissidents and opposition figures, and victims in the United States, combining cyber intrusion activity with information operations and destructive effects. Available reporting supports espionage and disruptive state-directed activity rather than financially motivated crime as the dominant purpose.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Void Manticore/MOIS-linked persona targeting the Israeli government with destructive malware.
Threat actor whose websites were used during attacks and to leak sensitive documents and data stolen in cyberattacks targeting victims in the United States and globally.
A hacktivist persona identified by the FBI as part of the same conspiracy as Handala and Homeland Justice, allegedly operated by the same individuals tied to Iran’s MOIS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.