Karma Below is an Iranian state-linked cyber persona associated with Iran’s Ministry of Intelligence and Security (MOIS) and assessed to be part of the broader cluster commonly tracked as Void Manticore, also known as TAG-145, Red Sandstorm, and Banished Kitten. It is one of several operational brands used to support Iranian cyber, influence, and psychological operations while preserving plausible deniability through hacktivist-style front identities. Karma Below has been linked alongside Handala Hack Team and Homeland Justice as part of the same operator ecosystem, and U.S. government reporting has stated that these personas are operated by the same individuals. The persona has been associated with attacks and data-leak activity targeting victims in the United States and internationally. It has specifically been reported as targeting the Israeli government and deploying destructive malware referred to as the BiBi wiper. The broader MOIS-linked cluster tied to Karma Below is known for hack-and-leak operations, destructive attacks, psychological operations, and the use of online personas to amplify intimidation and publicity. Related personas have used websites and Telegram channels to claim intrusions, leak stolen information, and shape narratives around operations. Tradecraft observed across the cluster includes social engineering, Windows malware deployment, data theft, destructive wiping, and coordinated information operations. Known associated aliases and related personas include karmabelow, Handala Hack Team, Homeland Justice, and Justice Homeland. Based on available reporting, Karma Below should be understood less as an isolated intrusion set than as a reusable operational persona within a larger MOIS-directed campaign apparatus targeting Israeli interests, dissidents, opposition figures, and, increasingly, U.S.-linked targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Void Manticore/MOIS-linked persona targeting the Israeli government with destructive malware.
Threat actor whose websites were used during attacks and to leak sensitive documents and data stolen in cyberattacks targeting victims in the United States and globally.
A hacktivist persona identified by the FBI as part of the same conspiracy as Handala and Homeland Justice, allegedly operated by the same individuals tied to Iran’s MOIS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.