Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack

Handala Hack (Void Manticore) Wiper Campaign via Microsoft (TL-2026-0220), also tracked as Operation Handala, is a critical-severity advanced persistent threat campaign, first published 2026-03-12. It is attributed to VOID MANTICORE (Iran) with high confidence, affects Microsoft Microsoft Intune, maps to 27 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 40 indicators of compromise.

Key facts for TL-2026-0220

Threat ID
TL-2026-0220
Also known as
Operation Handala, Handala Wiper Campaign
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-03-12
Last reviewed
2026-03-12
Attribution
VOID MANTICORE
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
healthcare, medical-devices, government, critical-infrastructure, technology, telecom, energy, defense, education, transportation
Target regions
Israel, United States, Albania, Middle East, Europe
Detection rules
9
Indicators of compromise
40

Malware and tooling in Handala Hack (Void Manticore) Wiper Campaign via Microsoft

Malware and tooling: BiBi Wiper, CI Wiper, Handala Wiper, Karma Shell, No-Justice Wiper (LowEraser), ADRecon, NetBird, VeraCrypt, reGeorge

Iran-linked threat actor Handala Hack (Void Manticore / Storm-0842), operating under Iran's Ministry of Intelligence and Security (MOIS), is conducting escalated destructive wiper attacks against Israeli and US organizations. The group compromises administrative credentials via phishing and brute-force, then abuses Microsoft Intune MDM to mass-wipe enrolled devices. On March 11, 2026, the group claimed a devastating attack on Stryker Corporation, wiping over 200,000 devices across 79 countries.

How Handala Hack (Void Manticore) Wiper Campaign via Microsoft works

Handala Hack is an online persona operated by Void Manticore (also tracked as Storm-0842, COBALT MYSTIQUE, Red Sandstorm, and Banished Kitten), an Iranian state-sponsored threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically the Internal Security Deputy and Counter-Terrorism Division.

The group first emerged in late 2023 and has since conducted multiple destructive campaigns against Israeli organizations, Albanian government infrastructure, and most recently US corporations. Void Manticore maintains several hacktivist personas including Handala Hack (targeting Israel), Karma (targeting Israel), and Homeland Justice (targeting Albania).

The attack chain begins with credential compromise through phishing campaigns and brute-force attacks against VPN infrastructure. Attackers operate from commercial VPN nodes and Starlink IP ranges, conducting hundreds of login attempts. Once initial access is obtained, the group establishes persistent access through compromised IT service providers and supply chain relationships, maintaining dwell times of several months before destructive operations.

Lateral movement is conducted manually via Remote Desktop Protocol (RDP) from at least five distinct attacker-controlled machines. The group deploys NetBird, a zero-trust mesh networking tool, for persistent command and control. Credential harvesting is performed through LSASS process dumping using rundll32.exe and comsvcs.dll, registry hive exporting (HKLM, SAM, SECURITY), and Active Directory reconnaissance using ADRecon (deployed as dra.ps1).

The destructive phase employs multiple wiper mechanisms: the custom Handala Wiper (handala.exe) distributed via Group Policy logon scripts, a PowerShell-based wiper that enumerates and deletes user directories while deploying propaganda imagery, VeraCrypt disk encryption as a destruction mechanism, and direct deletion of virtual machines from hypervisors.

In the March 11, 2026 attack on Stryker Corporation, a $25 billion medical technology company, the attackers introduced a novel technique: abusing Microsoft Intune, Stryker's cloud-based Mobile Device Management (MDM) platform. After compromising Global Administrator credentials for the Intune environment, the attackers issued mass Remote Wipe commands to all enrolled devices simultaneously. This affected over 200,000 systems including servers, workstations, and mobile devices across 79 countries, idling approximately 56,000 employees. Personal devices enrolled under BYOD policies were also factory-reset, destroying personal data, eSIMs, and 2FA configurations. Handala claimed to have exfiltrated 50 terabytes of data.

Israel's National Cyber Directorate issued a warning on March 6, 2026, alerting that attackers had gained access to corporate networks and were deleting servers. The Stryker attack represents the first confirmed major cyber disruption of a US corporation since joint US-Israeli military strikes on Iran commenced on February 28, 2026.

Notably, a decline in the group's operational security was observed post-January 2026, when Iran experienced an internet shutdown. Operators transitioned to Starlink IP ranges and began connecting directly from Iranian IP addresses, deviating from their historical use of commercial VPN egress nodes.

MITRE ATT&CK techniques used in TL-2026-0220

credential-access

T1003 OS Credential Dumping; T1110 Brute Force

collection

T1005 Data from Local System

lateral-movement

T1021 Remote Services

persistence

T1037 Boot or Logon Initialization Scripts; T1133 External Remote Services; T1505 Server Software Component

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts; T1484 Domain or Tenant Policy Modification

discovery

T1087 Account Discovery

command-and-control

T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

initial-access

T1199 Trusted Relationship; T1566 Phishing

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1529 System Shutdown/Reboot; T1531 Account Access Removal; T1561 Disk Wipe

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Handala Hack (Void Manticore) Wiper Campaign via Microsoft

  • Microsoft — Microsoft Intune
    Vulnerable versions: All versions with Remote Wipe enabled
  • Microsoft — Microsoft Entra ID (Azure AD)
    Vulnerable versions: All versions
  • Stryker Corporation — Global Enterprise Infrastructure
    Vulnerable versions: Entire Microsoft environment

Remediation for Handala Hack (Void Manticore) Wiper Campaign via Microsoft

Immediate actions

  • Enforce MFA on all Microsoft Intune and Entra ID administrative accounts immediately
  • Audit and restrict Global Administrator and Intune Administrator account assignments
  • Block known Handala VPS IPs at perimeter: 82.25.35.25, 31.57.35.223, 107.189.19.52, 146.185.219.235
  • Monitor Intune audit logs for RemoteWipe and FactoryReset actions — alert on 5+ wipe commands in 1 hour
  • Instruct employees to unenroll personal BYOD devices from corporate MDM until threat is contained
  • Verify immutable offline backups exist for all critical systems

Workarounds

  • Disable remote wipe capability in Intune policies where not operationally required
  • Restrict RDP access and disable where unnecessary
  • Block Starlink IP ranges and Iranian IP ranges at perimeter where feasible
  • Implement network segmentation between MDM management plane and general corporate network

Longer-term hardening

  • Implement Just-in-Time (JIT) access using Microsoft Entra Privileged Identity Management (PIM) — eliminate standing admin privileges
  • Require FIDO2 hardware security keys (e.g., YubiKeys) for all privileged account elevation
  • Deploy Conditional Access policies restricting Intune admin access to corporate IP ranges only
  • Reduce administrative session lifetimes to under 1 hour
  • Enable Token Protection to cryptographically bind authentication tokens to devices
  • Implement Data Loss Prevention (DLP) with exfiltration blocking
  • Deploy EDR with behavioral detection for LSASS dumping and GPO abuse
  • Segment administrative accounts — separate Intune admin from Global Admin roles
  • Monitor for deployment of NetBird, VeraCrypt, and ADRecon on endpoints

Weaknesses (CWE) in Handala Hack (Void Manticore) Wiper Campaign via Microsoft

CWE-287, CWE-269, CWE-522

Timeline of Handala Hack (Void Manticore) Wiper Campaign via Microsoft

  • Handala Hack persona first appears online, presenting as a pro-Palestinian hacktivist group
  • Check Point Research publicly links Void Manticore to Handala Hack and Karma personas, attributing to Iran MOIS
  • Void Manticore deploys BiBi Wiper variants against Israeli organizations, corrupting files with .BiBi extension
  • Iran internet shutdown forces Handala operators to shift to Starlink IPs and direct Iranian IP connections, degrading OPSEC
  • Joint US-Israeli military strikes on Iran commence, triggering escalation of retaliatory cyber operations
  • Israel National Cyber Directorate issues warning that attackers gained access to corporate networks and are deleting servers
  • US intelligence community ramps up warnings of possible retaliatory cyberattacks by Iran against US entities
  • Handala claims responsibility via Telegram, stating retaliation for US bombing and claiming 50TB data exfiltration
  • Handala Hack executes devastating wiper attack on Stryker Corporation via Microsoft Intune abuse, wiping 200,000+ devices across 79 countries
  • Unit 42 and Check Point Research publish detailed technical analyses of Handala Hack TTPs and the Stryker attack
  • As of 2026-05-29, Void Manticore/Handala (Iran MOIS, Storm-0842) remains active, breaching its own US-attack pause by leaking US Marines data and continuing Israel ops post-ceasefire. No CVE to patch; CISA/Microsoft issued Intune hardening guidance but the identity/remote-wipe abuse stays viable in unhardened tenants. (High confidence.)

Sources cited for Handala Hack (Void Manticore) Wiper Campaign via Microsoft

Threats related to Handala Hack (Void Manticore) Wiper Campaign via Microsoft

Detection coverage for TL-2026-0220

As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0220 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats