Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack — Threadlinqs Intelligence
As of 2026-05-30, Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack is a critical-severity apt threat attributed to VOID MANTICORE (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0220 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: VOID MANTICORE · Iran · DESTRUCTION
Iran-linked threat actor Handala Hack (Void Manticore / Storm-0842), operating under Iran's Ministry of Intelligence and Security (MOIS), is conducting escalated destructive wiper attacks against
Handala Hack is an online persona operated by Void Manticore (also tracked as Storm-0842, COBALT MYSTIQUE, Red Sandstorm, and Banished Kitten), an Iranian state-sponsored threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically the Internal Security Deputy and Counter-Terrorism Division.
The group first emerged in late 2023 and has since conducted multiple destructive campaigns against Israeli organizations, Albanian government infrastructure, and most recently US corporations. Void Manticore maintains several hacktivist personas including Handala Hack (targeting Israel), Karma (targeting Israel), and Homeland Justice (targeting Albania).
The attack chain begins with credential compromise through phishing campaigns and brute-force attacks against VPN infrastructure. Attackers operate from commercial VPN nodes and Starlink IP ranges, conducting hundreds of login attempts. Once initial access is obtained, the group establishes persistent access through compromised IT service providers and supply chain relationships, maintaining dwell times of several months before destructive operations.
Lateral movement is conducted manually via Remote Desktop Protocol (RDP) from at least five distinct attacker-controlled machines. The group deploys NetBird, a zero-trust mesh networking tool, for persistent command and control. Credential harvesting is performed through LSASS process dumping using rundll32.exe and comsvcs.dll, registry hive exporting (HKLM, SAM, SECURITY), and Active Directory reconnaissance using ADRecon (deployed as dra.ps1).
The destructive phase employs multiple wiper mechanisms: the custom Handala Wiper (handala.exe) distributed via Group Policy logon scripts, a PowerShell-based wiper that enumerates and deletes user directories while deploying propaganda imagery, VeraCrypt disk encryption as a destruction mechanism, and direct deletion of virtual machines from hypervisors.
In the March 11, 2026 attack on Stryker Corporation, a $25 billion medical technology company, the attackers introduced a novel technique: abusing Microsoft Intune, Stryker's cloud-based Mobile Device Management (MDM) platform. After compromising Global Administrator credentials for the Intune environment, the attackers issued mass Remote Wipe commands to all enrolled devices simultaneously. This affected over 200,000 systems including servers, workstations, and mobile devices across 79 countries, idling approximately 56,000 employees. Personal devices enrolled under BYOD policies were also factory-reset, destroying personal data, eSIMs, and 2FA configurations. Handala claimed to have exfiltrated 50 terabytes of data.
Israel's National Cyber Directorate issued a warning on March 6, 2026, alerting that attackers had gained access to corporate networks and were deleting servers. The Stryker attack represents the first confirmed major cyber disruption of a US corporation since joint US-Israeli military strikes on Iran commenced on February 28, 2026.
Notably, a decline in the group's operational security was observed post-January 2026, when Iran experienced an internet shutdown. Operators transitioned to Starlink IP ranges and began connecting directly from Iranian IP addresses, deviating from their historical use of commercial VPN egress nodes.
Weaknesses (CWE)
CWE-287, CWE-269, CWE-522
Target sectors: healthcare, medical-devices, government, critical-infrastructure, technology, telecom, energy, defense, education, transportation
Target regions: Israel, United States, Albania, Middle East, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1566, T1078, T1078, T1078, T1133, T1199, T1059, T1072, T1053, T1047