Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack
Handala Hack (Void Manticore) Wiper Campaign via Microsoft (TL-2026-0220), also tracked as Operation Handala, is a critical-severity advanced persistent threat campaign, first published 2026-03-12. It is attributed to VOID MANTICORE (Iran) with high confidence, affects Microsoft Microsoft Intune, maps to 27 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 40 indicators of compromise.
Key facts for TL-2026-0220
- Threat ID
- TL-2026-0220
- Also known as
- Operation Handala, Handala Wiper Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-12
- Last reviewed
- 2026-03-12
- Attribution
- VOID MANTICORE
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- healthcare, medical-devices, government, critical-infrastructure, technology, telecom, energy, defense, education, transportation
- Target regions
- Israel, United States, Albania, Middle East, Europe
- Detection rules
- 9
- Indicators of compromise
- 40
Malware and tooling in Handala Hack (Void Manticore) Wiper Campaign via Microsoft
Malware and tooling: BiBi Wiper, CI Wiper, Handala Wiper, Karma Shell, No-Justice Wiper (LowEraser), ADRecon, NetBird, VeraCrypt, reGeorge
Iran-linked threat actor Handala Hack (Void Manticore / Storm-0842), operating under Iran's Ministry of Intelligence and Security (MOIS), is conducting escalated destructive wiper attacks against Israeli and US organizations. The group compromises administrative credentials via phishing and brute-force, then abuses Microsoft Intune MDM to mass-wipe enrolled devices. On March 11, 2026, the group claimed a devastating attack on Stryker Corporation, wiping over 200,000 devices across 79 countries.
How Handala Hack (Void Manticore) Wiper Campaign via Microsoft works
Handala Hack is an online persona operated by Void Manticore (also tracked as Storm-0842, COBALT MYSTIQUE, Red Sandstorm, and Banished Kitten), an Iranian state-sponsored threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically the Internal Security Deputy and Counter-Terrorism Division.
The group first emerged in late 2023 and has since conducted multiple destructive campaigns against Israeli organizations, Albanian government infrastructure, and most recently US corporations. Void Manticore maintains several hacktivist personas including Handala Hack (targeting Israel), Karma (targeting Israel), and Homeland Justice (targeting Albania).
The attack chain begins with credential compromise through phishing campaigns and brute-force attacks against VPN infrastructure. Attackers operate from commercial VPN nodes and Starlink IP ranges, conducting hundreds of login attempts. Once initial access is obtained, the group establishes persistent access through compromised IT service providers and supply chain relationships, maintaining dwell times of several months before destructive operations.
Lateral movement is conducted manually via Remote Desktop Protocol (RDP) from at least five distinct attacker-controlled machines. The group deploys NetBird, a zero-trust mesh networking tool, for persistent command and control. Credential harvesting is performed through LSASS process dumping using rundll32.exe and comsvcs.dll, registry hive exporting (HKLM, SAM, SECURITY), and Active Directory reconnaissance using ADRecon (deployed as dra.ps1).
The destructive phase employs multiple wiper mechanisms: the custom Handala Wiper (handala.exe) distributed via Group Policy logon scripts, a PowerShell-based wiper that enumerates and deletes user directories while deploying propaganda imagery, VeraCrypt disk encryption as a destruction mechanism, and direct deletion of virtual machines from hypervisors.
In the March 11, 2026 attack on Stryker Corporation, a $25 billion medical technology company, the attackers introduced a novel technique: abusing Microsoft Intune, Stryker's cloud-based Mobile Device Management (MDM) platform. After compromising Global Administrator credentials for the Intune environment, the attackers issued mass Remote Wipe commands to all enrolled devices simultaneously. This affected over 200,000 systems including servers, workstations, and mobile devices across 79 countries, idling approximately 56,000 employees. Personal devices enrolled under BYOD policies were also factory-reset, destroying personal data, eSIMs, and 2FA configurations. Handala claimed to have exfiltrated 50 terabytes of data.
Israel's National Cyber Directorate issued a warning on March 6, 2026, alerting that attackers had gained access to corporate networks and were deleting servers. The Stryker attack represents the first confirmed major cyber disruption of a US corporation since joint US-Israeli military strikes on Iran commenced on February 28, 2026.
Notably, a decline in the group's operational security was observed post-January 2026, when Iran experienced an internet shutdown. Operators transitioned to Starlink IP ranges and began connecting directly from Iranian IP addresses, deviating from their historical use of commercial VPN egress nodes.
MITRE ATT&CK techniques used in TL-2026-0220
credential-access
T1003 OS Credential Dumping; T1110 Brute Force
collection
lateral-movement
persistence
T1037 Boot or Logon Initialization Scripts; T1133 External Remote Services; T1505 Server Software Component
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools
defense-evasion
T1070 Indicator Removal; T1078 Valid Accounts; T1484 Domain or Tenant Policy Modification
discovery
command-and-control
T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
initial-access
T1199 Trusted Relationship; T1566 Phishing
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1529 System Shutdown/Reboot; T1531 Account Access Removal; T1561 Disk Wipe
defense-impairment
Affected products and versions in Handala Hack (Void Manticore) Wiper Campaign via Microsoft
- Microsoft — Microsoft Intune
Vulnerable versions: All versions with Remote Wipe enabled - Microsoft — Microsoft Entra ID (Azure AD)
Vulnerable versions: All versions - Stryker Corporation — Global Enterprise Infrastructure
Vulnerable versions: Entire Microsoft environment
Remediation for Handala Hack (Void Manticore) Wiper Campaign via Microsoft
Immediate actions
- Enforce MFA on all Microsoft Intune and Entra ID administrative accounts immediately
- Audit and restrict Global Administrator and Intune Administrator account assignments
- Block known Handala VPS IPs at perimeter: 82.25.35.25, 31.57.35.223, 107.189.19.52, 146.185.219.235
- Monitor Intune audit logs for RemoteWipe and FactoryReset actions — alert on 5+ wipe commands in 1 hour
- Instruct employees to unenroll personal BYOD devices from corporate MDM until threat is contained
- Verify immutable offline backups exist for all critical systems
Workarounds
- Disable remote wipe capability in Intune policies where not operationally required
- Restrict RDP access and disable where unnecessary
- Block Starlink IP ranges and Iranian IP ranges at perimeter where feasible
- Implement network segmentation between MDM management plane and general corporate network
Longer-term hardening
- Implement Just-in-Time (JIT) access using Microsoft Entra Privileged Identity Management (PIM) — eliminate standing admin privileges
- Require FIDO2 hardware security keys (e.g., YubiKeys) for all privileged account elevation
- Deploy Conditional Access policies restricting Intune admin access to corporate IP ranges only
- Reduce administrative session lifetimes to under 1 hour
- Enable Token Protection to cryptographically bind authentication tokens to devices
- Implement Data Loss Prevention (DLP) with exfiltration blocking
- Deploy EDR with behavioral detection for LSASS dumping and GPO abuse
- Segment administrative accounts — separate Intune admin from Global Admin roles
- Monitor for deployment of NetBird, VeraCrypt, and ADRecon on endpoints
Weaknesses (CWE) in Handala Hack (Void Manticore) Wiper Campaign via Microsoft
CWE-287, CWE-269, CWE-522
Timeline of Handala Hack (Void Manticore) Wiper Campaign via Microsoft
- Handala Hack persona first appears online, presenting as a pro-Palestinian hacktivist group
- Check Point Research publicly links Void Manticore to Handala Hack and Karma personas, attributing to Iran MOIS
- Void Manticore deploys BiBi Wiper variants against Israeli organizations, corrupting files with .BiBi extension
- Iran internet shutdown forces Handala operators to shift to Starlink IPs and direct Iranian IP connections, degrading OPSEC
- Joint US-Israeli military strikes on Iran commence, triggering escalation of retaliatory cyber operations
- Israel National Cyber Directorate issues warning that attackers gained access to corporate networks and are deleting servers
- US intelligence community ramps up warnings of possible retaliatory cyberattacks by Iran against US entities
- Handala claims responsibility via Telegram, stating retaliation for US bombing and claiming 50TB data exfiltration
- Handala Hack executes devastating wiper attack on Stryker Corporation via Microsoft Intune abuse, wiping 200,000+ devices across 79 countries
- Unit 42 and Check Point Research publish detailed technical analyses of Handala Hack TTPs and the Stryker attack
- As of 2026-05-29, Void Manticore/Handala (Iran MOIS, Storm-0842) remains active, breaching its own US-attack pause by leaking US Marines data and continuing Israel ops post-ceasefire. No CVE to patch; CISA/Microsoft issued Intune hardening guidance but the identity/remote-wipe abuse stays viable in unhardened tenants. (High confidence.)
Sources cited for Handala Hack (Void Manticore) Wiper Campaign via Microsoft
- Unit 42 - Insights Into the Increased Risk of Wiper Attacks by Handala Hack
- Check Point Research - Handala Hack: Unveiling Group's Modus Operandi
- Krebs on Security - Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
- BleepingComputer - Medtech Giant Stryker Offline After Iran-Linked Wiper Malware Attack
- Check Point Research - Bad Karma, No Justice: Void Manticore Destructive Activities in Israel
- Zetter Zero Day - Iranian Hacktivists Strike Medical Device Maker Stryker in Severe Attack
- NBC News - Iran Appears to Have Conducted Significant Cyberattack Against US Company
- Cybersecurity Dive - US Entities Face Heightened Cyber Risk Related to Iran War
- Nextgov/FCW - Suspected Pro-Iran Hacker Group Tied to Stryker Cyberattack
- SOCRadar - Dark Web Profile: Storm-842 (Void Manticore)
Threats related to Handala Hack (Void Manticore) Wiper Campaign via Microsoft
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
Detection coverage for TL-2026-0220
As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0220 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.