Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)
Iranian APT Identity Weaponization (TL-2026-0237), also tracked as Stryker Wiper Attack, is a critical-severity advanced persistent threat campaign, first published 2026-03-16. It is attributed to Void Manticore (Iran) with high confidence, affects Microsoft Microsoft Intune, maps to 30 MITRE ATT&CK techniques (T1003, T1005, T1020), and is covered by 9 detection rules and 32 indicators of compromise.
Key facts for TL-2026-0237
- Threat ID
- TL-2026-0237
- Also known as
- Stryker Wiper Attack, Operation Handala, Handala MDM Attack
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-16
- Last reviewed
- 2026-03-16
- Attribution
- Void Manticore
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- healthcare, medical-devices, energy, industrial, technology, higher-education, government, telecommunications
- Target regions
- North America, Europe, Middle East, Israel, Global
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in Iranian APT Identity Weaponization
Malware and tooling: BiBi Wiper, Handala Wiper, ADRecon, NetBird, VeraCrypt
Iranian MOIS-linked threat group Void Manticore, operating under the Handala hacktivist persona, compromised Microsoft Intune administrator credentials to issue remote wipe commands across 200,000+ corporate and BYOD devices at Stryker Corporation, representing a paradigm shift from custom wiper malware to identity-based destruction via legitimate cloud management platforms that bypasses traditional endpoint security.
How Iranian APT Identity Weaponization works
On March 11, 2026, the Iranian state-aligned threat group Void Manticore — operating through its Handala hacktivist persona — executed a devastating wiper attack against Stryker Corporation, a Fortune 500 medical technology company with $25 billion in annual revenue and 56,000 employees across 61+ countries. The attack represents a fundamental evolution in Iranian destructive cyber operations: rather than deploying custom wiper malware (Shamoon, ZeroCleare, BiBi), the attackers compromised highly privileged Microsoft Entra ID administrator credentials and weaponized Stryker's own Microsoft Intune MDM platform to issue legitimate remote wipe and factory reset commands to the entire managed device fleet.
The attack simultaneously wiped over 200,000 corporate laptops, servers, and BYOD-enrolled mobile devices across 79 countries. Because the wipe commands originated from authenticated, authorized administrative channels within Microsoft's trusted cloud infrastructure, EDR and antivirus platforms remained entirely blind to the activity — no malicious binary was dropped, no anomalous disk-writing processes were initiated, and no exploit was triggered.
Void Manticore (tracked as Storm-0842/Storm-1084 by Microsoft, Banished Kitten by CrowdStrike, and COBALT MYSTIQUE) operates under the supervision of Iran's Ministry of Intelligence and Security (MOIS), specifically the Internal Security Deputy Counter-Terrorism Division. The group emerged in late 2023 and has been assessed with high confidence by Unit 42, Check Point Research, and Microsoft as a state-directed front rather than an independent hacktivist operation.
The Stryker attack was explicitly motivated by geopolitical retaliation — Handala cited the February 28, 2026 military strike on an Iranian school that killed 175+ people, and framed Stryker as a 'Zionist-rooted corporation' due to its 2019 acquisition of Israeli company OrthoSpace. The attackers claimed to have exfiltrated 50 terabytes of data prior to the destructive phase, though this remains unconfirmed by independent verification.
The healthcare impact was severe: Stryker's LifeNet EKG transmission system was disrupted nationwide in the United States, forcing Maryland EMS to issue emergency manual ECG consultation protocols. 5,000+ employees in Ireland were sent home. Hospitals globally were unable to order surgical supplies through Stryker's systems. Employees who had enrolled personal phones for work access via BYOD also lost all personal data when their devices were factory reset.
This attack establishes a new threat model for enterprises: centralized cloud MDM platforms represent a Tier-0 administrative control plane whose compromise enables global-scale destruction in minutes without deploying any malware. The Iranian threat ecosystem — spanning Void Manticore, APT33/Curious Serpens, APT34/Evasive Serpens, Agrius/Agonizing Serpens, and MuddyWater/Boggy Serpens — has been converging on identity-based attack techniques, with 65% of initial access in recent incidents driven by credential compromise rather than vulnerability exploitation.
Historically, Iranian destructive operations evolved through distinct phases: the 2012 Shamoon attack on Saudi Aramco (MBR wipers using Eldos RawDisk driver), the 2016-2019 'blunt instruments' era (ZeroCleare, Dustman targeting energy/industrial), the 2020-2022 ransomware-as-smokescreen period (Apostle, Fantasy with plausible deniability), and the 2023-2025 hacktivist persona era (BiBi, Hatef, Hamsa cross-platform wipers with Telegram-based psychological operations). The 2026 MDM weaponization represents the latest and most dangerous evolution — identity-based destruction that renders traditional malware detection irrelevant.
Check Point Research documented Handala's broader operational toolkit including custom executable wipers (handala.exe) with MBR overwrite capability, PowerShell-based wipers targeting C:\Users recursively, VeraCrypt disk encryption for drive-level destruction, NetBird mesh networking for C2 tunneling, LSASS memory dumping via rundll32/comsvcs.dll, ADRecon for Active Directory enumeration, and Group Policy modification for domain-wide wiper distribution. The group's operational security has notably declined in 2026, with direct connections from Iranian IP addresses observed and Starlink IP usage following January internet restrictions.
MITRE ATT&CK techniques used in TL-2026-0237
credential-access
T1003 OS Credential Dumping; T1110 Brute Force
collection
exfiltration
lateral-movement
defense-evasion
T1027 Obfuscated Files or Information; T1078 Valid Accounts; T1218 System Binary Proxy Execution; T1484 Domain or Tenant Policy Modification; T1497 Virtualization/Sandbox Evasion
persistence
T1037 Boot or Logon Initialization Scripts; T1098 Account Manipulation; T1133 External Remote Services
execution
T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1648 Serverless Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
discovery
command-and-control
T1102 Web Service; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
initial-access
T1199 Trusted Relationship; T1566 Phishing
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1491 Defacement; T1531 Account Access Removal; T1561 Disk Wipe
reconnaissance
Affected products and versions in Iranian APT Identity Weaponization
- Microsoft — Microsoft Intune
Vulnerable versions: All versions with standing admin privileges
Fixed in: N/A - configuration-based mitigation required - Microsoft — Microsoft Entra ID (Azure AD)
Vulnerable versions: All versions
Fixed in: N/A - requires PIM and conditional access hardening - Stryker — LifeNet EKG Transmission System
Vulnerable versions: Intune-managed deployments
Fixed in: N/A - Multiple — Cloud-based MDM/RMM Platforms
Vulnerable versions: Any platform with standing admin privileges and no MAA for destructive operations
Fixed in: N/A - configuration hardening required
Remediation for Iranian APT Identity Weaponization
Immediate actions
- Audit all Entra ID Global Administrator and Intune Administrator role assignments immediately
- Enforce phishing-resistant hardware MFA (FIDO2/YubiKey/Windows Hello) for all administrative accounts — reject software TOTP and SMS
- Implement conditional access policies restricting admin access to compliant managed devices from named locations only
- Create SIEM alerts for bulk MDM wipe commands (threshold: 3-5+ devices in short timeframe)
- Verify offline air-gapped immutable backups exist and test restoration procedures
- Stream Entra ID and Intune audit logs to tenant-independent external SIEM
- Block known Handala C2 infrastructure at perimeter: 82.25.35.25, 31.57.35.223, 107.189.19.52
Workarounds
- Restrict BYOD enrollment scope to minimize personal device exposure in wipe scenarios
- Implement network segmentation between MDM management plane and operational technology
- Establish manual fallback procedures for critical services dependent on managed infrastructure (e.g., EKG transmission, surgical supply ordering)
- Pre-position OS deployment infrastructure for mass re-imaging scenarios
Longer-term hardening
- Deploy Privileged Identity Management (PIM) with just-in-time access — zero standing admin privileges with maximum 4-8 hour activation windows
- Implement multi-administrator approval (MAA) for all destructive MDM operations (remote wipe, factory reset)
- Establish dedicated Privileged Access Workstations (PAWs) for all cloud administrative functions
- Treat MDM/RMM management plane as Tier-0 infrastructure equivalent to Domain Controllers
- Deploy Data Security Posture Management (DSPM) for sensitive data classification and DLP with exfiltration monitoring
- Conduct wiper-specific tabletop exercises including offline communications and mass device re-imaging capacity planning
- Implement separation of duties for destructive capabilities — no single account should be able to wipe entire fleet
- Reduce session lifetimes for sensitive administrative portals to under 1 hour
Weaknesses (CWE) in Iranian APT Identity Weaponization
CWE-269, CWE-250, CWE-284
Timeline of Iranian APT Identity Weaponization
- Shamoon wiper attacks Saudi Aramco, establishing Iranian destructive cyber operations capability — 35,000 workstations destroyed
- ZeroCleare and Dustman wipers deployed against Middle Eastern energy and industrial sectors, evolving beyond Shamoon
- Void Manticore deploys CL Wiper against Albanian government via SharePoint exploitation under Homeland Justice persona
- Handala hacktivist persona emerges; BiBi-Linux and BiBi-Windows cross-platform wipers deployed against Israeli targets
- U.S. Treasury sanctions Yahya Hosseini Panjaki (MOIS deputy minister) for directing Void Manticore destructive operations
- Iran internet connectivity drops to 1-4% following military strikes, forcing Handala operators to use Starlink IPs and degrading operational security
- Military strike on Iranian school kills 175+ people — cited by Handala as justification for retaliatory cyber operations
- Israel National Cyber Directorate issues warning about imminent Iranian wiper attacks targeting Israeli organizations
- Handala claims responsibility via Telegram manifesto, alleging 50TB data exfiltration and framing Stryker as Zionist-rooted corporation due to OrthoSpace acquisition
- Handala executes devastating attack on Stryker Corporation — compromises Entra ID admin credentials, weaponizes Microsoft Intune to wipe 200,000+ devices across 79 countries
- Unit 42 and Check Point Research publish initial technical analysis of Handala operations and Stryker attack methodology
- Maryland EMS reports statewide LifeNet EKG transmission system disruption; emergency manual ECG protocols activated for cardiac care
- Unit 42 publishes comprehensive analysis of Iranian cyber threat evolution from MBR wipers to identity weaponization via MDM platform abuse
- As of 2026-05-29, TL-2026-0237 remains ACTIVE: Void Manticore/Handala (Iran/MOIS) is still operating, expanding past the March Stryker Intune-wipe into a late-April doxxing campaign vs US Marines in Bahrain, with no disruption reported. The MDM/identity-weaponization technique has no CVE and only config-based mitigation, so it stays viable enterprise-wide.
Sources cited for Iranian APT Identity Weaponization
- Unit 42: Iranian Cyber Threat Evolution - From MBR Wipers to Identity Weaponization
- Unit 42: Increased Risk of Wiper Attacks from Handala Hack
- Unit 42: Threat Brief - March 2026 Escalation of Iranian Cyber Risk
- Check Point Research: Handala Hack - Unveiling Group's Modus Operandi
- Krebs on Security: Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
- Splunk: Handala's Wiper - Threat Analysis and Detections
- CSA: Handala Wiper Attack on Stryker - MOIS Hacktivists Destroy Medical Operations
- 7ai: Stryker Wiper Attack - What Security Teams Need to Know Now
- SecureWorld: Iran-Linked Hacktivist Group Weaponizes Microsoft Intune in Destructive Wiper Attack
- Tom's Hardware: Iran Hacking Group Claims Attack on Stryker - 200K+ Devices Wiped
- Presidio: When the Wiper Is the Product - Nation-state MDM Attacks
- Deepwatch: Handala Cyber Alert - Prevent MDM Wipes and Wiper Attacks
Threats related to Iranian APT Identity Weaponization
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
Detection coverage for TL-2026-0237
As of 2026-03-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0237 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.