Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack) — Threadlinqs Intelligence
As of 2026-05-30, Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack) is a critical-severity apt threat attributed to Void Manticore (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0237 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: Void Manticore · Iran · DESTRUCTION
Iranian MOIS-linked threat group Void Manticore, operating under the Handala hacktivist persona, compromised Microsoft Intune administrator credentials to issue remote wipe commands across 200,000+
On March 11, 2026, the Iranian state-aligned threat group Void Manticore — operating through its Handala hacktivist persona — executed a devastating wiper attack against Stryker Corporation, a Fortune 500 medical technology company with $25 billion in annual revenue and 56,000 employees across 61+ countries. The attack represents a fundamental evolution in Iranian destructive cyber operations: rather than deploying custom wiper malware (Shamoon, ZeroCleare, BiBi), the attackers compromised highly privileged Microsoft Entra ID administrator credentials and weaponized Stryker's own Microsoft Intune MDM platform to issue legitimate remote wipe and factory reset commands to the entire managed device fleet.
The attack simultaneously wiped over 200,000 corporate laptops, servers, and BYOD-enrolled mobile devices across 79 countries. Because the wipe commands originated from authenticated, authorized administrative channels within Microsoft's trusted cloud infrastructure, EDR and antivirus platforms remained entirely blind to the activity — no malicious binary was dropped, no anomalous disk-writing processes were initiated, and no exploit was triggered.
Void Manticore (tracked as Storm-0842/Storm-1084 by Microsoft, Banished Kitten by CrowdStrike, and COBALT MYSTIQUE) operates under the supervision of Iran's Ministry of Intelligence and Security (MOIS), specifically the Internal Security Deputy Counter-Terrorism Division. The group emerged in late 2023 and has been assessed with high confidence by Unit 42, Check Point Research, and Microsoft as a state-directed front rather than an independent hacktivist operation.
The Stryker attack was explicitly motivated by geopolitical retaliation — Handala cited the February 28, 2026 military strike on an Iranian school that killed 175+ people, and framed Stryker as a 'Zionist-rooted corporation' due to its 2019 acquisition of Israeli company OrthoSpace. The attackers claimed to have exfiltrated 50 terabytes of data prior to the destructive phase, though this remains unconfirmed by independent verification.
The healthcare impact was severe: Stryker's LifeNet EKG transmission system was disrupted nationwide in the United States, forcing Maryland EMS to issue emergency manual ECG consultation protocols. 5,000+ employees in Ireland were sent home. Hospitals globally were unable to order surgical supplies through Stryker's systems. Employees who had enrolled personal phones for work access via BYOD also lost all personal data when their devices were factory reset.
This attack establishes a new threat model for enterprises: centralized cloud MDM platforms represent a Tier-0 administrative control plane whose compromise enables global-scale destruction in minutes without deploying any malware. The Iranian threat ecosystem — spanning Void Manticore, APT33/Curious Serpens, APT34/Evasive Serpens, Agrius/Agonizing Serpens, and MuddyWater/Boggy Serpens — has been converging on identity-based attack techniques, with 65% of initial access in recent incidents driven by credential compromise rather than vulnerability exploitation.
Historically, Iranian destructive operations evolved through distinct phases: the 2012 Shamoon attack on Saudi Aramco (MBR wipers using Eldos RawDisk driver), the 2016-2019 'blunt instruments' era (ZeroCleare, Dustman targeting energy/industrial), the 2020-2022 ransomware-as-smokescreen period (Apostle, Fantasy with plausible deniability), and the 2023-2025 hacktivist persona era (BiBi, Hatef, Hamsa cross-platform wipers with Telegram-based psychological operations). The 2026 MDM weaponization represents the latest and most dangerous evolution — identity-based destruction that renders traditional malware detection irrelevant.
Check Point Research documented Handala's broader operational toolkit including custom executable wipers (handala.exe) with MBR overwrite capability, PowerShell-based wipers targeting C:\Users recursively, VeraCrypt disk encryption for drive-level destruc
Weaknesses (CWE)
CWE-269, CWE-250, CWE-284
Target sectors: healthcare, medical-devices, energy, industrial, technology, higher-education, government, telecommunications
Target regions: North America, Europe, Middle East, Israel, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1566, T1078, T1078, T1133, T1199, T1059, T1047, T1053, T1648, T1037