Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation
Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and (TL-2026-0268), also tracked as Stryker Incident, is a critical-severity advanced persistent threat campaign, first published 2026-03-22. It is attributed to Handala (Iran) with high confidence, affects Microsoft Entra ID (Azure Active Directory), maps to 20 MITRE ATT&CK techniques (T1003, T1021, T1037), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0268
- Threat ID
- TL-2026-0268
- Also known as
- Stryker Incident, Operation Handala, Stryker Wiper Attack
- Severity
- CRITICAL
- Status
- MONITORING
- Category
- APT
- First published
- 2026-03-22
- Last reviewed
- 2026-03-22
- Attribution
- Handala
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- healthcare, medical-devices, manufacturing, critical-infrastructure
- Target regions
- North America, Europe, Asia Pacific, Global (79 countries)
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and
Malware and tooling: ADRecon, NetBird, VeraCrypt
Iranian threat actor Handala, assessed as a persona of Void Manticore directed by Iran's Ministry of Intelligence and Security (MOIS), compromised Microsoft Entra ID Global Administrator credentials at Stryker Corporation and weaponized Microsoft Intune's built-in Remote Wipe feature to destroy over 200,000 devices across 79 countries without deploying any malware. The attack disrupted manufacturing, ordering, shipping, and healthcare-adjacent systems globally.
How Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and works
On March 11, 2026, Iranian-linked threat actor Handala executed a devastating identity control plane attack against Stryker Corporation, one of the world's largest medical device manufacturers (56,000 employees, $25.1B annual revenue). The attack represents a paradigm shift in destructive cyber operations — leveraging legitimate SaaS administration capabilities as a weapon rather than deploying custom malware.
The attack chain began months before the destructive phase, with initial access likely achieved through one of three vectors: adversary-in-the-middle (AiTM) phishing targeting IT administrators to capture authenticated session tokens after MFA completion, VPN credential brute-force with subsequent lateral movement and credential harvesting, or supply chain compromise through a managed service provider with inherited privileged access. Check Point Research documented Handala's broader operational pattern of targeting IT and service providers for credential theft, with hundreds of brute-force attempts against organizational VPN infrastructure observed across multiple campaigns.
Once inside Stryker's Microsoft tenant, the attackers compromised or obtained Global Administrator credentials for Microsoft Entra ID (formerly Azure AD). They created a new Global Administrator account for persistence, ensuring continued access even if the original compromised account was reset. With Global Administrator privileges, the attackers had unrestricted access to Microsoft Intune, the enterprise endpoint management platform managing every enrolled device in Stryker's global fleet.
Between approximately 05:00 and 08:00 UTC on March 11, 2026, the attackers executed Intune's built-in Remote Wipe (factory reset) command against all enrolled devices simultaneously. Over 200,000 systems were rendered inoperable — corporate laptops, mobile devices, virtual servers, and personal BYOD-enrolled phones. The wipe destroyed not only corporate data but personal photos, eSIMs, banking authenticator apps, and locally stored files on BYOD devices.
The operational impact was immediate and global: Stryker's 5,500-person Ireland hub sent all employees home; Maryland paramedics lost LifeNet ECG transmission capability and fell back to radio consultations; surgical supply ordering systems went offline; the company's US headquarters declared a building emergency. WhatsApp became the primary employee communication channel as corporate systems were destroyed.
Handala claimed responsibility the same day, publishing propaganda with the group's signature barefoot boy logo and stating the attack was retaliation for a February 28, 2026 missile strike on an Iranian school that killed at least 175 people, mostly children. The group also claimed exfiltration of data, though specifics remain unconfirmed.
Multiple threat intelligence vendors (Check Point, CrowdStrike, Microsoft, Palo Alto Networks Unit 42) converge on attributing Handala as an operational persona of Void Manticore (also tracked as Storm-0842, Banished Kitten, and Dune), a destructive operations unit within Iran's MOIS Counter-Terrorism Division. Void Manticore historically operated the Homeland Justice persona targeting Albania and the Karma persona for data leaks, with Handala becoming the primary public-facing identity from late 2023 onward.
On March 18, 2026, CISA issued an advisory urging all organizations to harden endpoint management systems, specifically recommending Multi Admin Approval for destructive Intune actions, phishing-resistant MFA on all privileged accounts, role-based access control with least privilege, and Privileged Identity Management for just-in-time access elevation. Microsoft concurrently released updated Intune security best practices.
This incident demonstrates that identity compromise is now the most impactful initial access vector for destructive operations. As Push Security noted in their analysis: the attack proves that operators are creative and pragmatic — if the path of least resistance is a compromised admin credential and a legitimate MDM feature, no serious attacker will deploy custom wiper malware instead.
MITRE ATT&CK techniques used in TL-2026-0268
credential-access
T1003 OS Credential Dumping; T1110 Brute Force; T1557 Adversary-in-the-Middle
lateral-movement
persistence
T1037 Boot or Logon Initialization Scripts; T1098 Account Manipulation; T1133 External Remote Services
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools
defense-evasion
T1078 Valid Accounts; T1484 Domain or Tenant Policy Modification
discovery
initial-access
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1529 System Shutdown/Reboot; T1561 Disk Wipe
command-and-control
defense-impairment
Affected products and versions in Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and
- Microsoft — Entra ID (Azure Active Directory)
Vulnerable versions: All versions without MAA and phishing-resistant MFA
Fixed in: With MAA, PIM, and FIDO2 MFA configured - Microsoft — Intune
Vulnerable versions: All versions without Multi Admin Approval
Fixed in: With MAA and RBAC least privilege configured - Stryker Corporation — Global IT Infrastructure
Vulnerable versions: 200,000+ enrolled devices across 79 countries
Remediation for Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and
Immediate actions
- Enable Multi Admin Approval (MAA) for all destructive Intune actions including device wipe, factory reset, application removal, and script deployment
- Enforce phishing-resistant MFA (FIDO2/passkeys) on all Global Administrator and Intune Administrator accounts immediately
- Audit all Entra ID privileged role assignments — remove unnecessary Global Administrator accounts
- Review Intune audit logs for bulk device wipe commands or unusual admin activity
- Implement Conditional Access policies restricting admin portal access to managed devices and trusted locations
- Block legacy authentication protocols that bypass MFA
Workarounds
- Restrict Intune wipe capabilities to a dedicated security operations role with mandatory second-person approval
- Configure bulk action thresholds that require escalated approval for operations affecting more than 5 devices
- Maintain offline backups of critical device configurations and enrollment profiles
Longer-term hardening
- Deploy Privileged Identity Management (PIM) for just-in-time elevation of all Entra ID administrative roles
- Implement scope tags in Intune to segment device management by region and business unit
- Integrate Entra ID sign-in logs with Intune audit logs for real-time correlation of admin actions
- Establish 24/7 approver roster for dual-control requirements on destructive operations
- Deploy behavioral anomaly detection on admin sessions to flag unusual geographic or temporal access patterns
- Test Autopilot device rebuild flows and maintain manual fallback procedures for mass recovery scenarios
- Treat Entra ID and Intune as Tier 0 assets with dedicated cloud-only administrative accounts on privileged access workstations
Weaknesses (CWE) in Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and
CWE-269, CWE-250, CWE-284, CWE-308
Timeline of Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and
- Missile strike hits Iranian school, killing at least 175 people (mostly children) — cited by Handala as retaliation motivation for the Stryker attack
- Active adversary-in-the-middle phishing campaigns targeting Stryker IT administrators documented by threat intelligence firms
- Maryland LifeNet paramedic ECG transmission system goes offline — EMS falls back to radio consultations for cardiac emergencies
- Handala publicly claims responsibility for the attack, displaying signature barefoot boy logo on defaced Stryker login pages and publishing manifesto
- Between 05:00-08:00 UTC, Handala executes Intune Remote Wipe destroying 200,000+ devices across 79 countries — Stryker Ireland hub sends 5,500 employees home
- Stryker US headquarters voicemail declares building emergency; LifeNet service disruptions confirmed
- Unit 42 (Palo Alto Networks) publishes assessment attributing Handala as MOIS-directed front group for Void Manticore
- Stryker publicly confirms Intune-based mass device wipe as attack method, states no malware was deployed, restoration underway
- CISA issues alert urging all organizations to harden endpoint management systems — recommends Multi Admin Approval, phishing-resistant MFA, RBAC least privilege
- Microsoft releases updated Intune security best practices including MAA implementation, Conditional Access hardening, and PIM deployment guidance
- Sygnia and Check Point Research publish detailed technical analyses of the attack methodology, Void Manticore TTPs, and IOCs from broader Handala operations
- As of 2026-05-29, the Stryker wiper campaign has concluded but the threat persists: Handala/Void Manticore (MOIS) remains active claiming new attacks despite a DOJ domain seizure, the killing of its persona leader, and Iran's sub-4% connectivity degrading operations. The Intune/Entra abuse has no patch (credential/config abuse), and CISA/Microsoft hardening guidance only mitigates it, so unhardened tenants stay exposed.
Sources cited for Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and
- Sygnia - Lessons from the Stryker Incident: Identity Control Plane Attack
- CISA - Urges Endpoint Management System Hardening After Cyberattack
- Check Point Research - Handala Hack: Unveiling Group's Modus Operandi
- Krebs on Security - Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
- Push Security - Analyzing Iran-nexus TTP Evolution in 2026
- Stryker Confirms Intune Wipe and Containment Measures
- Lumos - The Stryker Hack: How One Compromised Admin Account Led to 200,000 Wiped Devices
- SOCRadar - Dark Web Profile: Handala Hack
- Check Point Research - Iranian MOIS Actors and the Cyber Crime Connection
- BleepingComputer - CISA Warns Businesses to Secure Microsoft Intune After Stryker Breach
- Cybersecurity Dive - Stryker Attack Raises Concerns About Device Management Tools
- Unit 42 - Handala Attribution Assessment
Threats related to Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device Wiping (Stryker Attack)
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
Detection coverage for TL-2026-0268
As of 2026-03-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0268 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.