Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation

Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and (TL-2026-0268), also tracked as Stryker Incident, is a critical-severity advanced persistent threat campaign, first published 2026-03-22. It is attributed to Handala (Iran) with high confidence, affects Microsoft Entra ID (Azure Active Directory), maps to 20 MITRE ATT&CK techniques (T1003, T1021, T1037), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-0268

Threat ID
TL-2026-0268
Also known as
Stryker Incident, Operation Handala, Stryker Wiper Attack
Severity
CRITICAL
Status
MONITORING
Category
APT
First published
2026-03-22
Last reviewed
2026-03-22
Attribution
Handala
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
healthcare, medical-devices, manufacturing, critical-infrastructure
Target regions
North America, Europe, Asia Pacific, Global (79 countries)
Detection rules
9
Indicators of compromise
22

Malware and tooling in Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and

Malware and tooling: ADRecon, NetBird, VeraCrypt

Iranian threat actor Handala, assessed as a persona of Void Manticore directed by Iran's Ministry of Intelligence and Security (MOIS), compromised Microsoft Entra ID Global Administrator credentials at Stryker Corporation and weaponized Microsoft Intune's built-in Remote Wipe feature to destroy over 200,000 devices across 79 countries without deploying any malware. The attack disrupted manufacturing, ordering, shipping, and healthcare-adjacent systems globally.

How Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and works

On March 11, 2026, Iranian-linked threat actor Handala executed a devastating identity control plane attack against Stryker Corporation, one of the world's largest medical device manufacturers (56,000 employees, $25.1B annual revenue). The attack represents a paradigm shift in destructive cyber operations — leveraging legitimate SaaS administration capabilities as a weapon rather than deploying custom malware.

The attack chain began months before the destructive phase, with initial access likely achieved through one of three vectors: adversary-in-the-middle (AiTM) phishing targeting IT administrators to capture authenticated session tokens after MFA completion, VPN credential brute-force with subsequent lateral movement and credential harvesting, or supply chain compromise through a managed service provider with inherited privileged access. Check Point Research documented Handala's broader operational pattern of targeting IT and service providers for credential theft, with hundreds of brute-force attempts against organizational VPN infrastructure observed across multiple campaigns.

Once inside Stryker's Microsoft tenant, the attackers compromised or obtained Global Administrator credentials for Microsoft Entra ID (formerly Azure AD). They created a new Global Administrator account for persistence, ensuring continued access even if the original compromised account was reset. With Global Administrator privileges, the attackers had unrestricted access to Microsoft Intune, the enterprise endpoint management platform managing every enrolled device in Stryker's global fleet.

Between approximately 05:00 and 08:00 UTC on March 11, 2026, the attackers executed Intune's built-in Remote Wipe (factory reset) command against all enrolled devices simultaneously. Over 200,000 systems were rendered inoperable — corporate laptops, mobile devices, virtual servers, and personal BYOD-enrolled phones. The wipe destroyed not only corporate data but personal photos, eSIMs, banking authenticator apps, and locally stored files on BYOD devices.

The operational impact was immediate and global: Stryker's 5,500-person Ireland hub sent all employees home; Maryland paramedics lost LifeNet ECG transmission capability and fell back to radio consultations; surgical supply ordering systems went offline; the company's US headquarters declared a building emergency. WhatsApp became the primary employee communication channel as corporate systems were destroyed.

Handala claimed responsibility the same day, publishing propaganda with the group's signature barefoot boy logo and stating the attack was retaliation for a February 28, 2026 missile strike on an Iranian school that killed at least 175 people, mostly children. The group also claimed exfiltration of data, though specifics remain unconfirmed.

Multiple threat intelligence vendors (Check Point, CrowdStrike, Microsoft, Palo Alto Networks Unit 42) converge on attributing Handala as an operational persona of Void Manticore (also tracked as Storm-0842, Banished Kitten, and Dune), a destructive operations unit within Iran's MOIS Counter-Terrorism Division. Void Manticore historically operated the Homeland Justice persona targeting Albania and the Karma persona for data leaks, with Handala becoming the primary public-facing identity from late 2023 onward.

On March 18, 2026, CISA issued an advisory urging all organizations to harden endpoint management systems, specifically recommending Multi Admin Approval for destructive Intune actions, phishing-resistant MFA on all privileged accounts, role-based access control with least privilege, and Privileged Identity Management for just-in-time access elevation. Microsoft concurrently released updated Intune security best practices.

This incident demonstrates that identity compromise is now the most impactful initial access vector for destructive operations. As Push Security noted in their analysis: the attack proves that operators are creative and pragmatic — if the path of least resistance is a compromised admin credential and a legitimate MDM feature, no serious attacker will deploy custom wiper malware instead.

MITRE ATT&CK techniques used in TL-2026-0268

credential-access

T1003 OS Credential Dumping; T1110 Brute Force; T1557 Adversary-in-the-Middle

lateral-movement

T1021 Remote Services

persistence

T1037 Boot or Logon Initialization Scripts; T1098 Account Manipulation; T1133 External Remote Services

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools

defense-evasion

T1078 Valid Accounts; T1484 Domain or Tenant Policy Modification

discovery

T1087 Account Discovery

initial-access

T1199 Trusted Relationship

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1529 System Shutdown/Reboot; T1561 Disk Wipe

command-and-control

T1572 Protocol Tunneling

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and

  • Microsoft — Entra ID (Azure Active Directory)
    Vulnerable versions: All versions without MAA and phishing-resistant MFA
    Fixed in: With MAA, PIM, and FIDO2 MFA configured
  • Microsoft — Intune
    Vulnerable versions: All versions without Multi Admin Approval
    Fixed in: With MAA and RBAC least privilege configured
  • Stryker Corporation — Global IT Infrastructure
    Vulnerable versions: 200,000+ enrolled devices across 79 countries

Remediation for Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and

Immediate actions

  • Enable Multi Admin Approval (MAA) for all destructive Intune actions including device wipe, factory reset, application removal, and script deployment
  • Enforce phishing-resistant MFA (FIDO2/passkeys) on all Global Administrator and Intune Administrator accounts immediately
  • Audit all Entra ID privileged role assignments — remove unnecessary Global Administrator accounts
  • Review Intune audit logs for bulk device wipe commands or unusual admin activity
  • Implement Conditional Access policies restricting admin portal access to managed devices and trusted locations
  • Block legacy authentication protocols that bypass MFA

Workarounds

  • Restrict Intune wipe capabilities to a dedicated security operations role with mandatory second-person approval
  • Configure bulk action thresholds that require escalated approval for operations affecting more than 5 devices
  • Maintain offline backups of critical device configurations and enrollment profiles

Longer-term hardening

  • Deploy Privileged Identity Management (PIM) for just-in-time elevation of all Entra ID administrative roles
  • Implement scope tags in Intune to segment device management by region and business unit
  • Integrate Entra ID sign-in logs with Intune audit logs for real-time correlation of admin actions
  • Establish 24/7 approver roster for dual-control requirements on destructive operations
  • Deploy behavioral anomaly detection on admin sessions to flag unusual geographic or temporal access patterns
  • Test Autopilot device rebuild flows and maintain manual fallback procedures for mass recovery scenarios
  • Treat Entra ID and Intune as Tier 0 assets with dedicated cloud-only administrative accounts on privileged access workstations

Weaknesses (CWE) in Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and

CWE-269, CWE-250, CWE-284, CWE-308

Timeline of Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and

  • Missile strike hits Iranian school, killing at least 175 people (mostly children) — cited by Handala as retaliation motivation for the Stryker attack
  • Active adversary-in-the-middle phishing campaigns targeting Stryker IT administrators documented by threat intelligence firms
  • Maryland LifeNet paramedic ECG transmission system goes offline — EMS falls back to radio consultations for cardiac emergencies
  • Handala publicly claims responsibility for the attack, displaying signature barefoot boy logo on defaced Stryker login pages and publishing manifesto
  • Between 05:00-08:00 UTC, Handala executes Intune Remote Wipe destroying 200,000+ devices across 79 countries — Stryker Ireland hub sends 5,500 employees home
  • Stryker US headquarters voicemail declares building emergency; LifeNet service disruptions confirmed
  • Unit 42 (Palo Alto Networks) publishes assessment attributing Handala as MOIS-directed front group for Void Manticore
  • Stryker publicly confirms Intune-based mass device wipe as attack method, states no malware was deployed, restoration underway
  • CISA issues alert urging all organizations to harden endpoint management systems — recommends Multi Admin Approval, phishing-resistant MFA, RBAC least privilege
  • Microsoft releases updated Intune security best practices including MAA implementation, Conditional Access hardening, and PIM deployment guidance
  • Sygnia and Check Point Research publish detailed technical analyses of the attack methodology, Void Manticore TTPs, and IOCs from broader Handala operations
  • As of 2026-05-29, the Stryker wiper campaign has concluded but the threat persists: Handala/Void Manticore (MOIS) remains active claiming new attacks despite a DOJ domain seizure, the killing of its persona leader, and Iran's sub-4% connectivity degrading operations. The Intune/Entra abuse has no patch (credential/config abuse), and CISA/Microsoft hardening guidance only mitigates it, so unhardened tenants stay exposed.

Sources cited for Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and

Threats related to Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and

Detection coverage for TL-2026-0268

As of 2026-03-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0268 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats