Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation — Threadlinqs Intelligence
As of 2026-05-30, Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker Corporation is a critical-severity apt threat attributed to Handala (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0268 · Severity: CRITICAL · Status: MONITORING · Category: APT
Attribution: Handala · Iran · DESTRUCTION
Iranian threat actor Handala, assessed as a persona of Void Manticore directed by Iran's Ministry of Intelligence and Security (MOIS), compromised Microsoft Entra ID Global Administrator credentials
On March 11, 2026, Iranian-linked threat actor Handala executed a devastating identity control plane attack against Stryker Corporation, one of the world's largest medical device manufacturers (56,000 employees, $25.1B annual revenue). The attack represents a paradigm shift in destructive cyber operations — leveraging legitimate SaaS administration capabilities as a weapon rather than deploying custom malware.
The attack chain began months before the destructive phase, with initial access likely achieved through one of three vectors: adversary-in-the-middle (AiTM) phishing targeting IT administrators to capture authenticated session tokens after MFA completion, VPN credential brute-force with subsequent lateral movement and credential harvesting, or supply chain compromise through a managed service provider with inherited privileged access. Check Point Research documented Handala's broader operational pattern of targeting IT and service providers for credential theft, with hundreds of brute-force attempts against organizational VPN infrastructure observed across multiple campaigns.
Once inside Stryker's Microsoft tenant, the attackers compromised or obtained Global Administrator credentials for Microsoft Entra ID (formerly Azure AD). They created a new Global Administrator account for persistence, ensuring continued access even if the original compromised account was reset. With Global Administrator privileges, the attackers had unrestricted access to Microsoft Intune, the enterprise endpoint management platform managing every enrolled device in Stryker's global fleet.
Between approximately 05:00 and 08:00 UTC on March 11, 2026, the attackers executed Intune's built-in Remote Wipe (factory reset) command against all enrolled devices simultaneously. Over 200,000 systems were rendered inoperable — corporate laptops, mobile devices, virtual servers, and personal BYOD-enrolled phones. The wipe destroyed not only corporate data but personal photos, eSIMs, banking authenticator apps, and locally stored files on BYOD devices.
The operational impact was immediate and global: Stryker's 5,500-person Ireland hub sent all employees home; Maryland paramedics lost LifeNet ECG transmission capability and fell back to radio consultations; surgical supply ordering systems went offline; the company's US headquarters declared a building emergency. WhatsApp became the primary employee communication channel as corporate systems were destroyed.
Handala claimed responsibility the same day, publishing propaganda with the group's signature barefoot boy logo and stating the attack was retaliation for a February 28, 2026 missile strike on an Iranian school that killed at least 175 people, mostly children. The group also claimed exfiltration of data, though specifics remain unconfirmed.
Multiple threat intelligence vendors (Check Point, CrowdStrike, Microsoft, Palo Alto Networks Unit 42) converge on attributing Handala as an operational persona of Void Manticore (also tracked as Storm-0842, Banished Kitten, and Dune), a destructive operations unit within Iran's MOIS Counter-Terrorism Division. Void Manticore historically operated the Homeland Justice persona targeting Albania and the Karma persona for data leaks, with Handala becoming the primary public-facing identity from late 2023 onward.
On March 18, 2026, CISA issued an advisory urging all organizations to harden endpoint management systems, specifically recommending Multi Admin Approval for destructive Intune actions, phishing-resistant MFA on all privileged accounts, role-based access control with least privilege, and Privileged Identity Management for just-in-time access elevation. Microsoft concurrently released updated Intune security best practices.
This incident demonstrates that identity compromise is now the most impactful initial access vector for destructive operations. As Push Security noted in their analysis: the attack proves that operators are creative and pragmatic — if the p
Weaknesses (CWE)
CWE-269, CWE-250, CWE-284, CWE-308
Target sectors: healthcare, medical-devices, manufacturing, critical-infrastructure
Target regions: North America, Europe, Asia Pacific, Global (79 countries)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1078, T1078, T1133, T1199, T1072, T1059, T1053, T1098, T1037, T1484