logo

Epic Fury Update: Stryker Attack Highlights Handala's Shift from Espionage to Disruption

ID: 1a1c15be-a59c-5112-b2b9-b45ad0c7a6a4

STIX ID: report--1a1c15be-a59c-5112-b2b9-b45ad0c7a6a4

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
90/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

Author: Arthur Erzberger

...
...

LevelBlue reports that on March 11, 2026 Stryker experienced a global cyberattack impacting its Microsoft environment that the Iran-linked Handala Hack Team claimed responsibility for; attackers appear to have abused Intune/MDM admin access (and used a custom wiper) to remotely wipe or disable managed devices worldwide, creating major operational and business-continuity risk for the medical-technology firm. The report assesses Handala as an Iran-aligned persona/APT, outlines likely initial-access methods (phishing, session hijacking, valid account abuse), documents observed destructive techniques, and recommends identity- and privilege-focused mitigations (phishing-resistant MFA, least privilege, dedicated admin workstations, device recovery testing) while LevelBlue elevates monitoring and incident response readiness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.