Who Is Handala — The Iran-Linked Ghost Group That Just Wiped 200K Stryker Devices
ID: a8f40bac-477b-5c5c-ad93-911d10bef667
STIX ID: report--a8f40bac-477b-5c5c-ad93-911d10bef667
Feed Name: The Cyber Express
A destructive cyberattack attributed to the Handala group (linked by analysts to MOIS-affiliated Void Manticore) disrupted Stryker’s global Microsoft environment: attackers reportedly abused Microsoft Intune to remotely wipe managed endpoints, claimed to have exfiltrated ~50 TB of data and wiped over 200,000 devices, and forced operational shutdowns across multiple countries; reporting describes use of Rhadamanthys infostealer, custom wipers, living‑off‑the‑land lateral movement, and pre-positioned access to maximize impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
