logo

Who Is Handala — The Iran-Linked Ghost Group That Just Wiped 200K Stryker Devices

ID: a8f40bac-477b-5c5c-ad93-911d10bef667

STIX ID: report--a8f40bac-477b-5c5c-ad93-911d10bef667

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-03-12

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

A destructive cyberattack attributed to the Handala group (linked by analysts to MOIS-affiliated Void Manticore) disrupted Stryker’s global Microsoft environment: attackers reportedly abused Microsoft Intune to remotely wipe managed endpoints, claimed to have exfiltrated ~50 TB of data and wiped over 200,000 devices, and forced operational shutdowns across multiple countries; reporting describes use of Rhadamanthys infostealer, custom wipers, living‑off‑the‑land lateral movement, and pre-positioned access to maximize impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.