Iran-linked operators allegedly combined MuddyWater pre-positioning with Handala destructive actions to cripple Stryker by abusing Microsoft Intune rather than deploying ransomware or a conventional wiper. The reports say attackers stole a privileged session, elevated access through an Entra ID PIM design gap that accepted an existing MFA claim, and then used Intune API bulk Wipe and Retire actions to erase about 200,000 devices across 61 countries, disrupting roughly 56,000 employees. Supporting reporting ties the operation to MOIS-linked infrastructure, malware including Dindoor and Fakeset, and data theft activity using Rclone before the destructive phase.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
On April 16, 2026, ThreatHunter.ai published a consolidated detection pack describing a two-phase Iranian state-linked operation against Stryker, attributing pre-positioning to MuddyWater and the destructive action to Handala. The release added a unified IOC and detection package focused on identity-layer abuse, Intune wipe activity, MuddyWater tooling, and related infrastructure.
The reported Red Menshen espionage campaign expanded into European telecommunications infrastructure and continued through March 2026. Operators moved from earlier footholds into sensitive mobile core environments, including OSS/NMS/EMS systems, Kubernetes-hosted 5G functions, and SCTP signaling-related areas.
On March 19, 2026, ThreatHunter.ai published an analysis arguing that CISA's endpoint management hardening advice did not fully address the March 11 Stryker attack path. It said Intune Multi Admin Approval alone was insufficient against a Global Admin and recommended no standing Global Admin roles, JIT PIM activation, and fresh phishing-resistant FIDO2 authentication at role activation.
ThreatHunter.ai released a second detection pack on March 14, 2026 covering MuddyWater pre-positioning, Entra ID PIM token-abuse risks, bulk wipe controls, stale-session privileged operations, and Rclone exfiltration. The package included Sigma rules, KQL hunting queries, and IOC updates tied to malware and infrastructure associated with the campaign.
At 3:30 AM EDT on March 11, 2026, attackers used a compromised Global Administrator session and Microsoft Intune API bulk Wipe and Retire actions to destroy about 200,000 systems across 61 countries, disrupting roughly 56,000 employees. The operation is described as destructive rather than ransomware-based and is attributed to Handala, with prior pre-positioning linked to MuddyWater.
A newly documented intrusion set attributed with high confidence to the China-nexus actor Red Menshen was active by at least July 2024, using BPFdoor and related tooling against telecommunications providers. The campaign initially involved compromises through edge devices, VPN access, and transport-network management systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
threathunter.ai
Open sourcemrtiepolo.medium.com
Open sourcethreathunter.ai
Open sourcethreathunter.ai
Open sourcehaxrob.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.