Stryker wipe used Microsoft Intune abuse, not custom wiper malware
Assessment
Multiple outlets initially framed the Stryker incident as a "wiper attack," implying purpose-built destructive malware. KrebsOnSecurity reported, based on a single anonymous source "with knowledge of the attack," that the actual mechanism was abuse of Microsoft Intune's legitimate remote-wipe administrative function against all enrolled devices simultaneously — corroborated only informally by a Reddit thread of self-identified Stryker employees describing urgent instructions to uninstall Intune. Stryker itself had not, at the time of that reporting, confirmed the specific mechanism. This is a meaningful technical distinction: it describes identity/access-control compromise of an admin console rather than malware deployment, with different detection and containment implications, but is carried in most coverage as settled fact.
Where this claim appeared
KrebsOnSecurity · 2026-03-11
https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/What “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
Handala Hack's HEAVYGRAM Backdoor (CHOSEN BRICK) Spies on Iranian Dissidents via Telegram C2Think this assessment is wrong? Report an error.