ThreatPaper
Assessed, Not Confirmed

Stryker wipe used Microsoft Intune abuse, not custom wiper malware

Assessment

Multiple outlets initially framed the Stryker incident as a "wiper attack," implying purpose-built destructive malware. KrebsOnSecurity reported, based on a single anonymous source "with knowledge of the attack," that the actual mechanism was abuse of Microsoft Intune's legitimate remote-wipe administrative function against all enrolled devices simultaneously — corroborated only informally by a Reddit thread of self-identified Stryker employees describing urgent instructions to uninstall Intune. Stryker itself had not, at the time of that reporting, confirmed the specific mechanism. This is a meaningful technical distinction: it describes identity/access-control compromise of an admin console rather than malware deployment, with different detection and containment implications, but is carried in most coverage as settled fact.

Where this claim appeared

KrebsOnSecurity · 2026-03-11

https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Handala Hack's HEAVYGRAM Backdoor (CHOSEN BRICK) Spies on Iranian Dissidents via Telegram C2

Think this assessment is wrong? Report an error.