🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

~/ › Threat Intelligence › article

Threat Intelligence

The Intune Hijack: How The FAD Team Wiped 200,000 Middle East Systems in 2026

> By Haider | Aug 04, 2026 | 4 min read

⚠️ THREAT INTELLIGENCE ADVISORY:
The cyber threat landscape in the Middle East has crossed a dangerous threshold in 2026. Security researchers are tracking a massive escalation in destructive cyber operations orchestrated by The FAD Team (also known as the Fatimiyoun Cyber Team). Moving beyond data theft and ransomware extortion, this pro-Iranian hacktivist collective has demonstrated a terrifying capability: weaponizing legitimate enterprise IT management tools to execute catastrophic wiper malware attacks at an unprecedented scale.

The FAD Team

In one of the most severe incidents recorded in early 2026, The FAD Team successfully hijacked administrative controls to permanently erase data on over 200,000 endpoints. This campaign specifically targeted critical infrastructure, aviation networks, and Industrial Control Systems (ICS) across the Middle East. The sheer scale and speed of the destruction were not achieved through an advanced, undetected zero-day exploit, but rather through the malicious abuse of a tool designed to keep those very networks secure: Microsoft Intune.

> TABLE_OF_CONTENTS [toggle]

The Intune Hijack: Living Off the Land at Scale

Modern Endpoint Detection and Response (EDR) and Next-Generation Antivirus (NGAV) platforms have become exceptionally proficient at detecting bespoke malware payloads crossing the network perimeter. To bypass these defenses, The FAD Team relies heavily on “Living off the Land” (LotL) techniques-using the victim’s own administrative infrastructure against them.

In the 2026 campaigns, the threat actors prioritized the theft of highly privileged Global Administrator credentials. Once they successfully compromised an identity holding these privileges-often through MFA fatigue attacks or the purchasing of session tokens on the dark web-the attackers gained access to the organization’s Microsoft Intune environment (a cloud-based endpoint management solution).

From the Intune administrative console, The FAD Team did not deploy traditional malware. Instead, they weaponized the platform’s legitimate deployment capabilities. They created forced compliance policies and executed custom PowerShell scripts designed to overwrite the Master Boot Record (MBR) and irrevocably corrupt the file systems of all registered endpoints simultaneously. Because the command originated from Intune-a trusted, whitelisted enterprise application-local security agents blindly executed the wipe commands without raising a single alert.

Targeting SCADA and Critical Infrastructure

While the initial wipe commands devastated traditional IT environments (laptops, servers, and workstations), the true strategic goal of The FAD Team was the disruption of Operational Technology (OT) networks. Intelligence reports from mid-2026 highlight that the group actively targeted organizations running SCADA (Supervisory Control and Data Acquisition) systems and PLCs (Programmable Logic Controllers) in the energy, water, and manufacturing sectors.

By wiping the engineering workstations and Human-Machine Interfaces (HMIs) that bridge the IT and OT networks, the attackers successfully blinded facility operators. Without these critical interface systems, engineers lose the ability to monitor pressure valves in oil pipelines, regulate chemical mixtures in water treatment plants, or manage power distribution grids. This “blindness” effectively forces a hard, physical shutdown of the affected facilities to prevent catastrophic physical damage, achieving the attacker’s goal of massive economic and logistical disruption.

The FAD Team Intelligence Verification

Tactical Attribute Operational Details Intelligence Confidence
Primary Attack Vector Credential theft leading to Microsoft Intune/MDM hijack. Verified (High Confidence)
Malware Payload Objective Permanent MBR overwrite and filesystem corruption (Zero Recovery). Verified (High Confidence)
Target Environments Middle East Critical Infrastructure (Aviation, Energy, SCADA). Highly Probable

Mitigation: Defending the Defenders

The FAD Team’s 2026 operations underscore a critical reality: the tools used to manage and secure a network are currently the most dangerous weapons in an attacker’s arsenal. Defending against administrative hijacking requires strict adherence to Identity and Access Management (IAM) best practices:

  1. Implement Privileged Access Management (PAM): No user should hold standing Global Administrator privileges. Organizations must transition to Just-In-Time (JIT) access, where administrative rights are granted only for a specific task and immediately revoked upon completion.
  2. Phishing-Resistant MFA: Traditional SMS-based or push-notification MFA is no longer sufficient to stop highly motivated APTs. Organizations managing critical infrastructure must deploy FIDO2 hardware keys (e.g., YubiKeys) for all administrative accounts.
  3. Monitor Management Plane Telemetry: Security Operations Centers (SOCs) must ingest and monitor audit logs directly from management portals like Microsoft Intune. Mass deployment of highly obfuscated scripts or sudden changes to global compliance policies should trigger immediate, automated isolation of the offending administrative session.

As geopolitical conflicts continue to spill over into the digital domain, destructive wiper attacks will remain a favored tactic for state-aligned hacktivists seeking maximum disruption. For ongoing, clinical analysis of evolving Middle Eastern cyber threats and defense strategies, continue monitoring our Threat Intelligence portal.


> subscribe_to_intel

Get CyberAsia threat intelligence updates by email. Unsubscribe anytime. Privacy Policy.

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing The Intune Hijack: How The FAD Team Wiped 200,000 Middle East Systems in 2026 is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Haider

Lead Cyber Threat Intelligence (CTI) Editor at CyberAsia, specializing in regional cybercrime syndicates, threat actor tracking, and dark web intelligence investigations.

> related_intel --suggest