Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
2026-03-15T19:23:28Z•0c2afdfac5224658fe8fd560c9d64929f90610ca6805cee3777dd1f5b807a90b
ai-assistantsai-securitybadbox-2.0botnetcredential-theftddosdoxxingextortioni2piot-botnetiran-linkedkimwolfmedtechmfa-bypassmicrosoftpatch-tuesdayphishing-as-a-servicescattered-lapsusstarkillerstate-backedstrykerswattingthreat-actor-attributionvulnerabilitieswiper
What happened
KrebsOnSecurity coverage highlights multiple active cyber threats: an Iran-linked hacking group claims a wiper attack against medical device maker Stryker; Microsoft issued fixes for 77 vulnerabilities in March 2026 (no high-profile zero-day reported this month); a stealthy phishing-as-a-service called “Starkiller” proxies real login pages and relays MFA to capture credentials; the Kimwolf IoT botnet (≈2M devices) is driving large DDoS campaigns, abusing I2P to evade takedowns and is present in corporate and government networks, while its alleged operator (“Dort”) has orchestrated harassment/c
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 0c2afdfac5224658fe8fd560c9d64929f90610ca6805cee3777dd1f5b807a90b
- Enrichment time
- 2026-03-15T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.