‘CanisterWorm’ Springs Wiper Attack Targeting Iran
2026-03-24T01:23:32Z•19103fb6b5d3e435f0738873c79f8acf68188b113be20d1c53e3ecb0162b9569
AI assistantsAisuruCanisterWormDDoSFarsiI2P disruption","Scattered Lapsus ShinyHunters"IoT botnetIranJackSkidKimwolfMFA bypassMicrosoft Patch TuesdayMossadStarkillerStrykerextortioninsider threatmedtechphishingphishing-as-a-serviceproxyingtime-zone targetingvulnerabilitieswiperzero-day
What happened
This collection highlights multiple high-impact threats and industry responses in March 2026: a new wormed wiper dubbed “CanisterWorm” is being used in attacks targeting systems set to Iran time zones or Farsi locales and appears tied to financially motivated extortion; law enforcement disrupted four massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) that had compromised millions of devices and fueled record DDoS activity; Iran-linked actors claim a destructive wiper attack against medtech firm Stryker; the Kimwolf botnet and its alleged operator (“Dort”) continue aggressive operations (D
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 19103fb6b5d3e435f0738873c79f8acf68188b113be20d1c53e3ecb0162b9569
- Enrichment time
- 2026-03-24T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.