‘CanisterWorm’ Springs Wiper Attack Targeting Iran
2026-03-30T01:23:29Z•21b546d288a540ee479e1869a01724af1d97958fb2f6d1ec3a0acb3cca715d8b
AI assistants security shift','Scattered Lapsus ShinyHunters','rAisuruCanisterWormDDoSFarsi-localeI2PIoT botnetIranJackSkidKimwolfKimwolf-DortMFA bypassMicrosoft Patch TuesdayMossadStarkillerStrykerbotnet takedowncloud wormcredential relayextortionmedtech attackphishing-as-a-servicevulnerabilitieswiperzero-day
What happened
Collection of KrebsOnSecurity posts describing multiple active, high-impact threats: a new worm dubbed “CanisterWorm” that spreads via poorly secured cloud services and wipes data on systems with Iran timezone or Farsi locale (financially motivated group leveraging geopolitical conflict); large-scale IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) responsible for record DDoS attacks and recently disrupted by law enforcement; Kimwolf’s continued abuse of the I2P anonymity network and doxxing/SWAT-style harassment by its operator (“Dort”); a claimed Iran-linked wiper attack against medical techs
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 21b546d288a540ee479e1869a01724af1d97958fb2f6d1ec3a0acb3cca715d8b
- Enrichment time
- 2026-03-30T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.