‘CanisterWorm’ Springs Wiper Attack Targeting Iran

2026-03-30T01:23:29Z21b546d288a540ee479e1869a01724af1d97958fb2f6d1ec3a0acb3cca715d8b
AI assistants security shift','Scattered Lapsus ShinyHunters','rAisuruCanisterWormDDoSFarsi-localeI2PIoT botnetIranJackSkidKimwolfKimwolf-DortMFA bypassMicrosoft Patch TuesdayMossadStarkillerStrykerbotnet takedowncloud wormcredential relayextortionmedtech attackphishing-as-a-servicevulnerabilitieswiperzero-day

What happened

Collection of KrebsOnSecurity posts describing multiple active, high-impact threats: a new worm dubbed “CanisterWorm” that spreads via poorly secured cloud services and wipes data on systems with Iran timezone or Farsi locale (financially motivated group leveraging geopolitical conflict); large-scale IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) responsible for record DDoS attacks and recently disrupted by law enforcement; Kimwolf’s continued abuse of the I2P anonymity network and doxxing/SWAT-style harassment by its operator (“Dort”); a claimed Iran-linked wiper attack against medical techs

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
21b546d288a540ee479e1869a01724af1d97958fb2f6d1ec3a0acb3cca715d8b
Enrichment time
2026-03-30T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.