Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

2026-03-13T19:23:31Z23923f694192858847a7df95c0b987d6c7e1497609595e649d3cf402af4824fc
Strykerai-assistantsbadboxcredential-theftcybercrimeddosdoxxingextortioni2pinsider-riskiot-botnetiran-linkedkimwolfmedtechmfa-bypassmicrosoft-patch-tuesdaynation-statepatch-managementphishing-as-a-servicestarkillerswattingvulnerabilitieswiper

What happened

Multiple high-impact incidents and trends: an Iran-linked group claims a destructive wiper attack against medical device maker Stryker, reportedly disrupting operations and evacuating thousands of workers; the massive Kimwolf IoT botnet (2M+ devices) continues to drive large DDoS campaigns, disrupt anonymizing networks (I2P) and infiltrate corporate/government networks while its operators engage in doxxing, swatting and takeover of other botnet infrastructure (Badbox 2.0); a new phishing-as-a-service called “Starkiller” proxies real login pages and relays MFA codes to defeat common defenses; K

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
23923f694192858847a7df95c0b987d6c7e1497609595e649d3cf402af4824fc
Enrichment time
2026-03-13T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.