Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
2026-03-19T01:23:27Z•406de9f3bf71cc1e1b06d83cf419618ae236d5a966cf52ebac6eae93f25c9f8d
Badbox 2.0DDoSDortI2PIoT-botnetIranKimwolfMFA-bypassMicrosoft Patch TuesdayScattered LapsusShinyHunters","AI-assistants","insider-threatStarkillerStrykerbotmasterbotnetcredential-relaydata-destructionextortionmedtechnation-statepatchingphishingphishing-as-a-servicevulnerabilitieswiper
What happened
KrebsOnSecurity items (Jan–Mar 2026) cover multiple high-impact threats: an Iran-linked hacking group claims a destructive wiper attack on medtech giant Stryker (disrupting global operations); Microsoft’s March Patch Tuesday addressing 77 vulnerabilities; a stealthy “Starkiller” phishing-as-a-service that proxies real login pages and relays MFA codes; rapid growth and abuse of the Kimwolf IoT botnet (2M+ devices) disrupting I2P and infecting corporate/government networks; analysis of the Kimwolf botmaster “Dort” and ties to other botnets like Badbox 2.0; the changing risk profile from AI/agent
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 406de9f3bf71cc1e1b06d83cf419618ae236d5a966cf52ebac6eae93f25c9f8d
- Enrichment time
- 2026-03-19T01:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.