‘CanisterWorm’ Springs Wiper Attack Targeting Iran
2026-03-24T13:23:38Z•4cf2daafd23314cf92865eb44d3c15bd31a2ee4cd58322c93912cb3fb4d0d2df
AI assistantsAisuruCanisterWormDDoSI2PIoTIranJackSkidKimwolfMFA-bypassMicrosoft Patch TuesdayMossadStarkillerStrykerbotnetcloud compromisedata-wipingextortionmedtechphishing-as-a-servicetakedownthreat-actor-Dortvulnerabilitieswiperzero-day
What happened
This KrebsOnSecurity feed aggregates multiple high-impact incidents and trends from Feb–Mar 2026: a new wormed wiper dubbed “CanisterWorm” targeting systems using Iran time zone/Farsi and spreading via poorly secured cloud services; massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) responsible for record DDoS attacks and subject to international takedowns; an Iran-linked group claiming a destructive wiper attack against medical device vendor Stryker; a stealthy phishing-as-a-service named “Starkiller” that proxies real login pages and relays MFA codes; Kimwolf’s disruption of the I2P net
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 4cf2daafd23314cf92865eb44d3c15bd31a2ee4cd58322c93912cb3fb4d0d2df
- Enrichment time
- 2026-03-24T13:23:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.