Anti-DDoS Firm Heaped Attacks on Brazilian ISPs
2026-05-03T01:23:29Z•528858fa2a64719c4e2f887033e5af3bc83b50ea301d1c38985d206475b3be47
AisuruBrazilCanisterWormDDoSGandCrabISP attacksIoT botnetsJackSkidKimwolfMicrosoft Office tokensMossadPatch Tuesday 2026 April/March','zero‑day','SharePoint','BlueHREvilRussiaScattered SpiderStrykeranti‑DDoS abusebotnetcredential/token theftdoxinglaw enforcement disruptionransomwarerouter exploitstate‑linked actorwiper
What happened
Collection of KrebsOnSecurity reports (Mar–Apr 2026) detailing widespread, high-impact cyber activity: a Brazilian anti‑DDoS provider was implicated in enabling botnet attacks against ISPs; Russian military‑linked actors exploited router flaws to harvest Microsoft Office auth tokens from ~18,000 networks; multiple state‑linked and criminal groups deployed wipers and ransomware (including a claimed attack on Stryker and the CanisterWorm campaign); U.S. and allied authorities disrupted four large IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad); a senior "Scattered Spider" member pleaded guilty;和
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 528858fa2a64719c4e2f887033e5af3bc83b50ea301d1c38985d206475b3be47
- Enrichment time
- 2026-05-03T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.