‘CanisterWorm’ Springs Wiper Attack Targeting Iran
2026-04-02T07:23:53Z•5d5097abd568c42028b4c2e04bc8326c0f18830fab3b18fb4983bdf6efd86405
AI-assistantsAisuruCanisterWormDDoSIoTIranJackSkidKimwolfMFA-bypassMicrosoftMossadStarkillerStrykerbotnethacktivistinsider-threatnation-statepatch-tuesdayphishingphishing-as-a-serviceransom/extortionsecurity-updatesvulnerabilitieswiperzero-day
What happened
March 2026 security roundup: a financially motivated group unleashed “CanisterWorm,” a wormy wiper that propagates via misconfigured cloud services and targets systems set to Iran time zone or Farsi; an Iran-linked hacktivist group claims a wiper attack against medtech firm Stryker; law enforcement disrupted four massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) tied to record DDoS campaigns; Kimwolf activity and its alleged operator (“Dort”) continue to cause wide disruption including attacks on the I2P anonymity network. Other notable trends: a new phishing-as-a-service (“Starkiller”)‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 5d5097abd568c42028b4c2e04bc8326c0f18830fab3b18fb4983bdf6efd86405
- Enrichment time
- 2026-04-02T07:23:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.