‘CanisterWorm’ Springs Wiper Attack Targeting Iran

2026-04-05T07:23:27Z5dd8e400a006ecfe4843661e084c6f19d3a90f9a66df853566d3b628aa2aa6cf
AI-assistants-security','mfa','patch-tuesday','microsoft','vuln-AisuruCanisterWormDDoSFarsiI2PIoT-botnetIranIran-linkedJackSkidKimwolfMFA-bypassMossadStarkillerStrykerbotnetcloud-securitycredential-theftdata-wipingextortionlaw-enforcement-takedownphishingphishing-as-a-servicetime-zone-based-targetingwiper

What happened

Multiple high-impact cyber threats and defensive actions were reported: a financially motivated group unleashed “CanisterWorm,” a wormy wiper that spreads via poorly secured cloud services and targets systems using Iran time zone or Farsi settings; Iran-linked hacktivists claim a destructive wiper attack against medical device firm Stryker; U.S., Canadian and German authorities disrupted four massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) responsible for record DDoS attacks; the Kimwolf botnet has also been abusing the I2P anonymity network. A stealthy phishing-as-a-service called “St

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
5dd8e400a006ecfe4843661e084c6f19d3a90f9a66df853566d3b628aa2aa6cf
Enrichment time
2026-04-05T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ‘CanisterWorm’ Springs Wiper Attack Targeting Iran · Baitaphish