Feds Disrupt IoT Botnets Behind Huge DDoS Attacks
2026-03-21T01:23:30Z•7225a0f76e9e77119495bb1a16a96e04a4598366ab0f98cdf2a5981adff5cd17
AI-assistantsAisuruBadbox-2.0DDoSI2P-disruptionIoT-botnetIran-backedJackSkidKimwolfMFA-bypassMicrosoft-Patch-TuesdayMossadScattered-Lapsus-ShinyHuntersStarkillerStrykerautonomous-agentslaw-enforcement-takedownphishing-as-a-servicevulnerability-managementwiperzero-day
What happened
KrebsOnSecurity roundup covering multiple high-impact threats: U.S., Canadian and German authorities disrupted the command infrastructure for four massive IoT botnets (Aisuru, Kimwolf, JackSkid and Mossad) that infected millions of devices and powered record DDoS attacks; Kimwolf remains a prolific attacker (including I2P disruptions) and is tied to other botnet activity (Badbox 2.0). A separate Iran-linked actor claims a destructive wiper attack against medical device firm Stryker. New phishing-as-a-service called “Starkiller” proxies real sites and relays credentials and MFA codes to defeat
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 7225a0f76e9e77119495bb1a16a96e04a4598366ab0f98cdf2a5981adff5cd17
- Enrichment time
- 2026-03-21T01:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.