Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

2026-03-21T01:23:30Z7225a0f76e9e77119495bb1a16a96e04a4598366ab0f98cdf2a5981adff5cd17
AI-assistantsAisuruBadbox-2.0DDoSI2P-disruptionIoT-botnetIran-backedJackSkidKimwolfMFA-bypassMicrosoft-Patch-TuesdayMossadScattered-Lapsus-ShinyHuntersStarkillerStrykerautonomous-agentslaw-enforcement-takedownphishing-as-a-servicevulnerability-managementwiperzero-day

What happened

KrebsOnSecurity roundup covering multiple high-impact threats: U.S., Canadian and German authorities disrupted the command infrastructure for four massive IoT botnets (Aisuru, Kimwolf, JackSkid and Mossad) that infected millions of devices and powered record DDoS attacks; Kimwolf remains a prolific attacker (including I2P disruptions) and is tied to other botnet activity (Badbox 2.0). A separate Iran-linked actor claims a destructive wiper attack against medical device firm Stryker. New phishing-as-a-service called “Starkiller” proxies real sites and relays credentials and MFA codes to defeat

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
7225a0f76e9e77119495bb1a16a96e04a4598366ab0f98cdf2a5981adff5cd17
Enrichment time
2026-03-21T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.