‘CanisterWorm’ Springs Wiper Attack Targeting Iran
2026-04-01T07:23:27Z•880d13b8878a8be1caa7848793b4514222e0a81298faabe95efe3c0a8ee5c8d7
AisuruCanisterWormDDoSDortFarsiI2P-disruptionIoT-botnetIranJackSkidKimwolfMFA-bypassMossadSLSHScattered-Lapsus-ShinyHuntersStarkillerStrykercloud-wormcredential-theftdoxingextortionmedtechnation-state-linkedphishing-as-a-serviceswatting-behavioral-threats','patch-tuesday','microsoft-patch','wiper
What happened
This collection highlights multiple high-impact cyber threats and trends: a newly observed worm dubbed “CanisterWorm” that propagates through poorly secured cloud services and wipes systems configured for Iran time/Farsi; large IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) that infected millions of devices and powered record DDoS campaigns (with Kimwolf also disrupting I2P and its operator “Dort” engaging in harassment); a claimed wiper attack against medtech firm Stryker by Iran-linked actors; a stealthy phishing-as-a-service (“Starkiller”) that proxies legitimate sites to capture passwords
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 880d13b8878a8be1caa7848793b4514222e0a81298faabe95efe3c0a8ee5c8d7
- Enrichment time
- 2026-04-01T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.