‘CanisterWorm’ Springs Wiper Attack Targeting Iran
2026-03-29T07:23:25Z•8a113083e0f75f4927495187ded634e1abec211a5414b6576d1039bcbb54ab15
AisuruCanisterWormDDoSI2PIoT botnetIranIran-backedJackSkidKimwolfMFA bypassMossadSLSHScattered Lapsus ShinyHuntersStarkillerStrykeranonymity networkbotnetcloud service compromisecredential theftdata-wipingdoxing','swatting'extortionphishing-as-a-servicewiperworm
What happened
Multiple high-impact threats observed: a financially motivated group unleashed ‘CanisterWorm’, a worm that spreads via poorly secured cloud services and performs destructive wipes on systems with Iran timezone/Farsi settings; Iran-linked actors claimed a wiper attack against medical device vendor Stryker; law enforcement disrupted four massive IoT botnets (Kimwolf, Aisuru, JackSkid, Mossad) used for record DDoS operations and Kimwolf continues disruptive activity (including targeting I2P). New phishing-as-a-service (“Starkiller”) proxies real login pages to capture credentials and MFA tokens.■
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 8a113083e0f75f4927495187ded634e1abec211a5414b6576d1039bcbb54ab15
- Enrichment time
- 2026-03-29T07:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.