‘CanisterWorm’ Springs Wiper Attack Targeting Iran

2026-03-29T07:23:25Z8a113083e0f75f4927495187ded634e1abec211a5414b6576d1039bcbb54ab15
AisuruCanisterWormDDoSI2PIoT botnetIranIran-backedJackSkidKimwolfMFA bypassMossadSLSHScattered Lapsus ShinyHuntersStarkillerStrykeranonymity networkbotnetcloud service compromisecredential theftdata-wipingdoxing','swatting'extortionphishing-as-a-servicewiperworm

What happened

Multiple high-impact threats observed: a financially motivated group unleashed ‘CanisterWorm’, a worm that spreads via poorly secured cloud services and performs destructive wipes on systems with Iran timezone/Farsi settings; Iran-linked actors claimed a wiper attack against medical device vendor Stryker; law enforcement disrupted four massive IoT botnets (Kimwolf, Aisuru, JackSkid, Mossad) used for record DDoS operations and Kimwolf continues disruptive activity (including targeting I2P). New phishing-as-a-service (“Starkiller”) proxies real login pages to capture credentials and MFA tokens.■

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
8a113083e0f75f4927495187ded634e1abec211a5414b6576d1039bcbb54ab15
Enrichment time
2026-03-29T07:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ‘CanisterWorm’ Springs Wiper Attack Targeting Iran · Baitaphish