Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
2026-03-15T01:23:29Z•b0944ea5259192ae9e42cb1a3d679e8dc11011520a3428fd5d344e77a35f969c
AI-securityBadbox-2.0DDoSI2PIoT-botnetIran-backedKimwolfMFA-bypassScattered-Lapsus-ShinyHuntersStarkillerStrykerextortionmedical-devicepatch-tuesdayphishing-as-a-servicevulnerabilitieswiper
What happened
Multiple high-impact threats reported: an Iran-linked group claims a destructive wiper attack against medtech firm Stryker (service disruptions and mass employee displacement reported). A stealthy phishing-as-a-service dubbed “Starkiller” proxies real login pages and relays credentials and MFA codes to defeat MFA protections. The Kimwolf IoT botnet has grown to >2M devices, enabling massive DDoS, local-network spread, and disruption of anonymity network I2P; operators also claim access to Badbox 2.0 infrastructure. Separately, Microsoft’s March 2026 Patch Tuesday addresses ~77 vulnerabilities,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- b0944ea5259192ae9e42cb1a3d679e8dc11011520a3428fd5d344e77a35f969c
- Enrichment time
- 2026-03-15T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.