Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

2026-03-15T01:23:29Zb0944ea5259192ae9e42cb1a3d679e8dc11011520a3428fd5d344e77a35f969c
AI-securityBadbox-2.0DDoSI2PIoT-botnetIran-backedKimwolfMFA-bypassScattered-Lapsus-ShinyHuntersStarkillerStrykerextortionmedical-devicepatch-tuesdayphishing-as-a-servicevulnerabilitieswiper

What happened

Multiple high-impact threats reported: an Iran-linked group claims a destructive wiper attack against medtech firm Stryker (service disruptions and mass employee displacement reported). A stealthy phishing-as-a-service dubbed “Starkiller” proxies real login pages and relays credentials and MFA codes to defeat MFA protections. The Kimwolf IoT botnet has grown to >2M devices, enabling massive DDoS, local-network spread, and disruption of anonymity network I2P; operators also claim access to Badbox 2.0 infrastructure. Separately, Microsoft’s March 2026 Patch Tuesday addresses ~77 vulnerabilities,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
b0944ea5259192ae9e42cb1a3d679e8dc11011520a3428fd5d344e77a35f969c
Enrichment time
2026-03-15T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.