‘CanisterWorm’ Springs Wiper Attack Targeting Iran
2026-04-05T13:23:51Z•b486f3e149c91a3932a19181584a855726cb83b02c3776b6bab22f6ee5aadf41
AI assistantsAisuruCanisterWormDDoSI2P disruptionIoT botnetsIranJackSkidKimwolfMFA bypassMicrosoft Patch TuesdayMossadScattered Lapsus ShinyHuntersStarkillerStrykerbotmaster doxxing/swattingcloud misconfigurationdata ransomdooming/insider-like automationextortionphishingphishing-as-a-servicesupply-side threat modelvulnerabilitieswiper
What happened
KrebsOnSecurity roundup (Feb–Mar 2026) covering multiple active, high-impact threats: a financially motivated group is deploying “CanisterWorm,” a worm-like wiper that spreads via poorly secured cloud services and targets systems set to Iran time zone or Farsi; an Iran-linked hacktivist group claims a destructive wiper attack against medtech firm Stryker; and massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) that infected millions of devices have been disrupted by U.S., Canadian and German authorities. Related coverage details Kimwolf’s botmaster (“Dort”) and the botnet’s operational use
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- b486f3e149c91a3932a19181584a855726cb83b02c3776b6bab22f6ee5aadf41
- Enrichment time
- 2026-04-05T13:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.