‘CanisterWorm’ Springs Wiper Attack Targeting Iran

2026-04-05T13:23:51Zb486f3e149c91a3932a19181584a855726cb83b02c3776b6bab22f6ee5aadf41
AI assistantsAisuruCanisterWormDDoSI2P disruptionIoT botnetsIranJackSkidKimwolfMFA bypassMicrosoft Patch TuesdayMossadScattered Lapsus ShinyHuntersStarkillerStrykerbotmaster doxxing/swattingcloud misconfigurationdata ransomdooming/insider-like automationextortionphishingphishing-as-a-servicesupply-side threat modelvulnerabilitieswiper

What happened

KrebsOnSecurity roundup (Feb–Mar 2026) covering multiple active, high-impact threats: a financially motivated group is deploying “CanisterWorm,” a worm-like wiper that spreads via poorly secured cloud services and targets systems set to Iran time zone or Farsi; an Iran-linked hacktivist group claims a destructive wiper attack against medtech firm Stryker; and massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) that infected millions of devices have been disrupted by U.S., Canadian and German authorities. Related coverage details Kimwolf’s botmaster (“Dort”) and the botnet’s operational use

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
b486f3e149c91a3932a19181584a855726cb83b02c3776b6bab22f6ee5aadf41
Enrichment time
2026-04-05T13:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.