Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

2026-03-14T07:23:26Zc322e64e8237b59309944fdb430fe751c47f81e93610345196be687a4f1d55fd
BadboxDDoSI2PIoTIranKimwolfMFA-bypassMicrosoft-Patch-TuesdayScattered-Lapsus-ShinyHuntersStarkillerStrykerbotnetbotnet-attributioncredential-harvestdo​​xingextortionmedtechnation-statepatching-priority」「AI-assistants」「insider-riskphishingphishing-as-a-serviceswattingvulnerabilitieswiperzero-day

What happened

The collection highlights multiple active, high-impact threats: an Iran-linked actor claims a destructive wiper attack against medical device vendor Stryker (disrupting operations in Ireland and the U.S.); the rapidly growing Kimwolf IoT botnet (reported >2M devices) is causing large-scale DDoS and abusing anonymity networks (I2P), and its operators (handle “Dort”) are conducting harassment, doxing and retaliatory attacks. New overlaps between botnets (Badbox 2.0) and Kimwolf activity were reported. A stealthy phishing-as-a-service named “Starkiller” proxies real sites to harvest credentials +

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
c322e64e8237b59309944fdb430fe751c47f81e93610345196be687a4f1d55fd
Enrichment time
2026-03-14T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker · Baitaphish