Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
2026-03-14T07:23:26Z•c322e64e8237b59309944fdb430fe751c47f81e93610345196be687a4f1d55fd
BadboxDDoSI2PIoTIranKimwolfMFA-bypassMicrosoft-Patch-TuesdayScattered-Lapsus-ShinyHuntersStarkillerStrykerbotnetbotnet-attributioncredential-harvestdoxingextortionmedtechnation-statepatching-priority」「AI-assistants」「insider-riskphishingphishing-as-a-serviceswattingvulnerabilitieswiperzero-day
What happened
The collection highlights multiple active, high-impact threats: an Iran-linked actor claims a destructive wiper attack against medical device vendor Stryker (disrupting operations in Ireland and the U.S.); the rapidly growing Kimwolf IoT botnet (reported >2M devices) is causing large-scale DDoS and abusing anonymity networks (I2P), and its operators (handle “Dort”) are conducting harassment, doxing and retaliatory attacks. New overlaps between botnets (Badbox 2.0) and Kimwolf activity were reported. A stealthy phishing-as-a-service named “Starkiller” proxies real sites to harvest credentials +
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- c322e64e8237b59309944fdb430fe751c47f81e93610345196be687a4f1d55fd
- Enrichment time
- 2026-03-14T07:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.