Threats & Adversaries · DDoS

Iran-Related Cyber Campaigns Spike with Wipers and Ransomware

Iran-linked and anti‑Iran actors have increased destructive and disruptive cyber operations. Observed incidents include TeamPCP’s worm and Iran‑targeted Kubernetes wiper, a Trivy supply‑chain compromise that pushed credential‑stealing backdoors, and a Pay2Key ransomware deployment against a U.S. healthcare organization. Handala claimed broad device wipes; Stryker found a malicious file used to run remote commands with limited evidence of deployed wiper.

18 sources · Mar 24

Timeline

Sources

Part of the PlainSec briefing for 2026-03-24

Every edition of this story: Iran-Related Cyber Campaigns Spike with Wipers and Ransomware

More from today