Iran-Related Cyber Campaigns Spike with Wipers and Ransomware
Iran-linked and anti‑Iran actors have increased destructive and disruptive cyber operations. Observed incidents include TeamPCP’s worm and Iran‑targeted Kubernetes wiper, a Trivy supply‑chain compromise that pushed credential‑stealing backdoors, and a Pay2Key ransomware deployment against a U.S. healthcare organization. Handala claimed broad device wipes; Stryker found a malicious file used to run remote commands with limited evidence of deployed wiper.
Iran-linked ransomware gang targeted US healthcare org amid military conflict
The incident responders noted that there was no evidence that data was exfiltrated during the intrusion — an unusual development considering U.S. intelligence agencies previously said Pay2Key attacks were largely conducted for information theft.