Threats & Adversaries · DDoS

Iran-Related Cyber Campaigns Spike with Wipers and Ransomware

Iran-linked and aligned actors have stepped up destructive intrusions, supply-chain compromises, and DDoS operations. Reported incidents include Pay2Key encrypting a US healthcare environment with no confirmed exfiltration. Researchers also link a Stryker disruption to Handala activity abusing Intune and a worm-driven compromise of the Trivy scanner that poisoned npm packages.

18 sources · Mar 24

Timeline

Sources

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: Iran-Related Cyber Campaigns Spike with Wipers and Ransomware

More from today