logo

PCPJack Worm Attacks Docker, Kubernetes, Redis, and MongoDB

ID: a49f0f5e-48d1-5816-9203-dc323c2d0dda

STIX ID: report--a49f0f5e-48d1-5816-9203-dc323c2d0dda

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-22

Author: Varshini

...
...

PCPJack is an actively spreading password-stealing malware campaign targeting exposed cloud infrastructure and containerized environments (Docker, Kubernetes, Redis, MongoDB, and vulnerable web apps). The malware uses a Python-based dropper and worm behavior to establish persistence, harvest cloud keys and credentials, escape containers via exposed Docker sockets, map Kubernetes tokens, and propagate using Common Crawl datasets; it exfiltrates stolen secrets via encrypted Telegram channels and the report includes IOCs such as domains, an S3 subdomain, and a hardcoded IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.