PCPJack Worm Attacks Docker, Kubernetes, Redis, and MongoDB
ID: a49f0f5e-48d1-5816-9203-dc323c2d0dda
STIX ID: report--a49f0f5e-48d1-5816-9203-dc323c2d0dda
Feed Name: Cyber Press
PCPJack is an actively spreading password-stealing malware campaign targeting exposed cloud infrastructure and containerized environments (Docker, Kubernetes, Redis, MongoDB, and vulnerable web apps). The malware uses a Python-based dropper and worm behavior to establish persistence, harvest cloud keys and credentials, escape containers via exposed Docker sockets, map Kubernetes tokens, and propagate using Common Crawl datasets; it exfiltrates stolen secrets via encrypted Telegram channels and the report includes IOCs such as domains, an S3 subdomain, and a hardcoded IP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
