Worm rubs out competitor's malware, then takes control
ID: e9eb432f-acc4-5f10-9099-908db8da9a78
STIX ID: report--e9eb432f-acc4-5f10-9099-908db8da9a78
Feed Name: The Register (Security)
SentinelLabs identified PCPJack, an autonomous cloud-targeting worm that removes TeamPCP infections and replaces them by harvesting credentials and secrets from exposed Docker, Kubernetes, Redis, MongoDB, RayML and web app instances. The framework includes modules for lateral movement, credential parsing and exfiltration (env vars, config files, SSH keys, Docker secrets, Kubernetes tokens) and scanning for new targets, suggesting its goal is large-scale credential theft to enable fraud, spam, or resale of access; organizations should secure cloud services and require authentication for exposed instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
