TeamPCP Unleashes Iran-Targeted CanisterWorm Kubernetes Wiper
ID: b1e5e26c-e0a1-50f6-be19-1a5fff048c7b
STIX ID: report--b1e5e26c-e0a1-50f6-be19-1a5fff048c7b
Feed Name: GBHackers
CanisterWorm has evolved into a geopolitically targeted campaign attributed to TeamPCP that uses an Internet Computer Protocol (ICP) canister C2 to deliver a bash stager and Python controller which fingerprint hosts by Kubernetes presence, timezone, and locale; Iranian Kubernetes clusters receive a privileged DaemonSet (host-provisioner-iran) that wipes host files and force-reboots nodes to brick clusters, non-Iranian clusters receive persistence-focused DaemonSets, and non-Kubernetes Iranian hosts are subject to filesystem wipe via rm -rf; the campaign also spreads via SSH replay and exposed Docker APIs and hides backdoors as PostgreSQL monitoring tooling (pgmonitor/pglog), with specific IoCs and defender guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
