logo

CanisterWorm Targets Docker, Kubernetes, and Redis to Steal Secrets

ID: bf742d4f-fc10-5194-817d-a0b2d6ca111d

STIX ID: report--bf742d4f-fc10-5194-817d-a0b2d6ca111d

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

TeamPCP is conducting a large-scale, financially motivated campaign that targets exposed cloud services (Docker APIs, Kubernetes, Redis) and developer tooling by deploying CanisterWorm, a worm that harvests SSH keys, cloud credentials, Kubernetes tokens and crypto wallets, enables persistent access for extortion via Telegram, and includes a locale/timezone-aware wiper for Iran-configured systems; attackers also trojanized Trivy releases via compromised CI/CD workflows and leverage ICP canisters and GitHub abuse to increase resilience and distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.