logo

CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran

ID: fd8b3a1d-7901-5318-976f-fd63067c19f4

STIX ID: report--fd8b3a1d-7901-5318-976f-fd63067c19f4

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-03-22

Date Updated: 2026-07-24

...
...

TeamPCP is observed delivering a Kubernetes-native and host-based payload that fingerprints for Iranian systems and either deploys a privileged DaemonSet named 'host-provisioner-iran' which mounts host root and wipes nodes (container 'kamikaze'), or installs the CanisterWorm backdoor on non-Iranian hosts; later variants self-propagate via stolen SSH keys and exposed Docker API (2375). The report provides code excerpts, IOCs (ICP canister C2, Cloudflare delivery domains, DaemonSet names, file and service paths), and detection guidance to find malicious DaemonSets, privileged hostPath mounts, and suspicious outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.