‘CanisterWorm’ Springs Wiper Attack Targeting Iran
ID: 3fabf0da-0f3a-58b0-8ec5-842fc4a449c6
STIX ID: report--3fabf0da-0f3a-58b0-8ec5-842fc4a449c6
Feed Name: Krebs on Security
Threat Score
A financially motivated cybercriminal group, TeamPCP, has been running an automated cloud-focused campaign that abused exposed control planes and supply-chain compromises (notably Trivy and KICS GitHub Actions) to distribute credential-stealing malware and a self-propagating wiper (CanisterWorm) that targets systems localized to Iran; the group leverages ICP canisters for resilient hosting, siphons cloud/Kubernetes credentials, and publicly extorts victims via Telegram.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
