logo

‘CanisterWorm’ Springs Wiper Attack Targeting Iran

ID: 3fabf0da-0f3a-58b0-8ec5-842fc4a449c6

STIX ID: report--3fabf0da-0f3a-58b0-8ec5-842fc4a449c6

Feed Name: Krebs on Security

Threat Score
82/100

Date Published: 2026-03-23

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

A financially motivated cybercriminal group, TeamPCP, has been running an automated cloud-focused campaign that abused exposed control planes and supply-chain compromises (notably Trivy and KICS GitHub Actions) to distribute credential-stealing malware and a self-propagating wiper (CanisterWorm) that targets systems localized to Iran; the group leverages ICP canisters for resilient hosting, siphons cloud/Kubernetes credentials, and publicly extorts victims via Telegram.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.