logo

‘CanisterWorm’ Springs Wiper Attack Targeting Iran. But why?

ID: b299e803-3bd4-5e53-a53d-b611aab0fca9

STIX ID: report--b299e803-3bd4-5e53-a53d-b611aab0fca9

Feed Name: DataBreaches.Net

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-19

Author: Dissent

...
...

A financially motivated cybercrime group named TeamPCP is running a self-propagating worm (leveraging exposed Docker APIs, Kubernetes clusters, Redis servers, and the React2Shell vulnerability) that spreads through cloud environments, steals credentials, extorts victims via Telegram, and deploys a wiper targeting systems using Iran's time zone or Farsi settings; the report notes active destructive behavior and raises questions about the group's motivations and possible geopolitical implications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.