TeamPCP deploys Iran-targeted wiper in Kubernetes attacks
ID: 37e174b4-2515-5f2e-b6bb-067a3d791952
STIX ID: report--37e174b4-2515-5f2e-b6bb-067a3d791952
Feed Name: Bleeping Computer
TeamPCP is running a destructive campaign that targets Iranian systems by detecting timezone/locale and either deploying a Kubernetes DaemonSet that mounts the host filesystem to run an Alpine 'kamikaze' container which deletes top-level directories and reboots, or executing rm -rf --no-preserve-root on non-Kubernetes hosts; on non-Iranian systems it instead installs a persistent Python backdoor via privileged containers or unauthenticated Docker APIs. The activity reuses CanisterWorm/Trivy supply-chain infrastructure (same ICP canister C2 and drop paths) and newer variants spread via SSH credential theft and parsing auth logs; key IOCs include outbound SSH with StrictHostKeyChecking=no, connections to Docker API port 2375, and privileged Alpine containers mounting hostPath.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
