Operations & Intelligence Failures — 2026-03-23
CanisterWorm Wiper Campaign Targets Iranian Systems Through Cloud Infrastructure Exploits
A financially motivated cybercrime group called TeamPCP deployed a wiper named CanisterWorm that destroys data on systems configured with Iran's timezone or Farsi language settings. The malware spreads through exposed Docker APIs, Kubernetes clusters, and Redis servers — if it detects a Kubernetes cluster, it destroys data on every node. TeamPCP uses Internet Computer Protocol blockchain-based smart contracts to orchestrate campaigns, making infrastructure takedown difficult. The group previously compromised Aqua Security's Trivy vulnerability scanner, stealing credentials and cloud authentication tokens. Security researchers assess the Iran targeting is opportunistic rather than state-directed, with TeamPCP attempting to inject itself into the Iran conflict for attention and extortion purposes.
Analysis
Prior IC briefs tracked MOIS-directed Handala operations (Stryker wiper, FBI FLASH advisory) as the primary Iran-linked cyber threat. CanisterWorm introduces a distinct category: financially motivated non-state actors exploiting the conflict for opportunistic targeting. The cyber threat landscape around the Iran war now includes state-directed (Handala/MOIS), state-tolerated (CyberAv3ngers/IRGC proxies), and purely opportunistic actors — complicating attribution and response.
1 sources
- TeamPCP deploys Iran-targeted wiper in Kubernetes attacks - BleepingComputer
View in full brief →