Researchers reported that TeamPCP has expanded its cloud-native malware operations by adding a destructive payload to its CanisterWorm toolkit. The malware checks whether it is running in Kubernetes and whether the host appears configured for Iran based on timezone or locale, then selects one of four paths: wiping Iranian Kubernetes environments, deploying the CanisterWorm backdoor in non-Iranian Kubernetes environments, wiping local non-Kubernetes Iranian systems, or doing nothing elsewhere. In Kubernetes, the wiper deploys a privileged DaemonSet that mounts the host root filesystem, deletes top-level directories, and forces node reboots, effectively bricking the cluster.
Researchers linked the payload to earlier CanisterWorm activity through shared ICP canister command-and-control infrastructure, overlapping backdoor code, the /tmp/pglog path, and the same DaemonSet-based propagation model. Reporting also said newer variants broaden propagation by harvesting SSH-related data and scanning for exposed Docker APIs on port 2375, raising the risk of spread across containerized and cloud environments. Defenders were urged to review Kubernetes DaemonSets, suspicious services and file paths, block outbound access to icp0[.]io domains, secure Docker APIs, rotate SSH keys, and inspect SSH logs for signs of lateral movement.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Subsequent variants expanded propagation by collecting SSH-related data and scanning for exposed Docker APIs on port 2375. These additions increased the potential for the malware to spread destructively across cloud and containerized environments.
Aikido attributed the destructive payload to TeamPCP by tying it to the established CanisterWorm campaign through shared ICP canister C2 infrastructure, overlapping backdoor code, the /tmp/pglog path, and similar DaemonSet-based Kubernetes tradecraft. The report also published technical indicators including DaemonSet names, service names, file paths, and network observables for detection.
In Kubernetes environments identified as Iranian, the malware deploys a privileged DaemonSet that mounts the host root filesystem, deletes top-level directories, and force reboots nodes, effectively bricking the cluster. This marked an escalation from TeamPCP's prior persistence- and credential-theft-focused activity to destructive operations.
Researchers identified a new TeamPCP payload that checks whether it is running in Kubernetes and whether the host appears configured for Iran via timezone or locale. Based on those checks, it either wipes Iranian systems, deploys the CanisterWorm backdoor in non-Iranian Kubernetes environments, wipes local non-Kubernetes Iranian systems, or does nothing elsewhere.
In January 2026, TeamPCP used its Telegram channels to claim a breach of Vietnam's JobsGO and leak 2,325,285 candidate records. The disclosure showed the group pairing cloud intrusions with public extortion and data-leak operations.
In December 2025, TeamPCP began a large-scale campaign targeting exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell-vulnerable applications. The operation used automated worm-like tooling to spread across cloud workloads, deploy persistence, exfiltrate data, run XMRig miners, and establish proxy and C2 infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcetomshardware.com
Open sourcecybersecuritynews.com
Open sourcecstromblad.com
Open sourceaikido.dev
Open sourceflare.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.