Eriksen, C. (2026, March 22). CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran. Retrieved July 27, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareCanisterWorm | CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses. |
| T1018 Remote System Discovery |
MalwareCanisterWorm | CanisterWorm has scanned the local /24 subnet for new targets. |
| T1033 System Owner/User Discovery |
MalwareCanisterWorm | CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames. |
| T1053.006 Systemd Timers |
MalwareCanisterWorm | CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes. |
| T1059.004 Unix Shell |
MalwareCanisterWorm | CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
| T1070.004 File Deletion |
MalwareCanisterWorm | CanisterWorm has deleted itself after execution. |
| T1102.001 Dead Drop Resolver |
MalwareCanisterWorm | CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery. |
| T1105 Ingress Tool Transfer |
MalwareCanisterWorm | CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed. |
| T1124 System Time Discovery |
MalwareCanisterWorm | CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.” |
| T1480 Execution Guardrails |
MalwareCanisterWorm | CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran. |
| T1485 Data Destruction |
MalwareCanisterWorm | CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts. |
| T1529 System Shutdown/Reboot |
MalwareCanisterWorm | CanisterWorm has forced the target system to reboot after file deletion. |
| T1548.003 Sudo and Sudo Caching |
MalwareCanisterWorm | CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command. |
| T1552.004 Private Keys |
MalwareCanisterWorm | CanisterWorm has gathered SSH private keys from the .ssh file. |
| T1609 Container Administration Command |
MalwareCanisterWorm | CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl. |
| T1613 Container and Resource Discovery |
MalwareCanisterWorm | CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `. |
| T1614.001 System Language Discovery |
MalwareCanisterWorm | CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.