ATT&CKReferencesAikido CanisterWorm MAR 2026

Aikido CanisterWorm MAR 2026

Eriksen, C. (2026, March 22). CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran. Retrieved July 27, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses.

T1018
Remote System Discovery
MalwareCanisterWorm

CanisterWorm has scanned the local /24 subnet for new targets.

T1033
System Owner/User Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames.

T1053.006
Systemd Timers
MalwareCanisterWorm

CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes.

T1059.004
Unix Shell
MalwareCanisterWorm

CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence.

T1070.004
File Deletion
MalwareCanisterWorm

CanisterWorm has deleted itself after execution.

T1102.001
Dead Drop Resolver
MalwareCanisterWorm

CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery.

T1105
Ingress Tool Transfer
MalwareCanisterWorm

CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed.

T1124
System Time Discovery
MalwareCanisterWorm

CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.”

T1480
Execution Guardrails
MalwareCanisterWorm

CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran.

T1485
Data Destruction
MalwareCanisterWorm

CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts.

T1529
System Shutdown/Reboot
MalwareCanisterWorm

CanisterWorm has forced the target system to reboot after file deletion.

T1548.003
Sudo and Sudo Caching
MalwareCanisterWorm

CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command.

T1552.004
Private Keys
MalwareCanisterWorm

CanisterWorm has gathered SSH private keys from the .ssh file.

T1609
Container Administration Command
MalwareCanisterWorm

CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl.

T1613
Container and Resource Discovery
MalwareCanisterWorm

CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `.

T1614.001
System Language Discovery
MalwareCanisterWorm

CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.