Malware.View on attack.mitre.org
CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns since at least 2026. CanisterWorm has used npm credentials to infect software packages and propagate across developer ecosystems. CanisterWorm has a targeted wiper component and can use decentralized C2 infrastructure implemented via an Internet Computer Protocol (ICP) blockchain canister.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses. |
| T1018 Remote System Discovery |
CanisterWorm has scanned the local /24 subnet for new targets. |
| T1027.009 Embedded Payloads |
CanisterWorm has used embedded second stage Base64-encoded payloads. |
| T1033 System Owner/User Discovery |
CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames. |
| T1036.004 Masquerade Task or Service |
CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon. |
| T1036.005 Match Legitimate Resource Name or Location |
CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files. |
| T1053.006 Systemd Timers |
CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes. |
| T1059.004 Unix Shell |
CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
| T1059.006 Python |
CanisterWorm has used a Python script as a second-stage backdoor. |
| T1059.007 JavaScript |
CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation. |
| T1070.004 File Deletion |
CanisterWorm has deleted itself after execution. |
| T1083 File and Directory Discovery |
CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values. |
| T1102.001 Dead Drop Resolver |
CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery. |
| T1105 Ingress Tool Transfer |
CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed. |
| T1124 System Time Discovery |
CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.” |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.