A financially driven cybercrime group, TeamPCP, has recently targeted Iran with a wiper attack that exploits vulnerabilities in cloud services. This malicious campaign, identified as CanisterWorm, specifically seeks out systems configured to Iran's time zone or set to Farsi as the default language. TeamPCP emerged in late 2025, focusing on compromising corporate cloud environments by utilizing a self-replicating worm that targets exposed Docker APIs and Kubernetes clusters. The group has been known to extract credentials and extort victims via Telegram. Security firm Flare noted that TeamPCP primarily exploits control planes rather than end-user devices, with a significant focus on Azure and AWS cloud infrastructures. Recently, they executed a supply chain attack on Aqua Security's Trivy vulnerability scanner, injecting malware into legitimate releases. This weekend, they deployed a new payload that wipes data from systems identified as Iranian. The group has been boasting about their exploits on Telegram, claiming to have stolen sensitive data from major corporations. Experts warn that the recent surge in supply chain attacks highlights the need for enhanced security measures on platforms like GitHub.
CanisterWorm Launches Wiper Attack Targeting Iran
A new cybercriminal group, TeamPCP, has initiated a wiper attack aimed at Iranian systems, leveraging vulnerabilities in cloud services.
