A recently identified hacking collective, known as TeamPCP, has been actively conducting a campaign that utilizes a unique self-replicating backdoor alongside a destructive data-wiping tool aimed at Iranian systems. This group first came to light in December when security experts from Flare detected its worm-like malware targeting inadequately secured cloud platforms. The group's primary goal appears to be establishing a distributed proxy network to facilitate data exfiltration, ransomware deployment, extortion efforts, and cryptocurrency mining. TeamPCP is distinguished by its capability to automate attacks on a large scale while integrating various established hacking methods. In its latest operations, the group has intensified its efforts, employing rapidly changing malware to seize control of more systems. Recently, it executed a supply-chain attack that compromised nearly all versions of the popular Trivy vulnerability scanner after breaching the GitHub account of Aqua Security, the software's developer.
New Malware Threat Targets Open Source Software and Iranian Systems
A new hacking group is deploying self-replicating malware that affects open source software and wipes data from Iranian machines.
