
The TeamPCP hacking group is attacking Kubernetes setups using a damaging script. When the tool detects systems set up for Iran, it erases all the data on them.
This group was behind the recent supply-chain attack on the Trivy vulnerability scanner and the ‘CanisterWorm’ campaign on NPM that began in March.
Security researchers at Aikido have found that this new attack on Kubernetes uses the same command center (C2), hidden code, and method of delivering the malware as used in the CanisterWorm attacks.
However, this new campaign is different as it contains a destructive feature that targets Iranian systems, while placing the CanisterWorm backdoor on other systems.
“The script uses the exact same ICP canister (tdtqy-oyaaa-aaaae-af2dq-cai[.]raw[.]icp0[.]io) we documented in the CanisterWorm campaign. Same C2, same backdoor code, same /tmp/pglog drop path,” Aikido says.
“The Kubernetes-native lateral movement via DaemonSets is consistent with TeamPCP’s known playbook, but this variant adds something we haven’t seen from them before: a geopolitically targeted destructive payload aimed specifically at Iranian systems.”
According to Aikido’s research, the malware is designed to wipe any computer matching Iran’s location and time zone configurations, whether it uses Kubernetes or not.
If both these conditions are met, it sets up a ‘Host-provisioner-iran’ DaemonSet within ‘kube-system’. This uses powerful containers and mounts the main filesystem into /mnt/host.
Each container runs an Alpine version called ‘kamikaze’ which wipes every main directory on the host system before forcing the host to reboot.
If Kubernetes is present, but the system is not Iranian, the malware deploys a DaemonSet named ‘host-provisioner-std’ using privileged containers with the host filesystem mounted.
Instead of erasing data, each container adds a Python backdoor to the host system, and installs it as a persistent systemd service.
On identified Iranian systems that do not have Kubernetes, the malware erases any file accessible to the current user including system data, using the command rm -rf/ with the –no-preserve-root flag. If it doesn’t have root permissions, it attempts passwordless sudo.
On system that meet none of targeted condition rules, the malware does nothing and simply stops.
Aikido also discovered a recent version of the malware uses the same ICP canister backdoor, but instead of using Kubernetes for spreading, it now uses SSH, scanning logs for credentials and also uses stolen private keys.
The researchers pointed out important signs to watch for, which included outbound SSH connections with ‘StrictHostKeyChecking+no’ from compromised computers, outbound connections to the Docker API on port 2375 across the local subnet, and privileged Alpine containers via an unauthenticated Docker API with / mounted as a hostPath.
#attacks #deploy #iranian #kubernetes #malware #news #systems #targeting #teampcp #uses #wiper — News
© Bulletproof Servers. All rights reserved.