Self-propagating malware poisons open source software and wipes Iran-based machines
Development houses: It's time to check your networks for infections.
A new hacking group has been rampaging the Internet in a persistent campaign that spreads a self-propagating and never-before-seen backdoor—and curiously a data wiper that targets Iranian machines. The group, tracked under the name TeamPCP, first gained visibility in December, when researchers from security firm Flare observed it unleashing a worm that targeted cloud-hosted platforms that weren’t properly secured. The objective was to build a distributed proxy and scanning infrastructure and then use it to compromise servers for exfiltrating data, deploying ransomware, conducting extortion, and mining cryptocurrency. The group is notable for its skill in large-scale automation and integration of well-known attack techniques. Relentless and constantly evolving More recently, TeamPCP has waged a relentless campaign that uses continuously evolving malware to bring ever more systems under its control. Late last week, it compromised virtually all versions of the widely used Trivy vulnerability scanner in a supply-chain attack after gaining privileged access to the GitHub account of Aqua Security, the Trivy creator.Read full article Comments
Quick summary
TeamPCP, a newly identified hacking group, has deployed a self‑propagating backdoor and a data‑wiping component that specifically targets Iranian machines, initially spreading via a worm that compromised insecure cloud platforms and later compromising the Trivy vulnerability scanner through a GitHub account takeover of its creator, Aqua Security.
Related tags
Companies and people
Story threads
Continue with this story
Follow the same topic through connected articles, entity pages, and active story threads.
Orbital data centers, part 1: There’s no way this is economically viable, right?
"This is not physically impossible; it’s only a question of whether this is a rational thing."
A mission NASA might kill is still returning fascinating science from Jupiter
"We can’t quite afford to support everything that we have done in the past."
Trump's MAHA pick for surgeon general flounders amid GOP doubts
She stalled over MAHA woo-woo, anti-vaccine views, and lacking medical background.
Nvidia CEO tries to explain why DLSS 5 isn’t just “AI slop”
If game makers don’t like it, “they could decide not to use it, you know?"
After hackers hit an Iowa company, cars around the country failed to start
If you don't calibrate your interlock in time, your vehicle is dead.
US to pay TotalEnergies $1 billion to stop developing offshore wind in US
Payment reimburses the company for two leases, one for a massive 3 GW wind farm.
Ad slot
Article monetization slot
Reserved for contextual monetization inside article pages.
Related articles
More stories that share tags, source, or category context.
Orbital data centers, part 1: There’s no way this is economically viable, right?
"This is not physically impossible; it’s only a question of whether this is a rational thing."
A mission NASA might kill is still returning fascinating science from Jupiter
"We can’t quite afford to support everything that we have done in the past."
Trump's MAHA pick for surgeon general flounders amid GOP doubts
She stalled over MAHA woo-woo, anti-vaccine views, and lacking medical background.
Nvidia CEO tries to explain why DLSS 5 isn’t just “AI slop”
If game makers don’t like it, “they could decide not to use it, you know?"
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Orbital data centers, part 1: There’s no way this is economically viable, right?
"This is not physically impossible; it’s only a question of whether this is a rational thing."
A mission NASA might kill is still returning fascinating science from Jupiter
"We can’t quite afford to support everything that we have done in the past."
Trump's MAHA pick for surgeon general flounders amid GOP doubts
She stalled over MAHA woo-woo, anti-vaccine views, and lacking medical background.
Nvidia CEO tries to explain why DLSS 5 isn’t just “AI slop”
If game makers don’t like it, “they could decide not to use it, you know?"