Skip to main content

Self-Propagating Malware Poisons Open Source Software, Wipes Iran-Based Machines

6 days 16 hours ago
An anonymous reader quotes a report from Ars Technica: A new hacking group has been rampaging the Internet in a persistent campaign that spreads a self-propagating and never-before-seen backdoor -- and curiously a data wiper that targets Iranian machines. The group, tracked under the name TeamPCP, first gained visibility in December, when researchers from security firm Flare observed it unleashing a worm that targeted cloud-hosted platforms that weren't properly secured. The objective was to build a distributed proxy and scanning infrastructure and then use it to compromise servers for exfiltrating data, deploying ransomware, conducting extortion, and mining cryptocurrency. The group is notable for its skill in large-scale automation and integration of well-known attack techniques. More recently, TeamPCP has waged a relentless campaign that uses continuously evolving malware to bring ever more systems under its control. Late last week, it compromised virtually all versions of the widely used Trivy vulnerability scanner in a supply-chain attack after gaining privileged access to the GitHub account of Aqua Security, the Trivy creator. Over the weekend, researchers said they observed TeamPCP spreading potent malware that was also worm-enabled, meaning it had the potential to spread to new machines automatically, with no interaction required of victims behind the keyboard. [...] As the weekend progressed, CanisterWorm [as Aikido has named the malware] was updated to add an additional payload: a wiper that targets machines exclusively in Iran. When the updated worm infects machines, it checks if the machine is in the Iranian timezone or is configured for use in that country. When either condition was met, the malware no longer activated the credential stealer and instead triggered a novel wiper that TeamPCP developers named Kamikaze. Eriksen said in an email that there's no indication yet that the worm caused actual damage to Iranian machines, but that there was "clear potential for large-scale impact if it achieves active spread." It's unclear what the motive is for TeamPCP. Aikido researcher Charlie Eriksen wrote: "While there may be an ideological component, it could just as easily be a deliberate attempt to draw attention to the group. Historically, TeamPCP has appeared to be financially motivated, but there are signs that visibility is becoming a goal in itself. By going after security tools and open-source projects, including Checkmarx as of today, they are sending a clear and deliberate signal."

Read more of this story at Slashdot.

BeauHD

Remote or not, workers are drifting back toward the city

6 days 16 hours ago
Global hiring data shows employees relocating nearer major hubs, reversing pandemic-era shift

The post-pandemic shift away from cities has reversed since 2022, with return-to-office mandates playing a role, according to a new report on global hiring trends.…

Lindsay Clark

CMA dithers on cloud probe as Microsoft's meter runs on taxpayer dime

6 days 16 hours ago
Every month of 'careful consideration' is another month Redmond laughs all the way to the bank

Here's the uncomfortable truth: every week the UK's Competition and Markets Authority (CMA) hesitates on its decision on the outcome of its public cloud services market investigation, the meter keeps running and taxpayers continue to foot the bill.…

Bill McCluggage

Arm rolls its own 136-core AGI CPU to chase AI hype train

6 days 16 hours ago
Turns out artificial general intelligence was a CPU this whole time

Arm unveiled its first homegrown silicon — yes, an actual chip, not another shake-n-bake blueprint — during an event in San Francisco on Tuesday, and said that flagship customer Meta is set to deploy the 136-core CPU at scale later this year.…

Tobias Mann

Mozilla introduces cq, describing it as 'Stack Overflow for agents'

6 days 16 hours ago
A knowledge database where AI agents read, add and score the items – what could go wrong?

Mozilla is building cq - described by staff engineer Peter Wilson as "Stack Overflow for agents" - as an open source project to enable AI agents to discover and share collective knowledge.…

Tim Anderson