{"description": "Enterprise techniques used by CanisterWorm, ATT&CK software S9042 (v1.0)", "name": "CanisterWorm (S9042)", "domain": "enterprise-attack", "versions": {"layer": "4.5", "attack": "19", "navigator": "5.3.2"}, "techniques": [{"techniqueID": "T1548", "showSubtechniques": true}, {"techniqueID": "T1548.003", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has checked if the current user is root. If it is, [CanisterWorm](https://attack.mitre.org/software/S9042) will wipe the system using `rm \u2013rf / --no-preserve-root`. If it is not, [CanisterWorm](https://attack.mitre.org/software/S9042) will try passwordless sudo and will run the same command.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059", "showSubtechniques": true}, {"techniqueID": "T1059.004", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has used shell commands to enable and start the malicious systemd service for execution and persistence.(Citation: Aikido CanisterWorm MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059.006", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has used a Python script as a second-stage backdoor.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059.007", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1609", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl.(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1613", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has performed environment fingerprinting to identify Kubernetes clusters.(Citation: Palo Alto TeamPCP MAR 2026) [CanisterWorm](https://attack.mitre.org/software/S9042) has also searched for Kubernetes pods using the command ` os.path.exists(\"/var/run/secrets/kubernetes.io/serviceaccount\") or \"KUBERNETES_SERVICE_HOST\" in os.environ `.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1543", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1555", "showSubtechniques": true}, {"techniqueID": "T1555.006", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.(Citation: FBI TeamPCP JUL 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1485", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts.(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1140", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has decoded a long Base64 string to obtain a Python script for its second-stage payload.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1480", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1083", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1070", "showSubtechniques": true}, {"techniqueID": "T1070.004", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has deleted itself after execution.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1105", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes.(Citation: Aikido CanisterWorm MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026) [CanisterWorm](https://attack.mitre.org/software/S9042) has also downloaded kubectl to compromised environments if it was not already installed.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1036", "showSubtechniques": true}, {"techniqueID": "T1036.004", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has masqueraded itself as systemd or as a PostgreSQL utility named pgmon.(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1036.005", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1027", "showSubtechniques": true}, {"techniqueID": "T1027.009", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has used embedded second stage Base64-encoded payloads.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1677", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages.(Citation: Aikido TeamPCP Telnyx MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1018", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has scanned the local /24 subnet for new targets.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1053", "showSubtechniques": true}, {"techniqueID": "T1053.006", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has registered itself as a systemd service for persistence on targeted Kubernetes nodes.(Citation: Aikido CanisterWorm MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1528", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has gathered cloud access tokens.(Citation: FBI TeamPCP JUL 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1195", "showSubtechniques": true}, {"techniqueID": "T1195.001", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has spread through an automated process that infects and publishes npm packages.(Citation: Aikido TeamPCP Telnyx MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1614", "showSubtechniques": true}, {"techniqueID": "T1614.001", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component.(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1016", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1033", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has parsed the /var/log/auth.log and /var/log/secure files for usernames.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1569", "showSubtechniques": true}, {"techniqueID": "T1569.003", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1529", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has forced the target system to reboot after file deletion.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1124", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has checked if the target system\u2019s time zone is \u201cAsia/Tehran\u201d or \u201cIran.\u201d(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1552", "showSubtechniques": true}, {"techniqueID": "T1552.004", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has gathered SSH private keys from the .ssh file.(Citation: Aikido CanisterWorm MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1550", "showSubtechniques": true}, {"techniqueID": "T1550.001", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope.(Citation: Aikido TeamPCP Telnyx MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1497", "showSubtechniques": true}, {"techniqueID": "T1497.003", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments.(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1102", "showSubtechniques": true}, {"techniqueID": "T1102.001", "comment": "[CanisterWorm](https://attack.mitre.org/software/S9042) can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery.(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Aikido CanisterWorm MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by CanisterWorm", "color": "#66b1ff"}]}