
Self-replicating software that infects machines in range, called worms, are a common sight in the cybersecurity world. However, it's not every day that a hacking group takes a small detour from its usual purpose of monetary gain to just up and wipe machines residing in a specific nation — in this case, Iran — all while using a novel control mechanism.
The TeamPCP collective, which seems to have formed recently, was in the news last December for targeting commonly used cloud hosting infrastructure software such as Docker, Kubernetes, Redis, and Next.js. The group's main goal appears to be building a proxy network that it (or, presumably, its customers) can use to launch ransomware and extortion attacks, among other malicious operations.