Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TeamPCP’s Cyber Attacks Trace Back to 2020, Supply Chain Risks

TeamPCP’s Cyber Attacks Trace Back to 2020, Supply Chain Risks

Posted on August 7, 2026 By CWS

TeamPCP’s Cyber Activities Unveiled

Recent investigations have revealed that the cybercrime group known as TeamPCP has been active since 2020, focusing initially on internet-facing infrastructure and later expanding to software supply chain attacks. This long-standing activity was identified through similarities in domains, malware deployment methods, and operational techniques, according to Oligo Security researchers Avi Lumelsky and Gal Elbaz.

Key Campaigns and Techniques

Among the prominent campaigns attributed to TeamPCP are ShadowRay 2.0 and TA-NATALSTATUS. The former targeted artificial intelligence systems to create a self-replicating botnet, while the latter exploited Redis servers to deploy cryptocurrency miners. These campaigns demonstrate the group’s consistent focus on internet-exposed infrastructures, utilizing technologies like Ray, Docker, Redis, and React.

Initial evidence of TeamPCP’s activities emerged last year, linking the group to vulnerabilities in React Server Components and Next.js, which were used to steal credentials and sensitive data. This operation, named PCPcat, marked the beginning of their focus on exploiting cloud environments.

Expansion into Supply Chain Attacks

Earlier this year, Flare detailed TeamPCP’s extensive campaign targeting cloud-native environments. Their objectives included establishing a distributed proxy and scanning infrastructure, compromising servers for data extraction, ransomware deployment, extortion, and cryptocurrency mining. These operations highlight the group’s strategy of leveraging cloud infrastructure for malicious purposes.

Their transition into software supply chain compromises further illustrates their evolving tactics. By exploiting interconnected software systems, TeamPCP has managed to infect developer systems through methods like GitHub Actions manipulation and token theft.

Continued Evolution and Impact

Ongoing analysis shows that TeamPCP continues to exploit known vulnerabilities in platforms such as React, Docker, Redis, and Ray. Their methods include automated and self-propagating attacks, marking a significant evolution in their threat capabilities.

Their malware arsenal is also evolving, as evidenced by the use of the Python script “kube.py” in Kubernetes environments. Initially designed for propagation and persistence, new variants have introduced destructive features targeting specific regions, such as the Iran timezone, where a wiper named Kamikaze is deployed to erase data.

While it remains uncertain if TeamPCP represents a rebranded entity or a collaborative effort among related actors, the evidence suggests they are part of an ongoing operational ecosystem rather than a new threat actor emerging in late 2025.

The Hacker News Tags:Cybercrime, Cybersecurity, Docker, GitHub, Kubernetes, Malware, React, Redis, supply chain attacks, TeamPCP

Post navigation

Previous Post: Top Network Detection Tools for 2026
Next Post: 3.8 Million Affected by Major Unlimited Technology Systems Breach

Related Posts

APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine The Hacker News
The Hidden Risk of Orphan Accounts The Hidden Risk of Orphan Accounts The Hacker News
TA446 Uses DarkSword Exploit in Spear-Phishing Campaign TA446 Uses DarkSword Exploit in Spear-Phishing Campaign The Hacker News
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager The Hacker News
New Malware Campaigns Highlight Rising AI and Phishing Risks New Malware Campaigns Highlight Rising AI and Phishing Risks The Hacker News
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Unveils GPT-5.6 with Unlimited Chat Access
  • 3.8 Million Affected by Major Unlimited Technology Systems Breach
  • TeamPCP’s Cyber Attacks Trace Back to 2020, Supply Chain Risks
  • Top Network Detection Tools for 2026
  • Chrome 151 Update Addresses Major Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Unveils GPT-5.6 with Unlimited Chat Access
  • 3.8 Million Affected by Major Unlimited Technology Systems Breach
  • TeamPCP’s Cyber Attacks Trace Back to 2020, Supply Chain Risks
  • Top Network Detection Tools for 2026
  • Chrome 151 Update Addresses Major Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark