TeamPCP’s Cyber Activities Unveiled
Recent investigations have revealed that the cybercrime group known as TeamPCP has been active since 2020, focusing initially on internet-facing infrastructure and later expanding to software supply chain attacks. This long-standing activity was identified through similarities in domains, malware deployment methods, and operational techniques, according to Oligo Security researchers Avi Lumelsky and Gal Elbaz.
Key Campaigns and Techniques
Among the prominent campaigns attributed to TeamPCP are ShadowRay 2.0 and TA-NATALSTATUS. The former targeted artificial intelligence systems to create a self-replicating botnet, while the latter exploited Redis servers to deploy cryptocurrency miners. These campaigns demonstrate the group’s consistent focus on internet-exposed infrastructures, utilizing technologies like Ray, Docker, Redis, and React.
Initial evidence of TeamPCP’s activities emerged last year, linking the group to vulnerabilities in React Server Components and Next.js, which were used to steal credentials and sensitive data. This operation, named PCPcat, marked the beginning of their focus on exploiting cloud environments.
Expansion into Supply Chain Attacks
Earlier this year, Flare detailed TeamPCP’s extensive campaign targeting cloud-native environments. Their objectives included establishing a distributed proxy and scanning infrastructure, compromising servers for data extraction, ransomware deployment, extortion, and cryptocurrency mining. These operations highlight the group’s strategy of leveraging cloud infrastructure for malicious purposes.
Their transition into software supply chain compromises further illustrates their evolving tactics. By exploiting interconnected software systems, TeamPCP has managed to infect developer systems through methods like GitHub Actions manipulation and token theft.
Continued Evolution and Impact
Ongoing analysis shows that TeamPCP continues to exploit known vulnerabilities in platforms such as React, Docker, Redis, and Ray. Their methods include automated and self-propagating attacks, marking a significant evolution in their threat capabilities.
Their malware arsenal is also evolving, as evidenced by the use of the Python script “kube.py” in Kubernetes environments. Initially designed for propagation and persistence, new variants have introduced destructive features targeting specific regions, such as the Iran timezone, where a wiper named Kamikaze is deployed to erase data.
While it remains uncertain if TeamPCP represents a rebranded entity or a collaborative effort among related actors, the evidence suggests they are part of an ongoing operational ecosystem rather than a new threat actor emerging in late 2025.
