TeamPCP

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.[1][2][3][4][5][6]

ID: G1056
Associated Groups: PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058, UNC6780
Contributors: Kamei Risa, NEC Corporation; Sareena Karapoola, NEC Corporation India; Dhanvarshini Gopalsamy, NEC Corporation India; Rajkumar Barot; Jose Moya Villalba
Version: 1.0
Created: 16 July 2026
Last Modified: 31 July 2026

Associated Group Descriptions

Name Description
PCPCat

[5]

ShellForce

[5]

DeadCatx3

[5]

UNC6780

[7]

Techniques Used

Domain ID Name Use
Enterprise T1098 Account Manipulation

TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.[4]

Enterprise T1583 Acquire Infrastructure

In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.[8]

.001 Domains

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints.[2][3][4][9][10][11][6][12] TeamPCP has also set up a dark web leak site to post stolen data.[5][13]

.004 Server

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.[14][13]

.006 Web Services

TeamPCP has set up Clouflare Tunnels for malware C2.[2][4][15][6] TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via  *.getsession[.]org to recipient  ID 05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026.[11]

Enterprise T1547 .001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

TeamPCP has dropped malware into the Windows Startup folder to establish persistence.[15]

Enterprise T1059 .004 Command and Scripting Interpreter: Unix Shell

TeamPCP has leveraged malware capable of execution via the Linux CLI.[14]

.006 Command and Scripting Interpreter: Python

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.[14][15][6][14]

.007 Command and Scripting Interpreter: JavaScript

TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.[10][6]

.013 Command and Scripting Interpreter: Container CLI/API

TeamPCP has queried the Kubernetes API for local service account tokens and has used kubectl for lateral movement.[12][10]

Enterprise T1543 .002 Create or Modify System Process: Systemd Service

TeamPCP has used the systemd user service for malware persistence in targeted environments.[10]

Enterprise T1555 .006 Credentials from Password Stores: Cloud Secrets Management Stores

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.[9][15][5][13]

Enterprise T1485 Data Destruction

TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.[5]

Enterprise T1486 Data Encrypted for Impact

TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums.[5]

Enterprise T1005 Data from Local System

TeamPCP has stolen source code from victim environments including Mistral AI.[8]

Enterprise T1587 .001 Develop Capabilities: Malware

TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud.[2]

Enterprise T1585 .001 Establish Accounts: Social Media Accounts

TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications.[5][6][12]

Enterprise T1546 .016 Event Triggered Execution: Installer Packages

TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads.[11]

Enterprise T1190 Exploit Public-Facing Application

TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.[4][15][5][11]

Enterprise T1657 Financial Theft

TeamPCP has engaged in cryptocurrency mining and theft.[5][6] TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware.[8][12][13]

Enterprise T1683 .001 Generate Content: Written Content

TeamPCP has created Dune-themed GitHub repositories using stolen tokens.[11]

Enterprise T1564 .001 Hide Artifacts: Hidden Files and Directories

TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.[15]

Enterprise T1105 Ingress Tool Transfer

TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.[10][15]

Enterprise T1036 .005 Masquerading: Match Legitimate Resource Name or Location

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits.[4] TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.[15][5]

Enterprise T1027 .003 Obfuscated Files or Information: Steganography

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.[15][5]

Enterprise T1677 Poisoned Pipeline Execution

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.[2][3][3][4][9][10][15][5][5][11][6][14][12][8][13][7]

Enterprise T1684 .001 Social Engineering: Impersonation

TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository.[2][4]

Enterprise T1176 .002 Software Extensions: IDE Extensions

TeamPCP has compromised VS Code and Open VSX IDE extensions.[10][15][6][12][8]

Enterprise T1608 .001 Stage Capabilities: Upload Malware

TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.[3]

Enterprise T1528 Steal Application Access Token

TeamPCP has used malware to steal access tokens from targeted cloud and developer environments.[2][4][5][6][13]

Enterprise T1553 .002 Subvert Trust Controls: Code Signing

TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing.[6]

Enterprise T1195 .001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.[2][3][10][15][5][11][6][14][12][8][13][7]

Enterprise T1552 .004 Unsecured Credentials: Private Keys

TeamPCP has used malware to extract SSH and GPG keys from victim environments.[2][5][13]

Enterprise T1550 .001 Use Alternate Authentication Material: Application Access Token

TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments.[2][15][5]

Enterprise T1078 Valid Accounts

TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.[15]

.004 Cloud Accounts

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.[2][3][4][10][5][11][6][6][12]

Software

ID Name References Techniques
S9042 CanisterWorm TeamPCP has used CanisterWorm in credential harvesting and software supply chain campaigns since at least 2026.[15][5][16][17][13] Abuse Elevation Control Mechanism: Sudo and Sudo Caching, Command and Scripting Interpreter: Unix Shell, Command and Scripting Interpreter: Python, Command and Scripting Interpreter: JavaScript, Container Administration Command, Container and Resource Discovery, Create or Modify System Process, Credentials from Password Stores: Cloud Secrets Management Stores, Data Destruction, Deobfuscate/Decode Files or Information, Execution Guardrails, File and Directory Discovery, Indicator Removal: File Deletion, Ingress Tool Transfer, Masquerading: Masquerade Task or Service, Masquerading: Match Legitimate Resource Name or Location, Obfuscated Files or Information: Embedded Payloads, Poisoned Pipeline Execution, Remote System Discovery, Scheduled Task/Job: Systemd Timers, Steal Application Access Token, Supply Chain Compromise: Compromise Software Dependencies and Development Tools, System Location Discovery: System Language Discovery, System Network Configuration Discovery, System Owner/User Discovery, System Services: Systemctl, System Shutdown/Reboot, System Time Discovery, Unsecured Credentials: Private Keys, Use Alternate Authentication Material: Application Access Token, Virtualization/Sandbox Evasion: Time Based Checks, Web Service: Dead Drop Resolver
S9043 Mini Shai-Hulud TeamPCP has used Mini Shai-Hulud in supply chain campaigns targeting CI/CD workflows.[11][6][14][12][8][13] Account Discovery: Cloud Account, Application Layer Protocol: Web Protocols, Archive Collected Data: Archive via Utility, Archive Collected Data, Automated Collection, Command and Scripting Interpreter: Container CLI/API, Command and Scripting Interpreter: Python, Command and Scripting Interpreter: JavaScript, Compromise Host Software Binary, Container Administration Command, Create or Modify System Process: Launch Agent, Create or Modify System Process: Systemd Service, Credentials from Password Stores: Password Managers, Credentials from Password Stores: Cloud Secrets Management Stores, Data Destruction, Data Encoding: Standard Encoding, Data from Information Repositories: Code Repositories, Deobfuscate/Decode Files or Information, Event Triggered Execution: Python Startup Hooks, Event Triggered Execution, Execution Guardrails, Exfiltration Over C2 Channel, Exfiltration Over Web Service: Exfiltration to Code Repository, Fallback Channels, File and Directory Discovery, Hide Artifacts: Ignore Process Interrupts, Indicator Removal: File Deletion, Ingress Tool Transfer, Inter-Process Communication, Masquerading: Match Legitimate Resource Name or Location, Obfuscated Files or Information: Encrypted/Encoded File, OS Credential Dumping: Proc Filesystem, Poisoned Pipeline Execution, Proxy: Multi-hop Proxy, Remote Services: Cloud Services, Scheduled Task/Job: Systemd Timers, Steal Application Access Token, Steal or Forge Authentication Certificates, Supply Chain Compromise: Compromise Software Dependencies and Development Tools, System Information Discovery, System Location Discovery, System Location Discovery: System Language Discovery, System Network Configuration Discovery, System Owner/User Discovery, System Time Discovery, Traffic Signaling, Unsecured Credentials: Container API, Unsecured Credentials: Credentials In Files, Unsecured Credentials: Private Keys, Unsecured Credentials: Cloud Instance Metadata API, Use Alternate Authentication Material: Application Access Token, Valid Accounts: Cloud Accounts, Virtualization/Sandbox Evasion: System Checks, Virtualization/Sandbox Evasion, Web Service: Dead Drop Resolver
S9041 TeamPCP Cloud Stealer TeamPCP has used TeamPCP Cloud Stealer in credential harvesting and exfiltration.[2][3][4][9][10][5] Abuse Elevation Control Mechanism: Sudo and Sudo Caching, Application Layer Protocol: Web Protocols, Archive Collected Data: Archive via Utility, Automated Collection, Automated Exfiltration, Cloud Infrastructure Discovery, Cloud Service Discovery, Command and Scripting Interpreter: JavaScript, Command and Scripting Interpreter: Python, Command and Scripting Interpreter: Unix Shell, Container Administration Command, Container and Resource Discovery, Create or Modify System Process: Systemd Service, Credentials from Password Stores, Credentials from Password Stores: Cloud Secrets Management Stores, Data from Information Repositories: Code Repositories, Data from Information Repositories: Databases, Data Staged: Local Data Staging, Delay Execution, Deobfuscate/Decode Files or Information, Encrypted Channel: Symmetric Cryptography, Encrypted Channel: Asymmetric Cryptography, Event Triggered Execution: Installer Packages, Event Triggered Execution: Python Startup Hooks, Execution Guardrails, Exfiltration Over C2 Channel, Exfiltration Over Web Service: Exfiltration to Code Repository, Fallback Channels, File and Directory Discovery, Financial Theft, Hide Artifacts: Hidden Files and Directories, Indicator Removal: File Deletion, Ingress Tool Transfer, Masquerading: Match Legitimate Resource Name or Location, Obfuscated Files or Information: Encrypted/Encoded File, OS Credential Dumping: Proc Filesystem, Process Discovery, Software Discovery, Steal Application Access Token, System Information Discovery, System Network Configuration Discovery, System Network Connections Discovery, System Owner/User Discovery, Unsecured Credentials: Shell History, Unsecured Credentials: Container API, Unsecured Credentials: Credentials In Files, Unsecured Credentials: Private Keys

References