TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.[1][2][3][4][5][6]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1098 | Account Manipulation |
TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.[4] |
|
| Enterprise | T1583 | Acquire Infrastructure |
In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.[8] |
|
| .001 | Domains |
TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints.[2][3][4][9][10][11][6][12] TeamPCP has also set up a dark web leak site to post stolen data.[5][13] |
||
| .004 | Server |
TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.[14][13] |
||
| .006 | Web Services |
TeamPCP has set up Clouflare Tunnels for malware C2.[2][4][15][6] TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID |
||
| Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
TeamPCP has dropped malware into the Windows Startup folder to establish persistence.[15] |
| Enterprise | T1059 | .004 | Command and Scripting Interpreter: Unix Shell |
TeamPCP has leveraged malware capable of execution via the Linux CLI.[14] |
| .006 | Command and Scripting Interpreter: Python |
TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.[14][15][6][14] |
||
| .007 | Command and Scripting Interpreter: JavaScript |
TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.[10][6] |
||
| .013 | Command and Scripting Interpreter: Container CLI/API |
TeamPCP has queried the Kubernetes API for local service account tokens and has used |
||
| Enterprise | T1543 | .002 | Create or Modify System Process: Systemd Service |
TeamPCP has used the systemd user service for malware persistence in targeted environments.[10] |
| Enterprise | T1555 | .006 | Credentials from Password Stores: Cloud Secrets Management Stores |
TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.[9][15][5][13] |
| Enterprise | T1485 | Data Destruction |
TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.[5] |
|
| Enterprise | T1486 | Data Encrypted for Impact |
TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums.[5] |
|
| Enterprise | T1005 | Data from Local System |
TeamPCP has stolen source code from victim environments including Mistral AI.[8] |
|
| Enterprise | T1587 | .001 | Develop Capabilities: Malware |
TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud.[2] |
| Enterprise | T1585 | .001 | Establish Accounts: Social Media Accounts |
TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications.[5][6][12] |
| Enterprise | T1546 | .016 | Event Triggered Execution: Installer Packages |
TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads.[11] |
| Enterprise | T1190 | Exploit Public-Facing Application |
TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.[4][15][5][11] |
|
| Enterprise | T1657 | Financial Theft |
TeamPCP has engaged in cryptocurrency mining and theft.[5][6] TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware.[8][12][13] |
|
| Enterprise | T1683 | .001 | Generate Content: Written Content |
TeamPCP has created Dune-themed GitHub repositories using stolen tokens.[11] |
| Enterprise | T1564 | .001 | Hide Artifacts: Hidden Files and Directories |
TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.[15] |
| Enterprise | T1105 | Ingress Tool Transfer |
TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.[10][15] |
|
| Enterprise | T1036 | .005 | Masquerading: Match Legitimate Resource Name or Location |
TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits.[4] TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.[15][5] |
| Enterprise | T1027 | .003 | Obfuscated Files or Information: Steganography |
TeamPCP has hidden malicious payloads in the frame data of WAV audio files.[15][5] |
| Enterprise | T1677 | Poisoned Pipeline Execution |
TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.[2][3][3][4][9][10][15][5][5][11][6][14][12][8][13][7] |
|
| Enterprise | T1684 | .001 | Social Engineering: Impersonation |
TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository.[2][4] |
| Enterprise | T1176 | .002 | Software Extensions: IDE Extensions |
TeamPCP has compromised VS Code and Open VSX IDE extensions.[10][15][6][12][8] |
| Enterprise | T1608 | .001 | Stage Capabilities: Upload Malware |
TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.[3] |
| Enterprise | T1528 | Steal Application Access Token |
TeamPCP has used malware to steal access tokens from targeted cloud and developer environments.[2][4][5][6][13] |
|
| Enterprise | T1553 | .002 | Subvert Trust Controls: Code Signing |
TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing.[6] |
| Enterprise | T1195 | .001 | Supply Chain Compromise: Compromise Software Dependencies and Development Tools |
TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.[2][3][10][15][5][11][6][14][12][8][13][7] |
| Enterprise | T1552 | .004 | Unsecured Credentials: Private Keys |
TeamPCP has used malware to extract SSH and GPG keys from victim environments.[2][5][13] |
| Enterprise | T1550 | .001 | Use Alternate Authentication Material: Application Access Token |
TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments.[2][15][5] |
| Enterprise | T1078 | Valid Accounts |
TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.[15] |
|
| .004 | Cloud Accounts |
TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.[2][3][4][10][5][11][6][6][12] |
||