{"description": "Enterprise techniques used by TeamPCP Cloud Stealer, ATT&CK software S9041 (v1.0)", "name": "TeamPCP Cloud Stealer (S9041)", "domain": "enterprise-attack", "versions": {"layer": "4.5", "attack": "19", "navigator": "5.3.2"}, "techniques": [{"techniqueID": "T1548", "showSubtechniques": true}, {"techniqueID": "T1548.003", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can use `sudo` for code execution.(Citation: Aqua Security Blog Trivy Compromise APR 2026)\n", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1071", "showSubtechniques": true}, {"techniqueID": "T1071.001", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has used `curl` to upload stolen data to attacker controlled domains.(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1560", "showSubtechniques": true}, {"techniqueID": "T1560.001", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has bundled collected data into a file named tpcp.tar.gz for exfiltration.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1119", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can identify and collect credentials across over 50 file paths in Cloud, CI/CD, developer tooling, and container enviornments.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1020", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there.(Citation: Wiz Trivy Compromise MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1580", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has the ability to search for generic GitHub runners.(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1526", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can search GitHub for Actions runner processes.(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1059", "showSubtechniques": true}, {"techniqueID": "T1059.004", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting.(Citation: Sysdig TeamPCP MAR 2026) (Citation: Palo Alto TeamPCP MAR 2026)\n", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059.006", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059.007", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has infected victims through malicious pre and post-install scripts within the package.json file.(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1609", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can use `kubectl get secrets` to extract credentials from Kubernetes.(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1613", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can identify Docker and Kubernetes environments for credentials.(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1543", "showSubtechniques": true}, {"techniqueID": "T1543.002", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can create a systemd unit to execute a python script for persistence.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1555", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys.(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: FBI TeamPCP JUL 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1555.006", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can enumerate multiple filesystem paths to extract credentials for AWS, GCP,  and Azure including Identity Access Management (IAM) credentials.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: FBI TeamPCP JUL 2026)(Citation: Google AI Threat Tracker MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1213", "showSubtechniques": true}, {"techniqueID": "T1213.003", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can target sensitive file paths in Git repos to extract credentials.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1213.006", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf.(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1074", "showSubtechniques": true}, {"techniqueID": "T1074.001", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has created a staging file in `/tmp` for collected data.(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1678", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has leveraged a persistence script that will sleep for five minutes before additional execution.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1140", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can deobfuscate an encoded Python script prior to execution.(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1573", "showSubtechniques": true}, {"techniqueID": "T1573.001", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1573.002", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1546", "showSubtechniques": true}, {"techniqueID": "T1546.016", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can inject malicious pre or post-install scripts within package.json for payload execution.(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1546.018", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has used .pth\u202ffiles to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup.(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1480", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube.(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026) ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1041", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1567", "showSubtechniques": true}, {"techniqueID": "T1567.001", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1008", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1083", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can identify files containing environment variables, SSH keys, cloud credentials, access tokens, and cryptocurrency wallets.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1657", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1564", "showSubtechniques": true}, {"techniqueID": "T1564.001", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor.(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1070", "showSubtechniques": true}, {"techniqueID": "T1070.004", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has the ability to remove all staged files after exfiltration.(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1105", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has the ability to download additional payloads to targeted systems.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1036", "showSubtechniques": true}, {"techniqueID": "T1036.005", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has installed a backdoor named sysmon.py on targeted systems.(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1027", "showSubtechniques": true}, {"techniqueID": "T1027.013", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has used multi-stage payloads with double Base64-encoded scripts to evade static analysis.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1003", "showSubtechniques": true}, {"techniqueID": "T1003.007", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can scrape memory from the Runner.Worker process by reading `/proc//mem` to extract secrets including plaintext tokens.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1057", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can locate GitHub Actions runner processes.(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1518", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has searched for cryptocurrency wallets on targeted hosts.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1528", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can read runner.worker process memory to extract plaintext tokens.(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: FBI TeamPCP JUL 2026)(Citation: Google AI Threat Tracker MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1082", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has detected if it is on a developer machine by checking if the environmental variable\u202f GITHUB_ACTIONS != \u201ctrue\u201d.(Citation: Wiz Trivy Compromise MAR 2026) [TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`.(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1016", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has the ability to enumerate network interfaces.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1049", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can search compromised systems for webhook URLs connecting to Slack and Discord.(Citation: Sysdig TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1033", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can use `whoami` on self-hosted runners to identify the current user.(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1552", "showSubtechniques": true}, {"techniqueID": "T1552.001", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: FBI TeamPCP JUL 2026)(Citation: Google AI Threat Tracker MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1552.003", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can target credentials in shell history on self-hosted runners.(Citation: Aqua Security Blog Trivy Compromise APR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1552.004", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has searched victim hosts for TLS and SSH keys.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1552.007", "comment": "[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) can query the Kubernetes API for credentials.(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by TeamPCP Cloud Stealer", "color": "#66b1ff"}]}