Ethical Hacking News
A new analysis has uncovered evidence that suggests TeamPCP has been operating since at least 2020. The threat actor, known for its supply chain attacks and cryptocurrency mining campaigns, continues to evolve its tactics with updates to its malware arsenal and operational methods.
TeamPCP, a new threat actor, has emerged with brazen supply chain attacks demonstrating sophistication. The team's origins date back to 2020, with evidence suggesting they've been operating in the shadows for years. Traffic indicates that TeamPCP exploits vulnerabilities in widely used software such as React Server Components, Next.js, Docker, Ray, and Redis. The group has successfully hijacked AI infrastructure into self-propagating botnets using cryptocurrency miners. Operations link TeamPCP's activities to earlier campaigns attributed to ShadowRay 2.0, with supply chain compromises through GitHub Actions and token theft abuse.
Threat actors have long been a thorn in the side of cybersecurity professionals, continually evolving their tactics and techniques to evade detection and wreak havoc on unsuspecting organizations. In recent years, a new threat actor has emerged, dubbed TeamPCP, which has made headlines with its brazen supply chain attacks that demonstrate an unsettling level of sophistication.
According to researchers at Oligo Security, the origins of TeamPCP date back as far as 2020, with evidence suggesting that this group has been operating in the shadows for several years, honing their skills and refining their methods. The team's modus operandi is marked by a focus on exploiting vulnerabilities in widely used software such as React Server Components (RSC), Next.js, Docker, Ray, and Redis.
Their early exploits revealed an unusual capacity to hijack artificial intelligence (AI) infrastructure into self-propagating botnets, including the notorious ShadowRay 2.0 campaign, which has garnered significant attention for its cunning tactics. In this campaign, TeamPCP successfully managed to exploit security flaws in popular software to deliver cryptocurrency miners onto exposed Redis servers.
Their subsequent campaigns have expanded to include TA-NATALSTATUS, a variant that targeted exposed Redis servers and delivered malicious payloads designed to mine cryptocurrency. These campaigns demonstrate an unsettling degree of cohesion, with the group continually updating their malware arsenal to stay ahead of detection. The team's tools have been observed employing Python scripts like "kube.py" for breaching Kubernetes environments.
Furthermore, researchers have identified operational links between TeamPCP's activities and earlier campaigns attributed to ShadowRay 2.0. These findings suggest that TeamPCP has indeed branched into high-profile supply chain compromises by weaponizing interconnected software to infect developer systems on an unprecedented scale through GitHub Actions and token theft abuse.
The implications of these findings are far-reaching, with security professionals scrambling to update their knowledge of the ever-evolving threat landscape. As researchers continue to unravel the complexities of TeamPCP's modus operandi, one thing becomes increasingly clear: this group represents a significant escalation in supply chain attacks that leverage modern software and cloud infrastructure.
Their activities serve as a stark reminder of the importance of vigilance and proactive security measures in the face of an ever-present threat landscape. As security experts continue to grapple with the implications of TeamPCP's tactics, one thing is certain: this group will undoubtedly remain a thorn in the side of cybersecurity professionals for years to come.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Shadowy-Operations-of-TeamPCP-A-Complex-Web-of-Cybercrime-and-Supply-Chain-Attacks-ehn.shtml
https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html
https://www.learnexplore.org/uncategorized/teampcp-linked-to-redis-attacks-dating-back-to-2020-and-later-supply-chain-campaign/
Published: Fri Aug 7 03:45:46 2026 by llama3.2 3B Q4_K_M