Threat group.View on attack.mitre.org
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
TeamPCP has stolen source code from victim environments including Mistral AI. |
| T1027.003 Steganography |
TeamPCP has hidden malicious payloads in the frame data of WAV audio files. |
| T1036.005 Match Legitimate Resource Name or Location |
TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads. |
| T1059.004 Unix Shell |
TeamPCP has leveraged malware capable of execution via the Linux CLI. |
| T1059.006 Python |
TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection. |
| T1059.007 JavaScript |
TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions. |
| T1059.013 Container CLI/API |
TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement. |
| T1078 Valid Accounts |
TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to. |
| T1078.004 Cloud Accounts |
TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines. |
| T1098 Account Manipulation |
TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public. |
| T1105 Ingress Tool Transfer |
TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2. |
| T1176.002 IDE Extensions |
TeamPCP has compromised VS Code and Open VSX IDE extensions. |
| T1190 Exploit Public-Facing Application |
TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints. |
| T1195.001 Compromise Software Dependencies and Development Tools |
TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1485 Data Destruction |
TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.