SecBoard
Alle Akteure & Werkzeuge
BedrohungsakteurG1056

TeamPCP

Alias-Namen: PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058, UNC6780

Meldungen

26

letzte 90 Tage

8

erstmals

23.03.2026

zuletzt

27.08.2026

Profil laut MITRE ATT&CK

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.

Vollständiges MITRE-Profil

Beschreibung und Alias-Namen stammen aus MITRE ATT&CK®.

Nennungen im Zeitverlauf

09
10
11
12
01
02
03
04
05
06
07
08

Meldungen je Monat, letzte 12 Monate.

Beobachtete Techniken

ATT&CK-Techniken, die in denselben Meldungen benannt sind — nicht das vollständige MITRE-Repertoire.

Schwachstellen im selben Kontext

CVEs, die in denselben Meldungen auftauchen. Ko-Okkurrenz, kein Nachweis einer Ausnutzung.

Gemeinsam genannt

Betroffene Branchen

Meldungen

Australia arrests alleged TeamPCP hackers behind supply-chain attacks

BleepingComputer·27.08.2026

Australia Arrests 2 Alleged TeamPCP Hackers

SecurityWeek·27.08.2026

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

The Hacker News·27.08.2026

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

KrebsOnSecurity·27.08.2026

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

The Hacker News·07.08.2026

The serpent’s tongue: Luring the Python out of its den

Cisco Talos·14.07.2026

Vect and TeamPCP partner for ransomware campaigns

Sophos X-Ops·02.07.2026

Containers on fire: from container escapes to supply chain attacks

Securelist·01.06.2026

The Hackers Behind Shai-Hulud: Lucky or Skilled?

Dark Reading·26.05.2026

GitHub Confirms Breach, 4K Internal Repos Stolen

Dark Reading·20.05.2026

GitHub Confirms Hack Impacting 3,800 Internal Repositories

SecurityWeek·20.05.2026

GitHub investigates internal repositories breach claimed by TeamPCP

BleepingComputer·20.05.2026

GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories

The Hacker News·20.05.2026

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

The Hacker News·18.05.2026

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code

SecurityWeek·15.05.2026

TeamPCP hackers advertise Mistral AI code repos for sale

BleepingComputer·14.05.2026

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

The Hacker News·12.05.2026

Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain

Dark Reading·12.05.2026

TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack

The Hacker News·11.05.2026

‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials

SecurityWeek·08.05.2026

After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets

Dark Reading·07.05.2026

New PCPJack worm steals credentials, cleans TeamPCP infections

BleepingComputer·07.05.2026

PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems

The Hacker News·07.05.2026

TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack

Dark Reading·30.04.2026

Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error

Dark Reading·29.04.2026

‘CanisterWorm’ Springs Wiper Attack Targeting Iran

KrebsOnSecurity·23.03.2026

Quellen: The Hacker News (7), Dark Reading (6), BleepingComputer (4), SecurityWeek (4), KrebsOnSecurity (2), Cisco Talos (1), Sophos X-Ops (1), Securelist (1)

Alle Angaben auf dieser Seite stammen aus dem Alias-Abgleich der Meldungstexte gegen den MITRE-ATT&CK-Katalog. Beziehungen entstehen rein statistisch: Zwei Einträge gelten als verbunden, wenn sie in derselben Meldung benannt sind. Das ist keine eigenständige Attribution durch SecBoard, und eine Nennung ist kein Nachweis einer Täterschaft.