Country of origin for TeamPCP remains unknown, and cybersecurity researchers have not attributed the group to any specific nnation-state with confidence.
Attribution Challenges & False Flags
The group actively employs false flag operations to obscure its true location and mislead investigators:
Russian Markers: Malware samples contain Russian cultural references (e.g., Koschei, Baba Yaga) and code that exempts systems with Russian language settings (ru_* locale).
Contradictory Targets: Despite the Russian markers, the group deploys destructive wipers against Iranian infrastructure and includes logic targeting Israeli systems, creating conflicting geopolitical signals.
Analyst Consensus: Firms like Antiy Labs and Gurucul assess these markers as deliberate noise designed to fail traditional attribution mechanisms rather than authentic indicators of origin.
Operational Indicators
While the physical location is unconfirmed, some operational details offer limited geographic clues:
Infrastructure: Early command-and-control servers were hosted in Singapore, with additional infrastructure linked to the U.S. and UAE.
Affiliate Base: Their partner, Vect Ransomware Group, waives entry fees for affiliates from CIS countries (Russia and former Soviet states), suggesting a potential operational focus or membership base in that region, though this does not confirm TeamPCPs own origin.
Language: Communications are primarily in English, often with non-native phrasing, and occasional references to African politics (specifically Kenya) have been noted in their Telegram channels, though these are considered weak indicators.
TeamPCP (also tracked as PCPcat, DeadCatx3, ShellForce, and CipherForce) is a financially and geopolitically motivated cybercriminal group that emerged in late 2025, specializing in cloud-native infrastructure and software supply chain attacks. The group initially conducted large-scale worm-driven campaigns exploiting exposed Docker APIs, Kubernetes clusters, and Redis instances to build botnets for ransomware and cryptomining.
In March 2026, TeamPCP shifted tactics to compromise widely used CI/CD security tools, including Trivy, Checkmarx KICS, and LiteLLM. By stealing GitHub Actions tokens and PyPI publishing credentials, they deployed a TeamPCP Cloud Stealer payload designed to harvest cloud provider credentials (AWS, GCP, Azure), SSH keys, and Kubernetes tokens. The group utilizes novel infrastructure such as Internet Computer Protocol (ICP) blockchain canisters for command-and-control and employs self-propagating worms like CanisterWorm to infect additional packages across npm and PyPI.
Key operational characteristics include:
Hybrid Motivation: Primarily driven by financial gain through credential theft and access brokering, with secondary geopolitical objectives including destructive attacks on Iranian infrastructure.
Cascading Compromise: They leverage stolen credentials from one compromised tool to gain access to the next, creating a multi-ecosystem supply chain attack across GitHub, Docker Hub, npm, and PyPI.
Operational Security: Uses RSA-4096/AES-256-CBC encryption for exfiltration, typosquatted domains (e.g., aquasecurtiy[.]org), and YouTube kill-switches in backdoor payloads.
Partnerships: Functions as an access generation engine feeding into ransomware ecosystems, with formal partnerships noted with Vect Ransomware Group and collaborations with Lapsus$.
TeamPCP operates as a primary initial access broker, maintaining a complex web of partnerships to monetize stolen credentials through ransomware deployment and data extortion. Their specific partners include:
Primary Ransomware & Extortion Partners
Vect Ransomware Group
In late March 2026, TeamPCP announced a formal operational partnership with Vect, a Russian-speaking Ransomware-as-a-Service (RaaS) operation. Under this agreement, TeamPCP supplies the initial access gained through supply chain compromises (specifically the Trivy, KICS, and LiteLLM attacks), while Vect handles the encryption deployment and extortion. Sophos confirmed by July 2026 that Vect had successfully deployed ransomware using credentials sourced directly from TeamPCP operations.
Lapsus$
TeamPCP explicitly collaborates with the notorious extortion group Lapsus$ to monetize stolen data. Following the March 2026 supply chain campaigns, TeamPCP transferred approximately 300 GB of compressed credentials to Lapsus$, who utilized them to target multi-billion-dollar companies and sell access on thedark web. Mandiant and Wiz researchers confirmed this active collaboration, noting that Lapsus$ leverages TeamPCPs deep access to SaaS environments for high-profile data leaks.
Operational & Ecosystem Allies
xpl0itrs
This group maintains a close technical partnership with TeamPCP, engaging in joint operations such as the CanisterWorm deployment and the Bitwarden CLI compromise in April 2026. xpl0itrs functions as a secondary outlet for TeamPCPs initial access, sharing tooling and victim lists within a tightly integrated supply chain-focused cybercrime ecosystem.
BreachForums
While technically a marketplace, BreachForums serves as a critical force multiplier through its formal alliance with Vect and TeamPCP. In April 2026, the partnership facilitated the distribution of affiliate keys to BreachForums entire user base (approx. 300,000 members), effectively industrializing the distribution of TeamPCP-sourced access for mass ransomware campaigns.
ShinyHunters / UNC6240
TeamPCP brokers access to ShinyHunters (also tracked as UNC6240), who utilize the stolen credentials for large-scale repository cloning and data theft. Notable instances include the cloning of over 300 private Cisco repositories containing AI products and sensitive customer code.
Internal Monetization Brands
TeamPCP also operates its own parallel monetization tracks to ensure redundancy:
CipherForce: TeamPCPs proprietary ransomware brand, used for direct operations separate from the Vect partnership.
ShellForce: A persona used specifically for leaking and selling exfiltrated data.
TeamPCP has established a sophisticated ecosystem of partnerships designed to industrialize the monetization of stolen credentials, moving beyond simple data theft to coordinated ransomware deployment and large-scale extortion. These alliances function as a reverse kill chain, where access is secured via supply chain compromises first, and targets are selected from the resulting credential archive later.
The Vect-BreachForums Industrial Alliance
The most significant partnership is the formal triadbetween TeamPCP, Vect Ransomware Group, and BreachForums. Announced in late March 2026 and operationalized on April 16, 2026, this alliance created an unprecedented mass-affiliate model:
Role Division: TeamPCP acts as the exclusive initial access broker, supplying credentials harvested from compromised CI/CD tools (Trivy, KICS, LiteLLM). Vect provides the ransomware infrastructure (C++ based ChaCha20-Poly1305 encryption), while BreachForums supplies the human capital.
Scalen of Mobilization: Unlike traditional RaaS models that recruit affiliates selectively, this partnership distributed Vect affiliate keys to all ~300,000 registered users of BreachForums simultaneously. This effectively converted a massive forum user base into an instant ransomware deployment army.
Operational Impact: By July 2026, Sophos confirmed active ransomwaren deployments where Vect operators selected victims directly from TeamPCPs stolen credential archives. This model removes the need for affiliates to possess technical exploitation skills, as the entry ticket (valid cloud tokens) is pre-supplied by TeamPCP.
Extortion and Data Monetization Partners
To maximize the value of exfiltrated data (estimated at 300 GB of compressed credentials), TeamPCP collaborates with specialized extortion groups:
Lapsus$
TeamPCP maintains an explicitcollaboration with Lapsus$ to handle high-profile extortioncampaigns. While TeamPCP focuses on the technical infiltration of SaaSenvironments, Lapsus$ leverages its reputation for aggressive public shamingand social engineering to pressure victims. Wiz researchers confirmed thatTeamPCP transfers validated credentials to Lapsus$, who then targetmulti-billion-dollar companies for data leaks and ransom demands.
ShinyHunters (UNC6240)
A critical operational linkexists between TeamPCP and ShinyHunters. Following the March 2026 Trivycompromise, credentials harvested by TeamPCP were utilized by ShinyHunters tobreach Cisco. This collaboration resulted in the cloning of over 300private GitHub repositories, including source code for AI products andtools used by US government agencies (FBI, DHS, NASA). Thispartnership highlights a hand-off model where TeamPCP provides thefoothold, and ShinyHunters executes the deep data exfiltration.
*The relationshipbetween TeamPCP and ShinyHunters (alsotracked as UNC6240) is hostile and opportunistic, rather than a formalpartnership. While they operate in the same ecosystem, theirinteractions are defined by theft, deception, and conflicting publicnarratives.
The Scam and Hostile Takeover
Contrary to early reports ofcollaboration, TeamPCP leadershiphas explicitly stated that ShinyHunters is not a partner. Ina May 9, 2026 interview, the TeamPCP leader detailed a specific incident ofbetrayal:
The Infiltration:
A memberof ShinyHunters infiltrated the private operator chatof Vect (TeamPCPs ransomware partner), demonstrating a failurein TeamPCPs vetting or access control mechanisms for their own criminalecosystem.
The Theft:
The ShinyHunters member agreed tosplit profits on a bundle of stolen credentials, downloaded the data, andthen refused to pay.
The Smear:
To cover the theft and discreditTeamPCP, ShinyHunters released a mix of real and fabricated chatsportraying the interaction as a legitimate partnership or dispute, rather thana scam.
· Data Handover:
The thief was able to download a fullbundle of stolen credentials after agreeing to a profit-split, indicating thatTeamPCP lacks technical safeguards (such as staged data releases or escrowmechanisms) to prevent partners or infiltrators from absconding with the entiredataset.
· Reactive Counter-Measures
Once the theft was identified, TeamPCPemployed the following damage control tactics:
· Public Discrediting:
In a May 9, 2026 interviewwith Inside Darknet, the TeamPCP leader explicitly labeled theinteraction a scam and shitty business practice, aimingto destroy ShinyHunters reputation within the cybercriminal underground.
· Narrative Correction:
They released a mix of real andfabricated chats (mirroring ShinyHunters own tactics) to prove the theftoccurred and to distance themselves from subsequent high-profile breaches (likethe CERT-EU attack) that ShinyHunters executed using thestolen data.
· Attribution Shift:
TeamPCP leadership publicly clarified theirnon-involvement in government targets (We dont even target gov),attempting to shift the blame for the CERT-EU breach entirely onto ShinyHuntersto avoid law enforcement scrutiny.
Strategic Implications
The incident highlights that TeamPCPs security model is trust-based withina hostile environment. They have no technical method to revokeaccess to credentials once they are downloaded by an affiliate or partner.Their primary defense is the threat of reputational ruin andthe potential for retaliatory doxxing or law enforcement tipping, which servesas the only deterrent against internal theft in the cybercriminal ecosystem.
Divergent Operational Goals
The two groups havefundamentally different targeting doctrines, which led to friction overspecific breaches:
Targeting Conflicts:
TeamPCP publicly claims to exclude governments and non-profits from their directoperations. However, ShinyHunters used the stolenTeamPCP-sourced credentials to breach the European Commission (CERT-EU),stealing 340 GB of data from 42 EU departments. TeamPCPleaders subsequently clarified they did not perform this exfiltration and donot target government entities, attributing the act solely to ShinyHunters.
Cisco Breach:
While TeamPCPprovided the initial access vector (via the compromised Trivy scanner), ShinyHunters independentlyexecuted the deep intrusion into Cisco, cloning over 300 privaterepositories (including AI and government-related code) andlaunching their own extortion campaign with an April 3 deadline.
The Convergence Dynamic
Despite the hostility, the groupsare functionally linked in a convergence of cybercriminalecosystems:
Access vs. Extortion:
TeamPCPacts as the initial access broker, compromising the supplychain to harvest credentials. ShinyHunters acts asa predatory downstream actor, monitoring these compromisesto steal the harvested credentials for their own high-profile extortioncampaigns.
Blast Radius:
This dynamic means that even without a formalagreement, TeamPCPs compromises directly enable ShinyHunters operations.Security researchers note that this creates a complex threat landscapewhere defenders must contend with multiple independent groups exploiting thesame initial breach.
Technical and Operational Allies
xpl0itrs Thisgroup serves as TeamPCPs primary technical co-conspirator. They jointlydeveloped and deployed CanisterWorm, the first self-propagating npmworm utilizing Internet Computer Protocol (ICP) canisters forcommand-and-control. Their partnership extends to the BitwardenCLI compromise in April 2026. xpl0itrs often acts as asecondary outlet for selling access derived from TeamPCPs initial breaches,such as the alleged 569 GB breach of RapidFort claimed in July2026.
Internal Redundancy:
CipherForce
To ensure operational resilienceand avoid reliance solely on external partners, TeamPCP operates its ownproprietary ransomware brand, CipherForce. While theVect partnership handles mass distribution via BreachForums, CipherForce isused for direct, controlled operations where TeamPCP retains full authorityover encryption and negotiation, allowing them to test new tactics without exposingtheir primary affiliates.
TeamPCP compromised a specificset of high-value CI/CD and developer security toolsbetween March 19 and April 22, 2026, executing a cascading attackwhere credentials stolen from one tool were used to compromise the next.
Primary CI/CD & Security Tool Compromises
Trivy (Aqua Security)
Compromise Date: March 19, 2026 (following an initial breach on Feb 28).
Vector: TeamPCP exploited a pull_request_target vulnerability to steal a GitHub Actions PAT, then hijacked release tags (v0.69.4) to inject malware into GitHub Actions, binaries, and Docker Hub images.
Impact: As the initial pivot point, this compromise provided the GitHub Actions tokens and cloud credentials used to attack subsequent tools.
Checkmarx KICS (Keeping Infrastructure as CodeSecure)
Compromise Date: March 23, 2026.
Vector: Using credentials harvested from the Trivy compromise, the group poisoned KICS GitHub Actions (all 35 tags), OpenVSX extensions, and Docker images.
Impact: Allowed the theft of Infrastructure-as-Code secrets and further expanded access to enterprise cloud environments.
LiteLLM (BerriAI)
Compromise Date: March 24, 2026.
Vector: Compromised PyPI publishing credentials (stolen from CI/CD pipelines running the trojanized Trivy action) to publish malicious versions 1.82.7 and 1.82.8.
Impact: Targeted AI infrastructure, harvesting API keys for over 100 LLM providers (OpenAI, Anthropic, etc.) alongside cloud credentials.
Telnyx Python SDK
Compromise Date: March 27, 2026.
Vector: Similar to LiteLLM, malicious versions were published to PyPI using stolen publishing rights.
Impact: Compromised telecommunications API credentials and messaging workflows integrated into CI/CD pipelines.
Secondary & Related Compromises
Bitwarden CLI
Compromise Date: April 22, 2026.
Vector: A malicious version (2026.4.0) was published to npm by exploiting a compromised GitHub Action in Bitwardens CI/CD pipeline (linked to the broader TeamPCP campaign).
Impact: Targeted developer workstations and pipelines to harvest SSH keys, crypto wallet data, and npm tokens, utilizing a self-propagating worm mechanism.
TanStack & Others
The campaign also affected TanStack (via OIDC abuse in April 2026) and over 45 npm packages (including @EmilGroup and @opengov) via a self-propagating worm (deploy.js) that autonomously published malicious patch versions using stolen tokens.
The triad consistingof TeamPCP, Vect Ransomware Group,and BreachForums operates as an integrated, industrialized ransomwareecosystem rather than three separate entities collaboratingad-hoc. Their relationship is defined by a strict division of labor that inverts the traditional ransomware kill chain:
Operational Workflow: The Reverse KillChain
1. TeamPCP:The Access Engine (Supply Chain Layer)
TeamPCP functions exclusively asthe initial access broker. Instead of selecting specificvictims first, they compromise high-volume software supply chain components(e.g., Trivy, LiteLLM, KICS) to harvest amassive archive of over 500,000 credentials from CI/CDpipelines. They do not deploy ransomware themselves in this triad;their sole output is a validated inventory of compromised cloud tokens and APIkeys.
2. Vect:The Monetization Infrastructure (RaaS Layer)
Vect provides theweaponization and extortion capability. Unlike traditional RaaS models whereaffiliates must find their own way into a network, Vect operators simply searchTeamPCPs pre-existing credential archive to selectvictims. Vect supplies the C++ ransomware payload (usingChaCha20-Poly1305 encryption), the TOR-based leak site, and thenegotiation infrastructure. This allows affiliates to skip theexploitation phase entirely and move straight to deployment.
3. BreachForums: The Distribution & OperationalLayer
BreachForums serves asthe force multiplier and operational platform. On April 16, 2026,the triad operationalized a mass-affiliate model where all ~300,000registered BreachForums users were automatically issued Vect affiliatekeys. The forum provides:
Escrow Services: A Monero-based multi-signature escrow system for handling ransom payments.
Affiliate Management: Tiered incentive structures (offering up to 88% profit share) and support for less technical operators.
Instant Mobilization: Converting a passive forum user base into an active ransomware deployment army without selective recruitment.
Strategic Significance
This triad represents a shiftfrom targeted intrusion to industrialized exploitation. Bydecoupling access generation (TeamPCP) from victim selection and encryption(Vect/BreachForums), the group creates a persistent threat wherecredentials stolen in March 2026 can be weaponized monthslater. The model lowers the technical barrier to entry,allowing any BreachForums member to launch a sophisticated ransomware attackagainst a major enterprise simply by using a pre-stolen token provided byTeamPCP.
TeamPCP utilizes asophisticated payload known as the TeamPCP Cloud Stealer (andvariants like SANDCLOCK and CanisterWorm) toharvest a comprehensive array of credentials from CI/CD runners, developerworkstations, and cloud environments. The group targets secrets that facilitatelateral movement across the entire software supply chain.
Cloud Provider & Infrastructure Credentials
The primary objective is togain control over cloud infrastructure. The stealer specificallytargets:
Cloud Access Keys: AWS Access Keys and Secret Keys (~/.aws/credentials), GCP Service Account JSON keys, and Azure Service Principals/Environment Variables.
Kubernetes Secrets: ServiceAccount tokens, kubeconfig files (~/.kube/config), and cluster admin credentials.
Container Registry Tokens: Docker Hub, GitHub Container Registry (GHCR), and Amazon ECR authentication tokens.
Infrastructure-as-Code (IaC) State: Terraform state files containing embedded secrets and provider configurations.
CI/CD & Version Control Tokens
To propagate the attack andmaintain persistence within pipelines, TeamPCP extracts:
GitHub Personal Access Tokens (PATs): Specifically those with repo, workflow, and write:packages scopes, often harvested by dumping the memory of the Runner.Worker process.
OIDC Tokens: OpenID Connect tokens extracted from runner memory to impersonate identities in cloud environments.
Package Manager Tokens: PyPI API tokens (used to poison packages like LiteLLM), npm publish tokens (used for the CanisterWorm propagation), and OpenVSX publisher tokens.
GitLab CI/CD Variables: Protected variables and deploy keys stored in runner environments.
Application & AI API Keys
Leveraging the compromise of AI-focused toolslike LiteLLM and Xinference, the group harvests:
LLM Provider Keys: API keys for OpenAI, Anthropic, Azure AI, Mistral, and Google Vertex AI.
Communication Webhooks: Slack incoming webhook URLs and Discord bot tokens.
Database Credentials: Connection strings for PostgreSQL, MySQL, MongoDB, and Redis found in .env files and configuration directories.
Local Developer & Cryptocurrency Secrets
On developer workstations and build agents, the malware scans for:
SSH Keys: Private keys (id_rsa, id_ed25519) for server access and Git operations.
Cryptocurrency Wallets: Seed phrases, private keys, and credential files for wallets like MetaMask, Exodus, and Electrum.
VPN & TLS Certificates: OpenVPN configurations, private TLS keys, and certificate authorities.
Allharvested data is typically compressed into an encrypted archive(e.g., tpcp.tar.gz or love.tar.gz) using AES-256-CBC with RSA-4096 wrappedkeys before exfiltration to typosquatted domains(e.g., scan.aquasecurtiy[.]org) or fallback GitHub repositories(e.g., tpcp-docs).
TeamPCP deployed aspecific destructive wiper payload named Kamikaze (alsoreferred to as the Iran-focused Kubernetes wiper) against Iranianinfrastructure. This payload was integrated into theirbroader CanisterWorm malware family and activatedin late March 2026.
Wiper Mechanics and Targeting
The Kamikaze wiperoperates via a decision tree that distinguishes betweenIranian and non-Iranian systems based on locale and timezone settings:
Target Identification: The malware scans for specific indicators, primarily the Asia/Tehran timezone or the fa_IR (Farsi) locale setting.
Kubernetes Clusters: If an Iranian system is detected within a Kubernetes environment, the wiper deploys a privileged DaemonSet named host-provisioner-iran into the kube-system namespace. This DaemonSet schedules a destructive container (often named kamikaze) across every node in the cluster, including the control plane. The container mounts the hosts root filesystem and executes a recursive deletion command (rm -rf / --no-preserve-root), effectively bricking the entire cluster and forcing a reboot.
Standalone Hosts: On non-Kubernetes Iranian systems, the payload executes the same recursive deletion logic directly on the host machine, rendering the operating system unusable.
Non-Iranian Systems: If the target does not match Iranian indicators, the malware bypasses the wiper routine and instead installs the standard CanisterWorm backdoor for persistence and credential theft.
Operational Context
The deployment of Kamikaze markeda significant escalation for TeamPCP, transitioning the group frompurely financially motivated cybercrime to geopolitically motivateddestruction. Researchers assess this move as potentiallyopportunistic—a method for the group to gain notoriety and signalcapability—rather than evidence of direct state sponsorship, though theprecision of the targeting suggests a deliberate intent to disrupt Iraniandigital infrastructure amidst broader regional tensions.
TeamPCP consistently targetstrusted software distribution channels rather than end users directly.Operations focus on compromising packages, CI/CD infrastructure, developerworkflows, and cloud environments where a single successful intrusion cancascade into thousands of downstream organizations.
Observed operational patterns include:
Software supply chain compromise
Malicious package publishing on npm and PyPI
Compromise of GitHub Actions workflows
Credential theft from cloud environments
SSH key and API token harvesting
Kubernetes secret extraction
Source code theft
Cloud infrastructure compromise
Extortion following data theft
Ransomware access brokerage
Malware ecosystem
Security researchers and the FBI have attributed multiplemalware families to TeamPCP campaigns.
CanisterWorm harvests cloud credentials, API tokens, SSH keys, and authentication material from AWS, Azure, and Google Cloud Platform environments.
SANDCLOCK extracts AWS credentials, Kubernetes ServiceAccount tokens, environment variables, and cryptocurrency wallet data.
Mini Shai-Hulud is a self-propagating software supply chain worm capable of spreading across npm and PyPI ecosystems.
Miasma expands on Mini Shai-Hulud techniques by poisoning development environments while harvesting credentials.
Cloud and AI targeting
Much of TeamPCPs activity has centered around AI companies,cloud platforms, developer infrastructure, and enterprise software vendors.
Public reporting and alleged victimclaims have included organizations such as OpenAI, Mistral AI, Lightning AI,Mercor, GitHub, Cisco, and the European Commission. Rather than deployingransomware immediately, the group frequently monetizes access by stealingrepositories, cloud credentials, proprietary source code, and developmentsecrets.
Shift toward extortion
Recent activity indicates TeamPCPhas expanded beyond software supply chain compromise into direct extortion.According to the FBI, the group has published victim names on a public leaksite, threatened organizations with data disclosure, and collaborated withother cybercriminal groups to monetize stolen access.
The advisory also warns thatcredentials stolen during TeamPCP intrusions should be treated as a long-termrisk because affiliated threat actors may continue exploiting them well afterthe initial compromise.
Current threat assessment
TeamPCP remains one of the most significantsupply chain threats currently facing organizations that rely on modernsoftware development pipelines. By compromising trusted developer tools ratherthan individual victims, the group can rapidly affect thousands of downstreamenvironments through a single malicious update.
