Also tracked as: PCPcat, DeadCatx3, ShellForce, CipherForce, PersyPCP,
Country of origin for TeamPCP remains unknown,\\\\\\
and cybersecurity researchers have not attributed the group to any specific\\\\\\
nation-state with confidence.
\\\\\\
Attribution Challenges & False Flags
\\\\\\
The group actively employs false flag operations to\\\\\\
obscure its true location and mislead investigators:
\\\\\\
- \\\\\\
- Russian\\\\\\
Markers: Malware samples contain Russian cultural references\\\\\\
(e.g., \\\\\\\"Koschei,\\\\\\\" \\\\\\\"Baba Yaga\\\\\\\") and code that\\\\\\
exempts systems with Russian language settings (ru_* locale). \\\\\\ - Contradictory\\\\\\
Targets: Despite the Russian markers, the group deploys\\\\\\
destructive wipers against Iranian infrastructure and\\\\\\
includes logic targeting Israeli systems, creating\\\\\\
conflicting geopolitical signals. \\\\\\ - Analyst\\\\\\
Consensus: Firms like Antiy Labs and Gurucul assess\\\\\\
these markers as deliberate \\\\\\\"noise\\\\\\\" designed to fail traditional\\\\\\
attribution mechanisms rather than authentic indicators of origin. \\\\\\
\\\\\\
Operational Indicators
\\\\\\
While the physical location is unconfirmed,\\\\\\
some operational details offer limited geographic clues:
\\\\\\
- \\\\\\
- Infrastructure: Early\\\\\\
command-and-control servers were hosted in Singapore, with additional infrastructure\\\\\\
linked to the U.S. and UAE. \\\\\\ - Affiliate\\\\\\
Base: Their partner, Vect Ransomware Group, waives\\\\\\
entry fees for affiliates from CIS countries (Russia and\\\\\\
former Soviet states), suggesting a potential operational focus or\\\\\\
membership base in that region, though this does not confirm TeamPCP\\\\\\\'s own\\\\\\
origin. \\\\\\ - Language: Communications are\\\\\\
primarily in English, often with non-native phrasing, and\\\\\\
occasional references to African politics (specifically Kenya) have been\\\\\\
noted in their Telegram channels, though these are considered weak\\\\\\
indicators. \\\\\\
\\\\\\
\\\\\\
\\\\\\
TeamPCP (also tracked as PCPcat, DeadCatx3, ShellForce,\\\\\\
and CipherForce) is a financially and geopolitically\\\\\\
motivated cybercriminal group that emerged in late 2025,\\\\\\
specializing in cloud-native infrastructure and software\\\\\\
supply chain attacks. The group initially conducted\\\\\\
large-scale worm-driven campaigns exploiting exposed Docker APIs, Kubernetes clusters,\\\\\\
and Redis instances to build botnets for ransomware and cryptomining.
\\\\\\
In March 2026, TeamPCP\\\\\\
shifted tactics to compromise widely used CI/CD security\\\\\\
tools, including Trivy, Checkmarx KICS, and LiteLLM. By\\\\\\
stealing GitHub Actions tokens and PyPI publishing\\\\\\
credentials, they deployed a \\\\\\\"TeamPCP Cloud Stealer\\\\\\\" payload\\\\\\
designed to harvest cloud provider credentials (AWS, GCP,\\\\\\
Azure), SSH keys, and Kubernetes tokens. The group utilizes novel\\\\\\
infrastructure such as Internet Computer Protocol (ICP) blockchain\\\\\\
canisters for command-and-control and employs self-propagating worms\\\\\\
like CanisterWorm to infect additional packages across npm and PyPI.
\\\\\\
Key operational characteristics include:
\\\\\\
- \\\\\\
- Hybrid\\\\\\
Motivation: Primarily driven by financial gain through\\\\\\
credential theft and access brokering, with secondary geopolitical objectives\\\\\\
including destructive attacks on Iranian infrastructure. \\\\\\ - Cascading\\\\\\
Compromise: They leverage stolen credentials from one compromised\\\\\\
tool to gain access to the next, creating a multi-ecosystem supply chain\\\\\\
attack across GitHub, Docker Hub, npm,\\\\\\
and PyPI. \\\\\\ - Operational\\\\\\
Security: Uses RSA-4096/AES-256-CBC encryption\\\\\\
for exfiltration, typosquatted domains (e.g., aquasecurtiy[.]org),\\\\\\
and YouTube kill-switches in backdoor payloads. \\\\\\ - Partnerships:\\\\\\
Functions as an access generation engine feeding into ransomware\\\\\\
ecosystems, with formal partnerships noted with Vect Ransomware\\\\\\
Group and collaborations with Lapsus$. \\\\\\
\\\\\\
TeamPCP operates as a primary initial access\\\\\\
broker, maintaining a complex web of partnerships to\\\\\\
monetize stolen credentials through ransomware deployment and data\\\\\\
extortion. Their specific partners include:
\\\\\\
Primary Ransomware & Extortion Partners
\\\\\\
Vect\\\\\\
Ransomware Group
\\\\\\
mso-highlight:yellow\\\\"\\"\">In late March 2026, TeamPCP announced a\\\\\\
formal operational partnership with Vect, a Russian-speaking\\\\\\
Ransomware-as-a-Service (RaaS) operation. Under this\\\\\\
agreement, TeamPCP supplies the initial access gained through supply chain\\\\\\
compromises (specifically the Trivy, KICS, and LiteLLM attacks),\\\\\\
while Vect handles the encryption deployment and extortion. Sophos\\\\\\
confirmed by July 2026 that Vect had successfully deployed ransomware using\\\\\\
credentials sourced directly from TeamPCP operations.
\\\\\\
Lapsus$
\\\\\\
TeamPCP explicitly collaborates with the\\\\\\
notorious extortion group Lapsus$ to monetize stolen data.\\\\\\
Following the March 2026 supply chain campaigns, TeamPCP transferred\\\\\\
approximately 300 GB of compressed credentials to Lapsus$, who\\\\\\
utilized them to target multi-billion-dollar companies and sell access on the\\\\\\
dark web. Mandiant and Wiz researchers confirmed this active\\\\\\
collaboration, noting that Lapsus$ leverages TeamPCP’s deep access to SaaS\\\\\\
environments for high-profile data leaks.
\\\\\\
Operational & Ecosystem Allies
\\\\\\
xpl0itrs
\\\\\\
This group yellow;mso-highlight:yellow\\\\"\\"\">maintains a close technical partnership\\\\\\
with TeamPCP, engaging in joint operations such as the CanisterWorm deployment\\\\\\
and the Bitwarden CLI compromise in April\\\\\\
2026. xpl0itrs functions as a secondary outlet for TeamPCP’s\\\\\\
initial access, sharing tooling and victim lists within a tightly integrated\\\\\\
supply chain-focused cybercrime ecosystem.
\\\\\\
BreachForums
\\\\\\
While\\\\\\
technically a marketplace, yellow\\\\"\\"\">BreachForums serves as a critical force multiplier through\\\\\\
its formal alliance with Vect and TeamPCP. In\\\\\\
April 2026, the partnership facilitated the distribution of affiliate keys to\\\\\\
BreachForums\\\\\\\' entire user base (approx. 300,000 members), effectively\\\\\\
industrializing the distribution of TeamPCP-sourced access for mass ransomware\\\\\\
campaigns.
\\\\\\
ShinyHunters / UNC6240
\\\\\\
mso-highlight:yellow\\\\"\\"\">TeamPCP brokers access to ShinyHunters (also\\\\\\
tracked as UNC6240), who utilize the stolen credentials for large-scale\\\\\\
repository cloning and data theft. Notable instances include the\\\\\\
cloning of over 300 private Cisco repositories containing AI\\\\\\
products and sensitive customer code.
\\\\\\
Internal Monetization Brands
\\\\\\
TeamPCP also operates its own parallel monetization tracks\\\\\\
to ensure redundancy:
\\\\\\
- \\\\\\
- CipherForce:\\\\\\
TeamPCP’s proprietary ransomware brand, used for direct operations\\\\\\
separate from the Vect partnership. \\\\\\ - ShellForce:\\\\\\
A persona used specifically for leaking and selling exfiltrated\\\\\\
data. \\\\\\
\\\\\\
TeamPCP has established\\\\\\
a sophisticated ecosystem of partnerships designed to industrialize the\\\\\\
monetization of stolen credentials, moving beyond simple data theft to\\\\\\
coordinated ransomware deployment and large-scale extortion. These alliances function as a\\\\\\
\\\\\\\"reverse kill chain,\\\\\\\" where access is secured via supply chain\\\\\\
compromises first, and targets are selected from the resulting credential\\\\\\
archive later.
\\\\\\
The Vect-BreachForums Industrial Alliance
\\\\\\
The most significant partnership\\\\\\
is the formal triadbetween\\\\\\
TeamPCP, Vect Ransomware Group, and BreachForums.\\\\\\
Announced in late March 2026 and operationalized on April 16, 2026,\\\\\\
this alliance created an unprecedented \\\\\\\"mass-affiliate\\\\\\\" model:
\\\\\\
- \\\\\\
- Role\\\\\\
Division: TeamPCP acts as the exclusive initial access\\\\\\
broker, supplying credentials harvested from compromised CI/CD tools\\\\\\
(Trivy, KICS, LiteLLM). Vect provides the ransomware\\\\\\
infrastructure (C++ based ChaCha20-Poly1305 encryption), while\\\\\\
BreachForums supplies the human capital. \\\\\\ - Scale\\\\\\
of Mobilization: Unlike traditional RaaS models that recruit\\\\\\
affiliates selectively, this partnership distributed Vect affiliate keys\\\\\\
to all ~300,000 registered users of BreachForums\\\\\\
simultaneously. This effectively converted a massive forum user\\\\\\
base into an instant ransomware deployment army. \\\\\\ - Operational\\\\\\
Impact: By July 2026, Sophos confirmed active ransomware\\\\\\
deployments where Vect operators selected victims directly from TeamPCP’s\\\\\\
stolen credential archives. This model removes the need for affiliates to\\\\\\
possess technical exploitation skills, as the \\\\\\\"entry ticket\\\\\\\"\\\\\\
(valid cloud tokens) is pre-supplied by TeamPCP. \\\\\\
\\\\\\
Extortion and Data Monetization Partners
\\\\\\
To maximize the value of\\\\\\
exfiltrated data (estimated at 300 GB of compressed\\\\\\
credentials), TeamPCP collaborates with specialized extortion groups:
\\\\\\
Lapsus$
\\\\\\
TeamPCP maintains an explicit\\\\\\
collaboration with Lapsus$ to handle high-profile extortion\\\\\\
campaigns. While TeamPCP focuses on the technical infiltration of SaaS\\\\\\
environments, Lapsus$ leverages its reputation for aggressive public shaming\\\\\\
and social engineering to pressure victims. Wiz researchers confirmed that\\\\\\
TeamPCP transfers validated credentials to Lapsus$, who then target\\\\\\
multi-billion-dollar companies for data leaks and ransom demands.
\\\\\\
ShinyHunters (UNC6240)
\\\\\\
A critical operational link\\\\\\
exists between TeamPCP and ShinyHunters. Following the March 2026 Trivy\\\\\\
compromise, credentials harvested by TeamPCP were utilized by ShinyHunters to\\\\\\
breach Cisco. This collaboration resulted in the cloning of over 300\\\\\\
private GitHub repositories, including source code for AI products and\\\\\\
tools used by US government agencies (FBI, DHS, NASA). This\\\\\\
partnership highlights a \\\\\\\"hand-off\\\\\\\" model where TeamPCP provides the\\\\\\
foothold, and ShinyHunters executes the deep data exfiltration.
\\\\\\
mso-highlight:yellow\\\\"\\"\">*The relationship\\\\\\
between TeamPCP and ShinyHunters (also\\\\\\
tracked as UNC6240) yellow\\\\"\\"\">is hostile and opportunistic, rather than a formal\\\\\\
partnership. While they operate in the same ecosystem, their\\\\\\
interactions are defined by theft, deception, and conflicting public\\\\\\
narratives.
\\\\\\
The \\\\\\\"Scam\\\\\\\" and Hostile Takeover
\\\\\\
Contrary to early reports of\\\\\\
collaboration, TeamPCP leadership\\\\\\
has explicitly stated that ShinyHunters is not a partner. In\\\\\\
a May 9, 2026 interview, the TeamPCP leader detailed a specific incident of\\\\\\
betrayal:
\\\\\\
- \\\\\\
- The\\\\\\
Infiltration: \\\\\\
\\\\\\
A member\\\\\\
of ShinyHunters infiltrated the private operator chat\\\\\\
of Vect (TeamPCP’s ransomware partner), demonstrating a failure\\\\\\
in TeamPCP’s vetting or access control mechanisms for their own criminal\\\\\\
ecosystem.
\\\\\\
- \\\\\\
- The\\\\\\
Theft: \\\\\\
\\\\\\
The ShinyHunters member agreed to\\\\\\
split profits on a bundle of stolen credentials, downloaded the data, and\\\\\\
then refused to pay.
\\\\\\
- \\\\\\
- The\\\\\\
Smear: \\\\\\
\\\\\\
To cover the theft and discredit\\\\\\
TeamPCP, ShinyHunters released a \\\\\\\"mix of real and fabricated chats\\\\\\\"\\\\\\
portraying the interaction as a legitimate partnership or dispute, rather than\\\\\\
a scam.
\\\\\\
tab-stops:list=\"\\"\\"\" .5in\\\\\\\"=\"\\"\\"\">mso-bidi-font-size:12.0pt;line-height:115%;font-family:Symbol;mso-fareast-font-family:\\\\\\
Symbol;mso-bidi-font-family:Symbol\\\\"\\"\">· \\\\\\
Data Handover:
\\\\\\
The thief was able to download a full\\\\\\
bundle of stolen credentials after agreeing to a profit-split, indicating that\\\\\\
TeamPCP lacks technical safeguards (such as staged data releases or escrow\\\\\\
mechanisms) to prevent partners or infiltrators from absconding with the entire\\\\\\
dataset.
\\\\\\
tab-stops:list=\"\\"\\"\" .5in\\\\\\\"=\"\\"\\"\">mso-bidi-font-size:12.0pt;line-height:115%;font-family:Symbol;mso-fareast-font-family:\\\\\\
Symbol;mso-bidi-font-family:Symbol\\\\"\\"\">· \\\\\\
Reactive Counter-Measures
\\\\\\
Once the theft was identified, TeamPCP\\\\\\
employed the following damage control tactics:
\\\\\\
tab-stops:list=\"\\"\\"\" .5in\\\\\\\"=\"\\"\\"\">mso-bidi-font-size:12.0pt;line-height:115%;font-family:Symbol;mso-fareast-font-family:\\\\\\
Symbol;mso-bidi-font-family:Symbol\\\\"\\"\">· \\\\\\
Public Discrediting:
\\\\\\
In a May 9, 2026 interview\\\\\\
with Inside Darknet, the TeamPCP leader explicitly labeled the\\\\\\
interaction a \\\\\\\"scam\\\\\\\" and \\\\\\\"shitty business practice,\\\\\\\" aiming\\\\\\
to destroy ShinyHunters\\\\\\\' reputation within the cybercriminal underground.
\\\\\\
tab-stops:list=\"\\"\\"\" .5in\\\\\\\"=\"\\"\\"\">mso-bidi-font-size:12.0pt;line-height:115%;font-family:Symbol;mso-fareast-font-family:\\\\\\
Symbol;mso-bidi-font-family:Symbol\\\\"\\"\">· \\\\\\
Narrative Correction:
\\\\\\
They released \\\\\\\"a mix of real and\\\\\\
fabricated chats\\\\\\\" (mirroring ShinyHunters\\\\\\\' own tactics) to prove the theft\\\\\\
occurred and to distance themselves from subsequent high-profile breaches (like\\\\\\
the CERT-EU attack) that ShinyHunters executed using the\\\\\\
stolen data.
\\\\\\
tab-stops:list=\"\\"\\"\" .5in\\\\\\\"=\"\\"\\"\">mso-bidi-font-size:12.0pt;line-height:115%;font-family:Symbol;mso-fareast-font-family:\\\\\\
Symbol;mso-bidi-font-family:Symbol\\\\"\\"\">· \\\\\\
Attribution Shift:
\\\\\\
TeamPCP leadership publicly clarified their\\\\\\
non-involvement in government targets (\\\\\\\"We don\\\\\\\'t even target gov\\\\\\\"),\\\\\\
attempting to shift the blame for the CERT-EU breach entirely onto ShinyHunters\\\\\\
to avoid law enforcement scrutiny.
\\\\\\
Strategic Implications
\\\\\\
The incident highlights that TeamPCP’s security model is trust-based within\\\\\\
a hostile environment. They have no technical method to revoke\\\\\\
access to credentials once they are downloaded by an affiliate or partner.\\\\\\
Their primary defense is the threat of reputational ruin and\\\\\\
the potential for retaliatory doxxing or law enforcement tipping, which serves\\\\\\
as the only deterrent against internal theft in the cybercriminal ecosystem.
\\\\\\
Divergent Operational Goals
\\\\\\
The two groups have\\\\\\
fundamentally different targeting doctrines, which led to friction over\\\\\\
specific breaches:
\\\\\\
- \\\\\\
- Targeting\\\\\\
Conflicts: \\\\\\
\\\\\\
TeamPCP\\\\\\
publicly claims to exclude governments and non-profits from their direct\\\\\\
operations. However, ShinyHunters used the stolen\\\\\\
TeamPCP-sourced credentials to breach the European Commission (CERT-EU),\\\\\\
stealing 340 GB of data from 42 EU departments. TeamPCP\\\\\\
leaders subsequently clarified they did not perform this exfiltration and do\\\\\\
not target government entities, attributing the act solely to ShinyHunters.
\\\\\\
- \\\\\\
- Cisco\\\\\\
Breach: \\\\\\
\\\\\\
While TeamPCP\\\\\\
provided the initial access vector (via the compromised Trivy scanner), ShinyHunters independently\\\\\\
executed the deep intrusion into Cisco, cloning over 300 private\\\\\\
repositories (including AI and government-related code) and\\\\\\
launching their own extortion campaign with an April 3 deadline.
\\\\\\
The \\\\\\\"Convergence\\\\\\\" Dynamic
\\\\\\
Despite the hostility, the groups\\\\\\
are functionally linked in a \\\\\\\"convergence of cybercriminal\\\\\\
ecosystems\\\\\\\":
\\\\\\
- \\\\\\
- Access\\\\\\
vs. Extortion: T \\\\\\
\\\\\\
TeamPCP\\\\\\
acts as the initial access broker, compromising the supply\\\\\\
chain to harvest credentials. ShinyHunters acts as\\\\\\
a predatory downstream actor, monitoring these compromises\\\\\\
to steal the harvested credentials for their own high-profile extortion\\\\\\
campaigns.
\\\\\\
- \\\\\\
- Blast\\\\\\
Radius: \\\\\\
\\\\\\
yellow;mso-highlight:yellow\\\\"\\"\">This dynamic means that even without a formal\\\\\\
agreement, TeamPCP’s compromises directly enable ShinyHunters’ operations.\\\\\\
Security researchers note that this creates a complex threat landscape\\\\\\
where defenders must contend with multiple independent groups exploiting the\\\\\\
same initial breach.
\\\\\\
Technical and Operational Allies
\\\\\\
xpl0itrs This\\\\\\
group serves as TeamPCP’s primary technical co-conspirator. They jointly\\\\\\
developed and deployed CanisterWorm, the first self-propagating npm\\\\\\
worm utilizing Internet Computer Protocol (ICP) canisters for\\\\\\
command-and-control. Their partnership extends to the Bitwarden\\\\\\
CLI compromise in April 2026. xpl0itrs often acts as a\\\\\\
secondary outlet for selling access derived from TeamPCP’s initial breaches,\\\\\\
such as the alleged 569 GB breach of RapidFort claimed in July\\\\\\
2026.
\\\\\\
Internal Redundancy:
\\\\\\
CipherForce
\\\\\\
To ensure operational resilience\\\\\\
and avoid reliance solely on external partners, TeamPCP operates its own\\\\\\
proprietary ransomware brand, CipherForce. While the\\\\\\
Vect partnership handles mass distribution via BreachForums, CipherForce is\\\\\\
used for direct, controlled operations where TeamPCP retains full authority\\\\\\
over encryption and negotiation, allowing them to test new tactics without exposing\\\\\\
their primary affiliates.
\\\\\\
TeamPCP compromised a specific\\\\\\
set of high-value CI/CD and developer security tools\\\\\\
between March 19 and April 22, 2026, executing a cascading attack\\\\\\
where credentials stolen from one tool were used to compromise the next.
\\\\\\
Primary CI/CD & Security Tool Compromises
\\\\\\
Trivy (Aqua Security)
\\\\\\
- \\\\\\
- Compromise\\\\\\
Date: March 19, 2026 (following an initial breach on Feb\\\\\\
28). \\\\\\ - Vector: TeamPCP\\\\\\
exploited a pull_request_target vulnerability to steal a GitHub\\\\\\
Actions PAT, then hijacked release tags (v0.69.4) to inject malware\\\\\\
into GitHub Actions, binaries, and Docker\\\\\\
Hub images. \\\\\\ - Impact: As\\\\\\
the initial pivot point, this compromise provided the GitHub\\\\\\
Actions tokens and cloud credentials used to\\\\\\
attack subsequent tools. \\\\\\
\\\\\\
Checkmarx KICS (Keeping Infrastructure as Code\\\\\\
Secure)
\\\\\\
- \\\\\\
- Compromise\\\\\\
Date: March 23, 2026. \\\\\\ - Vector: Using\\\\\\
credentials harvested from the Trivy compromise, the group poisoned KICS\\\\\\
GitHub Actions (all 35 tags), OpenVSX extensions,\\\\\\
and Docker images. \\\\\\ - Impact: Allowed\\\\\\
the theft of Infrastructure-as-Code secrets and further expanded access to\\\\\\
enterprise cloud environments. \\\\\\
\\\\\\
LiteLLM (BerriAI)
\\\\\\
- \\\\\\
- Compromise\\\\\\
Date: March 24, 2026. \\\\\\ - Vector: Compromised PyPI\\\\\\
publishing credentials (stolen from CI/CD pipelines running the\\\\\\
trojanized Trivy action) to publish malicious versions 1.82.7 and 1.82.8. \\\\\\ - Impact: Targeted\\\\\\
AI infrastructure, harvesting API keys for over 100 LLM providers (OpenAI,\\\\\\
Anthropic, etc.) alongside cloud credentials. \\\\\\
\\\\\\
Telnyx Python SDK
\\\\\\
- \\\\\\
- Compromise\\\\\\
Date: March 27, 2026. \\\\\\ - Vector: Similar\\\\\\
to LiteLLM, malicious versions were published to PyPI using\\\\\\
stolen publishing rights. \\\\\\ - Impact: Compromised\\\\\\
telecommunications API credentials and messaging workflows integrated into\\\\\\
CI/CD pipelines. \\\\\\
\\\\\\
Secondary & Related Compromises
\\\\\\
Bitwarden CLI
\\\\\\
- \\\\\\
- Compromise\\\\\\
Date: April 22, 2026. \\\\\\ - Vector: A\\\\\\
malicious version (2026.4.0) was published to npm by\\\\\\
exploiting a compromised GitHub Action in Bitwarden’s CI/CD pipeline\\\\\\
(linked to the broader TeamPCP campaign). \\\\\\ - Impact: Targeted\\\\\\
developer workstations and pipelines to harvest SSH keys, crypto\\\\\\
wallet data, and npm tokens, utilizing a self-propagating\\\\\\
worm mechanism. \\\\\\
\\\\\\
TanStack & Others
\\\\\\
- \\\\\\
- The\\\\\\
campaign also affected TanStack (via OIDC abuse in April\\\\\\
2026) and over 45 npm packages (including @EmilGroup and @opengov)\\\\\\
via a self-propagating worm (deploy.js) that autonomously published\\\\\\
malicious patch versions using stolen tokens. \\\\\\
\\\\\\
The triad consisting\\\\\\
of TeamPCP, Vect Ransomware Group,\\\\\\
and BreachForums operates as an integrated, industrialized ransomware\\\\\\
ecosystem rather than three separate entities collaborating\\\\\\
ad-hoc. Their relationship is defined by a strict division\\\\\\
of labor that inverts the traditional ransomware kill chain:
\\\\\\
Operational Workflow: The \\\\\\\"Reverse Kill\\\\\\
Chain\\\\\\\"
\\\\\\
1. TeamPCP:\\\\\\
The Access Engine (Supply Chain Layer)
\\\\\\
TeamPCP functions exclusively as\\\\\\
the initial access broker. Instead of selecting specific\\\\\\
victims first, they compromise high-volume software supply chain components\\\\\\
(e.g., Trivy, LiteLLM, KICS) to harvest a\\\\\\
massive archive of over 500,000 credentials from CI/CD\\\\\\
pipelines. They do not deploy ransomware themselves in this triad;\\\\\\
their sole output is a validated inventory of compromised cloud tokens and API\\\\\\
keys.
\\\\\\
2. Vect:\\\\\\
The Monetization Infrastructure (RaaS Layer)
\\\\\\
Vect provides the\\\\\\
weaponization and extortion capability. Unlike traditional RaaS models where\\\\\\
affiliates must find their own way into a network, Vect operators simply search\\\\\\
TeamPCP’s pre-existing credential archive to select\\\\\\
victims. Vect supplies the C++ ransomware payload (using\\\\\\
ChaCha20-Poly1305 encryption), the TOR-based leak site, and the\\\\\\
negotiation infrastructure. This allows affiliates to skip the\\\\\\
exploitation phase entirely and move straight to deployment.
\\\\\\
3. \\\\\\
BreachForums: The Distribution & Operational\\\\\\
Layer
\\\\\\
BreachForums serves as\\\\\\
the force multiplier and operational platform. On April 16, 2026,\\\\\\
the triad operationalized a \\\\\\\"mass-affiliate\\\\\\\" model where all ~300,000\\\\\\
registered BreachForums users were automatically issued Vect affiliate\\\\\\
keys. The forum provides:
\\\\\\
- \\\\\\
- Escrow\\\\\\
Services: A Monero-based multi-signature escrow system for\\\\\\
handling ransom payments. \\\\\\ - Affiliate\\\\\\
Management: Tiered incentive structures (offering up to 88%\\\\\\
profit share) and support for less technical operators. \\\\\\ - Instant\\\\\\
Mobilization: Converting a passive forum user base into an\\\\\\
active ransomware deployment army without selective recruitment. \\\\\\
\\\\\\
Strategic Significance
\\\\\\
This triad represents a shift\\\\\\
from targeted intrusion to industrialized exploitation. By\\\\\\
decoupling access generation (TeamPCP) from victim selection and encryption\\\\\\
(Vect/BreachForums), the group creates a persistent threat where\\\\\\
credentials stolen in March 2026 can be weaponized months\\\\\\
later. The model lowers the technical barrier to entry,\\\\\\
allowing any BreachForums member to launch a sophisticated ransomware attack\\\\\\
against a major enterprise simply by using a pre-stolen token provided by\\\\\\
TeamPCP.
\\\\\\
TeamPCP utilizes a\\\\\\
sophisticated payload known as the \\\\\\\"TeamPCP Cloud Stealer\\\\\\\" (and\\\\\\
variants like SANDCLOCK and CanisterWorm) to\\\\\\
harvest a comprehensive array of credentials from CI/CD runners, developer\\\\\\
workstations, and cloud environments. The group targets secrets that facilitate\\\\\\
lateral movement across the entire software supply chain.
\\\\\\
Cloud Provider & Infrastructure Credentials
\\\\\\
The primary objective is to\\\\\\
gain control over cloud infrastructure. The stealer specifically\\\\\\
targets:
\\\\\\
- \\\\\\
- Cloud\\\\\\
Access Keys: AWS Access Keys and Secret Keys\\\\\\
(~/.aws/credentials), GCP Service Account JSON keys, and Azure Service\\\\\\
Principals/Environment Variables. \\\\\\ - Kubernetes\\\\\\
Secrets: ServiceAccount tokens, kubeconfig files\\\\\\
(~/.kube/config), and cluster admin credentials. \\\\\\ - Container\\\\\\
Registry Tokens: Docker Hub, GitHub Container Registry\\\\\\
(GHCR), and Amazon ECR authentication tokens. \\\\\\ - Infrastructure-as-Code\\\\\\
(IaC) State: Terraform state files containing embedded\\\\\\
secrets and provider configurations. \\\\\\
\\\\\\
CI/CD & Version Control Tokens
\\\\\\
To propagate the attack and\\\\\\
maintain persistence within pipelines, mso-highlight:yellow\\\\"\\"\">TeamPCP extracts:
\\\\\\
- \\\\\\
- GitHub\\\\\\
Personal Access Tokens (PATs): Specifically those\\\\\\
with repo, workflow, and write:packages scopes, often\\\\\\
harvested by dumping the memory of\\\\\\
the Runner.Worker process. \\\\\\ - OIDC\\\\\\
Tokens: OpenID Connect tokens extracted from runner memory to\\\\\\
impersonate identities in cloud environments. \\\\\\ - Package\\\\\\
Manager Tokens: PyPI API tokens (used to\\\\\\
poison packages like LiteLLM), npm publish tokens (used\\\\\\
for the CanisterWorm propagation), and OpenVSX publisher\\\\\\
tokens. \\\\\\ - GitLab\\\\\\
CI/CD Variables: Protected variables and deploy keys stored\\\\\\
in runner environments. \\\\\\
\\\\\\
Application & AI API Keys
\\\\\\
mso-highlight:yellow\\\\"\\"\">Leveraging the compromise of AI-focused tools\\\\\\
like LiteLLM and Xinference, the group harvests:
\\\\\\
- \\\\\\
- LLM\\\\\\
Provider Keys: API keys for OpenAI, Anthropic, Azure\\\\\\
AI, Mistral, and Google Vertex AI. \\\\\\ - Communication\\\\\\
Webhooks: Slack incoming webhook URLs and Discord bot\\\\\\
tokens. \\\\\\ - Database Credentials: Connection\\\\\\
strings for PostgreSQL, MySQL, MongoDB, and Redis found\\\\\\
in .env files and configuration directories. \\\\\\
\\\\\\
Local Developer & Cryptocurrency Secrets
\\\\\\
On developer workstations and build agents, the malware scans for:
\\\\\\
- \\\\\\
- SSH\\\\\\
Keys: Private keys (id_rsa, id_ed25519) for\\\\\\
server access and Git operations. \\\\\\ - Cryptocurrency\\\\\\
Wallets: Seed phrases, private keys, and credential files for\\\\\\
wallets like MetaMask, Exodus, and Electrum. \\\\\\ - VPN & TLS Certificates: OpenVPN\\\\\\
configurations, private TLS keys, and certificate authorities. \\\\\\
\\\\\\
All\\\\\\
harvested data is typically compressed into an encrypted archive\\\\\\
(e.g., tpcp.tar.gz or love.tar.gz) using AES-256-CBC with RSA-4096 wrapped\\\\\\
keys before exfiltration to typosquatted domains\\\\\\
(e.g., scan.aquasecurtiy[.]org) or fallback GitHub repositories\\\\\\
(e.g., tpcp-docs).
\\\\\\
TeamPCP deployed a\\\\\\
specific destructive wiper payload named Kamikaze (also\\\\\\
referred to as the Iran-focused Kubernetes wiper) against Iranian\\\\\\
infrastructure. This payload was integrated into their\\\\\\
broader CanisterWorm malware family and activated\\\\\\
in late March 2026.
\\\\\\
Wiper Mechanics and Targeting
\\\\\\
The Kamikaze wiper\\\\\\
operates via a \\\\\\\"decision tree\\\\\\\" that distinguishes between\\\\\\
Iranian and non-Iranian systems based on locale and timezone settings:
\\\\\\
- \\\\\\
- Target\\\\\\
Identification: The \\"\" mso-highlight:yellow\\\\\\\"=\"\\"\\"\">malware scans for specific indicators,\\\\\\
primarily the Asia/Tehran timezone or the fa_IR (Farsi)\\\\\\
locale setting. \\\\\\ - Kubernetes\\\\\\
Clusters: If an Iranian system\\\\\\
is detected within a Kubernetes environment, the wiper deploys a\\\\\\
privileged DaemonSet named host-provisioner-iran into\\\\\\
the kube-system namespace. This DaemonSet schedules a destructive\\\\\\
container (often named kamikaze) across every node in\\\\\\
the cluster, including the control plane. The\\\\\\
container mounts the host\\\\\\\'s root filesystem and executes a recursive\\\\\\
deletion command (rm -rf / --no-preserve-root), effectively\\\\\\
bricking the entire cluster and forcing a reboot. \\\\\\ - Standalone\\\\\\
Hosts: On \\"\" yellow\\\\\\\"=\"\\"\\"\">non-Kubernetes Iranian systems, the payload executes the same\\\\\\
recursive deletion logic directly on the host machine, rendering the\\\\\\
operating system unusable. \\\\\\ - Non-Iranian\\\\\\
Systems: If the target \\"\" mso-highlight:yellow\\\\\\\"=\"\\"\\"\">does not match Iranian indicators, the malware\\\\\\
bypasses the wiper routine and instead installs the standard CanisterWorm backdoor\\\\\\
for persistence and credential theft. \\\\\\
\\\\\\
Operational Context
\\\\\\
The deployment of Kamikaze marked\\\\\\
a significant escalation for TeamPCP, transitioning the group from\\\\\\
purely financially motivated cybercrime to geopolitically motivated\\\\\\
destruction. Researchers assess this move as potentially\\\\\\
opportunistic—a method for the group to gain notoriety and signal\\\\\\
capability—rather than evidence of direct state sponsorship, though the\\\\\\
precision of the targeting suggests a deliberate intent to disrupt Iranian\\\\\\
digital infrastructure amidst broader regional tensions.
\\\\\\
TeamPCP consistently targets\\\\\\
trusted software distribution channels rather than end users directly.\\\\\\
Operations focus on compromising packages, CI/CD infrastructure, developer\\\\\\
workflows, and cloud environments where a single successful intrusion can\\\\\\
cascade into thousands of downstream organizations.
\\\\\\
Observed operational patterns include:
\\\\\\
- \\\\\\
- Software\\\\\\
supply chain compromise \\\\\\ - Malicious\\\\\\
package publishing on npm and PyPI \\\\\\ - Compromise\\\\\\
of GitHub Actions workflows \\\\\\ - Credential\\\\\\
theft from cloud environments \\\\\\ - SSH\\\\\\
key and API token harvesting \\\\\\ - Kubernetes\\\\\\
secret extraction \\\\\\ - Source\\\\\\
code theft \\\\\\ - Cloud\\\\\\
infrastructure compromise \\\\\\ - Extortion\\\\\\
following data theft \\\\\\ - Ransomware\\\\\\
access brokerage \\\\\\
\\\\\\
Malware ecosystem
\\\\\\
Security researchers and the FBI have attributed multiple\\\\\\
malware families to TeamPCP campaigns.
\\\\\\
- \\\\\\
- CanisterWorm harvests\\\\\\
cloud credentials, API tokens, SSH keys, and authentication material from\\\\\\
AWS, Azure, and Google Cloud Platform environments. \\\\\\ - SANDCLOCK extracts\\\\\\
AWS credentials, Kubernetes ServiceAccount tokens, environment variables,\\\\\\
and cryptocurrency wallet data. \\\\\\ - Mini\\\\\\
Shai-Hulud is a self-propagating software supply chain worm\\\\\\
capable of spreading across npm and PyPI ecosystems. \\\\\\ - Miasma expands\\\\\\
on Mini Shai-Hulud techniques by poisoning development environments while\\\\\\
harvesting credentials. \\\\\\
\\\\\\
Cloud and AI targeting
\\\\\\
Much of TeamPCP’s activity has centered around AI companies,\\\\\\
cloud platforms, developer infrastructure, and enterprise software vendors.
\\\\\\
Public reporting and alleged victim\\\\\\
claims have included organizations such as OpenAI, Mistral AI, Lightning AI,\\\\\\
Mercor, GitHub, Cisco, and the European Commission. Rather than deploying\\\\\\
ransomware immediately, the group frequently monetizes access by stealing\\\\\\
repositories, cloud credentials, proprietary source code, and development\\\\\\
secrets.
\\\\\\
Shift toward extortion
\\\\\\
Recent activity indicates TeamPCP\\\\\\
has expanded beyond software supply chain compromise into direct extortion.\\\\\\
According to the FBI, the group has published victim names on a public leak\\\\\\
site, threatened organizations with data disclosure, and collaborated with\\\\\\
other cybercriminal groups to monetize stolen access.
\\\\\\
The advisory also warns that\\\\\\
credentials stolen during TeamPCP intrusions should be treated as a long-term\\\\\\
risk because affiliated threat actors may continue exploiting them well after\\\\\\
the initial compromise.
\\\\\\
Current threat assessment
\\\\\\
mso-ascii-theme-font:minor-latin;mso-fareast-font-family:Aptos;mso-fareast-theme-font:\\\\\\
minor-latin;mso-hansi-theme-font:minor-latin;mso-bidi-font-family:"Times\\"\" new=\"\\"\\"\" roman\\\";\\\\\\
mso-bidi-theme-font:minor-bidi;mso-ansi-language:en-us;mso-fareast-language:\\\\\\
en-us;mso-bidi-language:ar-sa\\\\\\\"=\"\\"\\"\">TeamPCP remains one of the most significant\\\\\\
supply chain threats currently facing organizations that rely on modern\\\\\\
software development pipelines. By compromising trusted developer tools rather\\\\\\
than individual victims, the group can rapidly affect thousands of downstream\\\\\\
environments through a single malicious update.
