hacker-news · Crawled Aug 7, 2026
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
2 IoCs 1 Actors
Read original article ↗
AI Summary
TeamPCP, a threat actor active since at least 2020, has evolved from exploiting exposed Redis, Docker, Ray, and React infrastructure to conducting large-scale supply chain attacks. The group has used overlapping infrastructure and tradecraft across campaigns, including ShadowRay 2.0 (aka IronErn) and TA-NATALSTATUS, which targeted Redis servers to deploy cryptocurrency miners. More recently, TeamPCP has poisoned open-source libraries via GitHub Actions abuse and token theft, while also deploying destructive malware such as 'kube.py' that includes wiper functionality targeting Kubernetes clusters, particularly those in Iran.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 16 techniques
T1005 Data from Local System · Collection T1036.005 Match Legitimate Name or Location · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1081 T1081 T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1548.001 Setuid and Setgid · Privilege Escalation T1553 Subvert Trust Controls · Defense Evasion T1566 Phishing · Initial Access