hacker-news · Crawled Aug 7, 2026

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

2 IoCs 1 Actors
Read original article ↗

AI Summary

TeamPCP, a threat actor active since at least 2020, has evolved from exploiting exposed Redis, Docker, Ray, and React infrastructure to conducting large-scale supply chain attacks. The group has used overlapping infrastructure and tradecraft across campaigns, including ShadowRay 2.0 (aka IronErn) and TA-NATALSTATUS, which targeted Redis servers to deploy cryptocurrency miners. More recently, TeamPCP has poisoned open-source libraries via GitHub Actions abuse and token theft, while also deploying destructive malware such as 'kube.py' that includes wiper functionality targeting Kubernetes clusters, particularly those in Iran.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Filename kube.py Details →
Filename Kamikaze Details →

MITRE ATT&CK TTPs 16 techniques