TeamPCP
Altered SpiderPCPcatShellForceDeadCatx3CanisterWormSHADOW-WATER-058UNC6780
TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and LiteLLM to deploy credential-stealing malware. They employed techniques like credential harvesting, lateral movement within Kubernetes environments, and audio steganography to evade detection. The group has demonstrated the ability to… Fuente: MISP
Actividad en Jábega · 12 semanas
2 noticias · vista por primera vez el 27 ago 2026 · la última, el 25 sept 2026
Noticias
- What We Missed: Google Gemini Joins the AI Escape PartyDark Reading · 25 sept 2026
- Two Alleged ‘TeamPCP’ Hackers Arrested in AustraliaKrebsOnSecurity · 27 ago 2026
Aparece junto a
Técnicas MITRE ATT&CK
Preparación de recursos
T1583Acquire InfrastructureT1583.001DomainsT1583.004ServerT1583.006Web ServicesT1585.001Social Media AccountsT1587.001Malware 10 reglas SigmaT1608.001Upload MalwareT1683.001Written Content
Acceso inicial
T1078Valid Accounts 82 reglas SigmaT1078.004Cloud Accounts 35 reglas SigmaT1190Exploit Public-Facing Application 40 reglas SigmaT1195.001Compromise Software Dependencies and Development Tools 2 reglas Sigma
Ejecución
T1059.004Unix Shell 17 reglas SigmaT1059.006Python 10 reglas SigmaT1059.007JavaScript 26 reglas SigmaT1059.013Container CLI/APIT1677Poisoned Pipeline Execution
Persistencia
T1098Account Manipulation 36 reglas SigmaT1176.002IDE ExtensionsT1543.002Systemd Service 3 reglas SigmaT1546.016Installer PackagesT1547.001Registry Run Keys / Startup Folder 38 reglas Sigma
Acceso a credenciales
T1528Steal Application Access Token 13 reglas SigmaT1552.004Private Keys 6 reglas SigmaT1555.006Cloud Secrets Management Stores
Movimiento lateral
Recopilación
Mando y control
Impacto
T1485Data Destruction 15 reglas SigmaT1486Data Encrypted for Impact 14 reglas SigmaT1657Financial Theft
Stealth
T1027.003Steganography 1 reglas SigmaT1036.005Match Legitimate Resource Name or Location 20 reglas SigmaT1564.001Hidden Files and Directories 7 reglas SigmaT1684.001Impersonation
Defense impairment
Relaciones por coaparición en noticias, no atribución. Fuentes: MISP galaxy, MITRE ATT&CK y SigmaHQ. attack.mitre.org ↗