TeamPCP
Altered SpiderPCPcatShellForceDeadCatx3CanisterWormSHADOW-WATER-058UNC6780
TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and LiteLLM to deploy credential-stealing malware. They employed techniques like credential harvesting, lateral movement within Kubernetes environments, and audio steganography to evade detection. The group has demonstrated the ability to… Source: MISP
Activity on Jábega · 12 weeks
2 stories · first seen on 27 Aug 2026 · last seen on 25 Sep 2026
News
- What We Missed: Google Gemini Joins the AI Escape PartyDark Reading · 25 Sep 2026
- Two Alleged ‘TeamPCP’ Hackers Arrested in AustraliaKrebsOnSecurity · 27 Aug 2026
Appears alongside
MITRE ATT&CK techniques
Resource Development
T1583Acquire InfrastructureT1583.001DomainsT1583.004ServerT1583.006Web ServicesT1585.001Social Media AccountsT1587.001Malware 10 Sigma rulesT1608.001Upload MalwareT1683.001Written Content
Initial Access
T1078Valid Accounts 82 Sigma rulesT1078.004Cloud Accounts 35 Sigma rulesT1190Exploit Public-Facing Application 40 Sigma rulesT1195.001Compromise Software Dependencies and Development Tools 2 Sigma rules
Execution
T1059.004Unix Shell 17 Sigma rulesT1059.006Python 10 Sigma rulesT1059.007JavaScript 26 Sigma rulesT1059.013Container CLI/APIT1677Poisoned Pipeline Execution
Persistence
T1098Account Manipulation 36 Sigma rulesT1176.002IDE ExtensionsT1543.002Systemd Service 3 Sigma rulesT1546.016Installer PackagesT1547.001Registry Run Keys / Startup Folder 38 Sigma rules
Credential Access
T1528Steal Application Access Token 13 Sigma rulesT1552.004Private Keys 6 Sigma rulesT1555.006Cloud Secrets Management Stores
Lateral Movement
Collection
Command and Control
Impact
T1485Data Destruction 15 Sigma rulesT1486Data Encrypted for Impact 14 Sigma rulesT1657Financial Theft
Stealth
T1027.003Steganography 1 Sigma rulesT1036.005Match Legitimate Resource Name or Location 20 Sigma rulesT1564.001Hidden Files and Directories 7 Sigma rulesT1684.001Impersonation
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗