Cybersecurity from Málaga · Networks, lures and threats

← Threats
Actor · MITRE G1056

TeamPCP

Altered SpiderPCPcatShellForceDeadCatx3CanisterWormSHADOW-WATER-058UNC6780

TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and LiteLLM to deploy credential-stealing malware. They employed techniques like credential harvesting, lateral movement within Kubernetes environments, and audio steganography to evade detection. The group has demonstrated the ability to… Source: MISP

Activity on Jábega · 12 weeks

2 stories · first seen on 27 Aug 2026 · last seen on 25 Sep 2026

News

Appears alongside

MITRE ATT&CK techniques

Resource Development

Initial Access

Execution

Persistence

Credential Access

Lateral Movement

Collection

Command and Control

Impact

Stealth

Defense impairment

Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗