LIVE · cybersecurity feed
Live wire
security

TeamPCP Traced Back to 2020 Cryptojacking Operation

Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020

zeroday.news ·

New research indicates that TeamPCP, a group recently implicated in a series of supply chain attacks on open-source developer tools, has been active since at least 2020, sharing infrastructure and tactics with earlier cryptojacking operations. Oligo Security, in collaboration with Mandiant and GitLab, published findings on August 5, 2026, linking TeamPCP to activities previously tracked as TA-NATALSTATUS, which spanned from 2020 to August 2025. GitLab confirmed the investigation and has banned the accounts identified as involved.

The investigation established a strong link between TeamPCP and the ShadowRay 2.0 campaign, which targeted exposed Ray clusters in November 2025. Oligo Security had initially attributed ShadowRay 2.0 to an actor named IronErn440, but now assesses that TeamPCP was responsible. The primary infrastructural connection identified across TA-NATALSTATUS, ShadowRay 2.0, and TeamPCP operations is the domain masscan[.]cloud, which certificate transparency records show was registered on May 11, 2025. TeamPCP's own GitHub account later listed this domain as its official website.

Further evidence of continuity includes the reuse of a distinctive deployment framework. This framework, characterized by a specific directory path and a set of staging scripts, was documented in earlier TA-NATALSTATUS campaigns and appeared unchanged in TeamPCP payloads. A compromised Ray cluster was observed downloading from this infrastructure on July 26, 2025, several months before the TeamPCP name became publicly known.

Direct evidence from GitLab further solidified the connection. An IP address received reverse shells from a compromised Ray cluster between October 15 and November 2. All these shell sessions ceased on November 2. Subsequently, between November 2 and November 4, the ironern440 account authenticated to GitLab from the same IP address, which was also hosting the campaign's tooling.

Oligo's timeline suggests that the operators began exploiting internet-facing infrastructure as early as 2020, often employing automated and wormable techniques, primarily for cryptojacking. Their activities then expanded to include GitHub Actions abuse and token theft. This progression led to campaigns like PCPcat, which peaked around Christmas 2025, targeting React2Shell vulnerabilities and exposed Docker APIs. These activities then evolved into the March 2026 compromises of Trivy, Checkmarx's KICS, and LiteLLM.

Beyond exploitation, the infrastructure also broadened to support other malicious activities, with subdomains observed facilitating credential phishing, payment fraud, and Zendesk impersonation. In late March, a second-stage Kubernetes payload developed a destructive capability. This script was designed to check if the victim system's timezone was set to Iran. If so, it would deploy a destructive workload that deleted filesystems and rebooted the machine. Oligo noted that Iranian internet connectivity was significantly disrupted at the time, which may have limited visibility into whether this destructive payload was ever successfully executed.

While the evidence strongly suggests operational continuity, Oligo Security cautioned against definitive attribution regarding the exact nature of the relationship. It remains uncertain whether the continuity reflects a direct rebrand, a shared set of operators, or close collaboration between related actors. However, the research clearly indicates that TeamPCP is not a newly formed group that emerged in late 2025, but rather a continuation of an established operational ecosystem.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

How the famed USENIX Security conf is managing a flood of papers in the AI era

AI usage is evident but isn't yet a serious problem

ai

OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it

OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]

malware

ClickFix attack pushes macOS infostealer for crypto theft attacks

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]

security

ChainDrop: Inside a Self-Propagating npm Worm

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

cybercrime

Attackers Exploit Law Enforcement Coordination Gaps

Cybercriminals are outpacing law enforcement efforts by adapting their tactics to evade detection. This is largely due to law enforcement agencies operating in silos, hindering effective coordination and response to evolving threats.

security

Snowflake Hacker Pleads Guilty in US Court

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek.