INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TeamPCP Booted from Compromised Machines via PCPJack Campaign

| 2026-05-08 09:00 LOW HIGH CYBERATTACK (GENERAL)
Executive Summary
AI-generated
A new threat campaign, dubbed PCPJack, has been discovered targeting victims of the notorious cybercrime group TeamPCP. The attack, which began in December 2025 and continued through May 8, 2026, aims to monetize stolen access by stealing credentials from cloud services such as Docker, Kubernetes, Redis, MongoDB, RayML, and vulnerable web applications. PCPJack is a credential theft framework that "worms across exposed cloud infrastructure" before removing artifacts associated with TeamPCP. The attack lacks cryptocurrency mining functionality but still poses significant risks to organizations, including data exposure and extortion. SentinelOne has urged organizations to defend against similar threats by implementing security best practices such as using multi-factor authentication for service accounts and enforcing access controls in AWS environments.
Technical Mitigations AI-generated
• Using authentication for Docker and Kubernetes, even if not exposed to the internet • Applying principle of least privilege to Kubernetes service accounts • Ensuring access to credential vaults is never stored in a file saved in clear text
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Boots TeamPCPCampaign Boots TeamPCP
Target & Sectors
Global Scope technologytechnology
Intelligence Sources
Infosecurity-Magazine 2026-05-08
Infosecurity-Magazine 2026-05-08