TeamPCP Linked to Redis Attacks Dating Back to 2020 and Later Supply Chain Campaign
A new analysis by Oligo Security has uncovered that the threat actor known as TeamPCP has been active in the cybercrime scene…
A new analysis by Oligo Security has uncovered that the threat actor known as TeamPCP has been active in the cybercrime scene…
TeamPCP is a threat actor active since at least 2020, initially targeting Redis servers and later evolving into sophisticated supply chain attacks.…
Kamikaze is a wiper malware used by TeamPCP to wipe all nodes in a Kubernetes cluster. It is deployed via a DaemonSet…
CanisterWorm is a backdoor deployed by TeamPCP on Kubernetes nodes located outside Iran. It is part of the group's evolving malware arsenal,…
kube.py is a Python script used by TeamPCP after breaching Kubernetes environments. Early versions focused on propagation and persistence, while newer variants…
Oligo Security is a cybersecurity company whose researchers Avi Lumelsky and Gal Elbaz conducted the analysis linking TeamPCP to Redis attacks dating…
[TeamPCP](https://attack.mitre.org/groups/G1056) is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency…
Flare is a cybersecurity company that documented a massive campaign by TeamPCP targeting cloud-native environments. The campaign aimed to build distributed proxy…