CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

TeamPCP: From Redis Exploitation to Supply Chain Attacks

August 7, 2026

TeamPCP is a threat actor active since at least 2020, initially targeting Redis servers and later evolving into sophisticated supply chain attacks. The group has been linked to campaigns such as ShadowRay 2.0 and TA-NATALSTATUS, exploiting vulnerabilities in Redis, Docker, Ray, and React. They have also been involved in Operation PCPcat and have developed destructive malware like Kamikaze and CanisterWorm for Kubernetes environments.