INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TeamPCP Linked To Redis Attacks Dating Back 2020

| 2026-08-07 06:50 CRITICAL HIGH
Executive Summary AI-generated
The threat actor, linked to the exploitation of security flaws in React Server Components and Next.js, has been quietly compromising internet-facing infrastructure for years. This campaign, dubbed Operation PCPcat, began dating back to 2020 with a new analysis revealing that TeamPCP has been active on the cybercrime scene since then. The group's tactics include hijacking artificial intelligence infrastructure into self-propagating botnets and targeting exposed Redis servers to deliver cryptocurrency miners. Overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft are all present in this threat actor's modus operandi. This suggests that the attackers have been building a distributed proxy and scanning infrastructure at scale for years before focusing on software supply chain vulnerabilities.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent exploitation of known security flaws, such as the use of Python scripts like "kube.py" that can be used for propagation and wiper-like functionality. * Regularly update and patch software dependencies, including popular open-source libraries like React, Docker, Redis, and Ray, to ensure they are protected against known vulnerabilities. * Use secure authentication mechanisms, such as OAuth or JWT-based authentication, when accessing cloud-native environments or infrastructure services to prevent unauthorized access. * Implement network segmentation and isolation techniques to limit the spread of malware and self-propagating botnets like IronErn and ShadowRay 2.0. * Conduct regular security audits and penetration testing to identify vulnerabilities in software supply chains and identify potential entry points for threat actors like TeamPCP.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowRayShadowRayOperation PCPcatOperation PCPcat TeamPCPTeamPCP CanisterWormCanisterWormWiperWiper
Target & Sectors
IR
technologytechnology mediamedia
Incident Timeline
‎April 2020
Trend Micro identified a 2020 cryptojacking operation that targeted Redis servers.
organisation TA-NATALSTATUS
organisation Trend Micro
organisation Redis
‎May 11, 2025
Threat actors used a 2020 cryptojacking operation to target TeamPCP.
threat_actor TeamPCP
organisation GitHub
‎July 2025
Avi Lumelsky, AI security researcher at Oligo Security, identified one of the domains linked to TeamPCP in July 2025.
threat_actor TeamPCP
‎July 26, 2025
Threat actors used compromised Ray cluster to target TeamPCP on July 26, 2025.
threat_actor TeamPCP
‎the second half of 2025
Threat actors used a 2020 cryptojacking operation to launch two subsequent campaigns: ShadowRay 2.0, which hijacked AI infrastructure into a self-propagating botnet, and TA-NATALSTATUS, which targeted exposed Redis servers with cryptocurrency miners.
tactic Botnet
campaign ShadowRay
attribution IronErn
attribution Redis
general_metric 2.0 ShadowRay
‎around Christmas 2025
Threat actors used React2Shell to target PCPcat, which peaked around Christmas 2025 against various targets including Trivy and Checkmarx's KICS.
organisation PCPcat
organisation React2Shell
organisation Checkmarx
organisation KICS
‎2025/08/07
Threat actors used a 2020 cryptojacking operation to exploit security flaws in React Server Components (RSC) and Next.js.
observable Next.js
tactic T1584.004 - Server
organisation RSC
‎late 2025
Threat actors used a 2020 cryptojacking operation as the basis for their ongoing TeamPCP cyber attack.
threat_actor TeamPCP
‎November 2025
The incident involved the use of ShadowRay 2.0, a cryptojacking tool, by TeamPCP against exposed Ray clusters in November 2025.
campaign ShadowRay
general_metric 2.0 ShadowRay
threat_actor TeamPCP
‎March 2026
Threat actors used React2Shell to target Trivy and Checkmarx's KICS, then exploited Docker APIs in March 2026 before transitioning to wiper-like functionality against LiteLLM.
tactic Wiper
organisation PCPcat
organisation React2Shell
organisation Checkmarx
organisation KICS
‎07, 2026
Threat actors tracked as TeamPCP began targeting internet-facing infrastructure in 2020.
threat_actor TeamPCP
organisation Cybercrime / Vulnerability
‎August 5
Threat actors used malware to target TeamPCP between August 5, 2020 and August 2025.
threat_actor TeamPCP
organisation Oligo Security
‎Aug 07, 2026
Threat actors used malware to infect the network of a 2020 cryptojacking operation.
‎between 2020 and August 2025
Threat actors used malware to target TeamPCP between 2020 and August 2025.
threat_actor TeamPCP
organisation Oligo Security
‎between October 15 and November 2
One IP address was used to host a compromised Ray cluster between October 15 and November 2.
organisation IP
organisation ironern440
data_breach 4 November
‎2026/08/07
TeamPCP linked to Redis attacks dating back to 2020 and later supply chain campaigns.
organisation DaemonSet
organisation GitHub Actions
organisation Cryptojacking to
threat_actor TeamPCP
organisation GitLab
organisation Oligo
organisation Kubernetes
organisation Later Supply Chain Campaign
organisation Traced Back
organisation TA-NATALSTATUS
organisation Oligo Security
organisation CyberScoop
organisation IronErn
organisation CTO
organisation Mandiant
‎November 2
One IP address was used to host a compromised Ray cluster between October 15 and November 2.
organisation IP
organisation ironern440
data_breach 4 November
Tactical Metrics
Metrics
data_breach
4
November
Intelligence Sources