INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TeamPCP Linked To Redis Attacks Dating Back 2020
| 2026-08-07 06:50 CRITICAL HIGHExecutive Summary AI-generated
The threat actor, linked to the exploitation of security flaws in React Server Components and Next.js, has been quietly compromising internet-facing infrastructure for years. This campaign, dubbed Operation PCPcat, began dating back to 2020 with a new analysis revealing that TeamPCP has been active on the cybercrime scene since then. The group's tactics include hijacking artificial intelligence infrastructure into self-propagating botnets and targeting exposed Redis servers to deliver cryptocurrency miners. Overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft are all present in this threat actor's modus operandi. This suggests that the attackers have been building a distributed proxy and scanning infrastructure at scale for years before focusing on software supply chain vulnerabilities.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent exploitation of known security flaws, such as the use of Python scripts like "kube.py" that can be used for propagation and wiper-like functionality.
* Regularly update and patch software dependencies, including popular open-source libraries like React, Docker, Redis, and Ray, to ensure they are protected against known vulnerabilities.
* Use secure authentication mechanisms, such as OAuth or JWT-based authentication, when accessing cloud-native environments or infrastructure services to prevent unauthorized access.
* Implement network segmentation and isolation techniques to limit the spread of malware and self-propagating botnets like IronErn and ShadowRay 2.0.
* Conduct regular security audits and penetration testing to identify vulnerabilities in software supply chains and identify potential entry points for threat actors like TeamPCP.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowRayShadowRayOperation PCPcatOperation PCPcat
TeamPCPTeamPCP
CanisterWormCanisterWormWiperWiper
Target & Sectors
IR
technologytechnology
mediamedia
Incident Timeline
April 2020
Trend Micro identified a 2020 cryptojacking operation that targeted Redis servers.
Click on any entity below to view its context and source!
organisation
TA-NATALSTATUS
TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware.
organisation
Trend Micro
TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware.
organisation
Redis
TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware.
May 11, 2025
Threat actors used a 2020 cryptojacking operation to target TeamPCP.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
Certificate transparency records date it to May 11, 2025, and TeamPCP's own GitHub account later listed it as the group's official website.
organisation
GitHub
Certificate transparency records date it to May 11, 2025, and TeamPCP's own GitHub account later listed it as the group's official website.
July 2025
Avi Lumelsky, AI security researcher at Oligo Security, identified one of the domains linked to TeamPCP in July 2025.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
One of the domains that Oligo Security identified in July 2025 was in the profile of TeamPCP’s official GitHub account, said Avi Lumelsky, AI security researcher at Oligo Security.
July 26, 2025
Threat actors used compromised Ray cluster to target TeamPCP on July 26, 2025.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
A compromised Ray cluster logged a download from that infrastructure on July 26, 2025, five months before the TeamPCP name surfaced publicly.
the second half of 2025
Threat actors used a 2020 cryptojacking operation to launch two subsequent campaigns: ShadowRay 2.0, which hijacked AI infrastructure into a self-propagating botnet, and TA-NATALSTATUS, which targeted exposed Redis servers with cryptocurrency miners.
Click on any entity below to view its context and source!
tactic
Botnet
This includes two campaigns observed in the second half of 2025:
ShadowRay 2.0
(aka IronErn), which involved hijacking artificial intelligence (AI) infrastructure into a self-propagating botnet, and
TA-NATALSTATUS
, which targeted exposed Redis servers to deliver cryptocurrency miners.
campaign
ShadowRay
This includes two campaigns observed in the second half of 2025:
ShadowRay 2.0
(aka IronErn), which involved hijacking artificial intelligence (AI) infrastructure into a self-propagating botnet, and
TA-NATALSTATUS
, which targeted exposed Redis servers to deliver cryptocurrency miners.
attribution
IronErn
This includes two campaigns observed in the second half of 2025:
ShadowRay 2.0
(aka IronErn), which involved hijacking artificial intelligence (AI) infrastructure into a self-propagating botnet, and
TA-NATALSTATUS
, which targeted exposed Redis servers to deliver cryptocurrency miners.
attribution
Redis
This includes two campaigns observed in the second half of 2025:
ShadowRay 2.0
(aka IronErn), which involved hijacking artificial intelligence (AI) infrastructure into a self-propagating botnet, and
TA-NATALSTATUS
, which targeted exposed Redis servers to deliver cryptocurrency miners.
general_metric
2.0 ShadowRay
This includes two campaigns observed in the second half of 2025:
ShadowRay 2.0
(aka IronErn), which involved hijacking artificial intelligence (AI) infrastructure into a self-propagating botnet, and
TA-NATALSTATUS
, which targeted exposed Redis servers to deliver cryptocurrency miners.
around Christmas 2025
Threat actors used React2Shell to target PCPcat, which peaked around Christmas 2025 against various targets including Trivy and Checkmarx's KICS.
Click on any entity below to view its context and source!
organisation
PCPcat
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
organisation
React2Shell
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
organisation
Checkmarx
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
organisation
KICS
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
2025/08/07
Threat actors used a 2020 cryptojacking operation to exploit security flaws in React Server Components (RSC) and Next.js.
Click on any entity below to view its context and source!
observable
Next.js
Details of the attackers first emerged towards the end of last year when they were linked to the exploitation of security flaws in React Server Components (RSC) and Next.js to facilitate the extraction of credentials and sensitive data from compromised environments.
tactic
T1584.004 - Server
Details of the attackers first emerged towards the end of last year when they were linked to the exploitation of security flaws in React Server Components (RSC) and Next.js to facilitate the extraction of credentials and sensitive data from compromised environments.
organisation
RSC
Details of the attackers first emerged towards the end of last year when they were linked to the exploitation of security flaws in React Server Components (RSC) and Next.js to facilitate the extraction of credentials and sensitive data from compromised environments.
late 2025
Threat actors used a 2020 cryptojacking operation as the basis for their ongoing TeamPCP cyber attack.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
"What the evidence does demonstrate is that TeamPCP represents the continuation of an existing operational ecosystem rather than an entirely new threat actor that appeared in late 2025."
What the evidence shows is that TeamPCP continues an existing operational ecosystem rather than being a new group that appeared in late 2025.
TeamPCP emerged publicly as a brand in late 2025.
November 2025
The incident involved the use of ShadowRay 2.0, a cryptojacking tool, by TeamPCP against exposed Ray clusters in November 2025.
Click on any entity below to view its context and source!
campaign
ShadowRay
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
general_metric
2.0 ShadowRay
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
threat_actor
TeamPCP
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
March 2026
Threat actors used React2Shell to target Trivy and Checkmarx's KICS, then exploited Docker APIs in March 2026 before transitioning to wiper-like functionality against LiteLLM.
Click on any entity below to view its context and source!
tactic
Wiper
While earlier versions of the script focused on propagation and setting up persistence, new variants observed as recently as March 2026 began to incorporate wiper-like functionality.
organisation
PCPcat
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
organisation
React2Shell
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
organisation
Checkmarx
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
organisation
KICS
That progression ran through PCPcat, which peaked around Christmas 2025 against
React2Shell targets
and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
07, 2026
Threat actors tracked as TeamPCP began targeting internet-facing infrastructure in 2020.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
Ravie Lakshmanan
Aug 07, 2026
Cybercrime / Vulnerability
A new analysis has uncovered that the threat actor tracked as
TeamPCP
has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.
organisation
Cybercrime / Vulnerability
Ravie Lakshmanan
Aug 07, 2026
Cybercrime / Vulnerability
A new analysis has uncovered that the threat actor tracked as
TeamPCP
has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.
August 5
Threat actors used malware to target TeamPCP between August 5, 2020 and August 2025.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
New research published by Oligo Security on August 5 showed that
TeamPCP
shares domains, malware deployment paths and backend infrastructure with activity previously tracked as TA-NATALSTATUS between 2020 and August 2025.
organisation
Oligo Security
New research published by Oligo Security on August 5 showed that
TeamPCP
shares domains, malware deployment paths and backend infrastructure with activity previously tracked as TA-NATALSTATUS between 2020 and August 2025.
Aug 07, 2026
Threat actors used malware to infect the network of a 2020 cryptojacking operation.
between 2020 and August 2025
Threat actors used malware to target TeamPCP between 2020 and August 2025.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
New research published by Oligo Security on August 5 showed that
TeamPCP
shares domains, malware deployment paths and backend infrastructure with activity previously tracked as TA-NATALSTATUS between 2020 and August 2025.
organisation
Oligo Security
New research published by Oligo Security on August 5 showed that
TeamPCP
shares domains, malware deployment paths and backend infrastructure with activity previously tracked as TA-NATALSTATUS between 2020 and August 2025.
between October 15 and November 2
One IP address was used to host a compromised Ray cluster between October 15 and November 2.
Click on any entity below to view its context and source!
organisation
IP
One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2.
All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling.
organisation
ironern440
One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2.
All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling.
data_breach
4 November
One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2.
All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling.
2026/08/07
TeamPCP linked to Redis attacks dating back to 2020 and later supply chain campaigns.
Click on any entity below to view its context and source!
organisation
DaemonSet
This
destructive code path
checked whether the victim system was configured for the Iran timezone and, if that's the case, fired a DaemonSet that wiped every node in the cluster via a wiper not-so-subtly named Kamikaze.
organisation
GitHub Actions
From Cryptojacking to Wiper
Oligo's timeline has the operators exploiting internet-facing infrastructure as early as 2020, often with automated and wormable techniques, before expanding into GitHub Actions abuse and token theft.
The group has since branched into
high-profile supply chain compromises
, weaponizing the interconnected nature of modern software to infect developer systems en masse by poisoning popular open-source libraries through a combination of GitHub Actions and token theft abuse.
organisation
Cryptojacking to
From Cryptojacking to Wiper
Oligo's timeline has the operators exploiting internet-facing infrastructure as early as 2020, often with automated and wormable techniques, before expanding into GitHub Actions abuse and token theft.
threat_actor
TeamPCP
The security vendor’s research team found multiple attacks that bear the markings of TeamPCP, including a late 2025 campaign involving the exploitation of a ShadowRay vulnerability that resulted in the first self-propogating botnet running on hijacked AI infrastructure.
"One of the strongest operational links is the overlap between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0 and TeamPCP's later infrastructure," Oligo said.
"Correlating GitLab authentication logs, command-and-control infrastructure, reverse-shell activity, and malware staging establishes a direct operational bridge between the ShadowRay 2.0 campaign and the actor later operating publicly as TeamPCP.
Evidence uncovered during that
investigation into the ShadowRay 2.0 campaign
was linked to more historical attacks originating from the same IPs, domains and other infrastructure TeamPCP used in attacks that captured widespread attention earlier this year.
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign.
This suggests that the threat actor has been actively targeting internet-accessible infrastructure across Ray, Docker, Redis, and React much before it branded itself as TeamPCP.
TeamPCP Traced Back to 2020 Cryptojacking Operation.
Alongside it, Oligo found the same deployment framework reused for years: a distinctive directory path and a set of staging scripts documented in earlier TA-NATALSTATUS campaigns turning up unchanged in TeamPCP payloads.
Widespread adoption of AI and TeamPCP’s use of the technology supported this growth as the threat actor built a brand, got more active on social media and boasted publicly about its activities and claimed victims.
Open-source software’s archenemy TeamPCP goes back further than anyone thought.
TeamPCP, the threat actor behind an unrelenting
flurry of attacks on open-source software
this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop.
From there, Oligo linked TeamPCP to activity tracked under multiple names, including TA-NATALSTATUS and IronErn, spanning from 2020 to late 2025.
Soon after, “TeamPCP started to go really broad and do campaigns, which are much more noisy,” said Gal Elbaz, co-founder and CTO at Oligo Security.
“If you don’t really have visibility in what’s going on there or how it behaves, that’s exactly what attackers are after.”
TeamPCP’s more recent attacks have capitalized on new security gaps created by developers’ increasing reliance on AI and the automated systems companies use to deploy code.
As it uncovered a long operational history spanning multiple campaigns, Oligo Security has gained more confidence in understanding how TeamPCP operates.
It also means TeamPCP was likely involved in other attacks that haven’t been attributed to it yet or attacks that haven’t been detected.
organisation
GitLab
"One of the strongest operational links is the overlap between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0 and TeamPCP's later infrastructure," Oligo said.
Oligo Security worked with Mandiant and GitLab on the investigation, and GitLab banned the accounts involved.
organisation
Oligo
"One of the strongest operational links is the overlap between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0 and TeamPCP's later infrastructure," Oligo said.
Alongside it, Oligo found the same deployment framework reused for years: a distinctive directory path and a set of staging scripts documented in earlier TA-NATALSTATUS campaigns turning up unchanged in TeamPCP payloads.
From there, Oligo linked TeamPCP to activity tracked under multiple names, including TA-NATALSTATUS and IronErn, spanning from 2020 to late 2025.
organisation
Kubernetes
These shifts have been complemented by continuous updates to its malware arsenal, including a Python script ("kube.py") that's specifically used after breaching Kubernetes environments.
organisation
Later Supply Chain Campaign
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign.
organisation
Traced Back
TeamPCP Traced Back to 2020 Cryptojacking Operation.
organisation
TA-NATALSTATUS
Alongside it, Oligo found the same deployment framework reused for years: a distinctive directory path and a set of staging scripts documented in earlier TA-NATALSTATUS campaigns turning up unchanged in TeamPCP payloads.
From there, Oligo linked TeamPCP to activity tracked under multiple names, including TA-NATALSTATUS and IronErn, spanning from 2020 to late 2025.
organisation
Oligo Security
TeamPCP, the threat actor behind an unrelenting
flurry of attacks on open-source software
this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop.
"The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft," Oligo Security researchers Avi Lumelsky and Gal Elbaz
said
.
organisation
CyberScoop
TeamPCP, the threat actor behind an unrelenting
flurry of attacks on open-source software
this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop.
organisation
IronErn
From there, Oligo linked TeamPCP to activity tracked under multiple names, including TA-NATALSTATUS and IronErn, spanning from 2020 to late 2025.
organisation
CTO
Soon after, “TeamPCP started to go really broad and do campaigns, which are much more noisy,” said Gal Elbaz, co-founder and CTO at Oligo Security.
organisation
Mandiant
Oligo Security worked with Mandiant and GitLab on the investigation, and GitLab banned the accounts involved.
November 2
One IP address was used to host a compromised Ray cluster between October 15 and November 2.
Click on any entity below to view its context and source!
organisation
IP
One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2.
All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling.
organisation
ironern440
One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2.
All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling.
data_breach
4 November
One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2.
All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling.
Tactical Metrics
Metrics
data_breach
4
November
Click for context!
One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2.
All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling.
Intelligence Sources
CyberScoop
2026-08-05
The Hacker News
2026-08-07
Infosecurity-Magazine
2026-08-06
TeamPCP Traced Back to 2020 Cryptojacking Operation
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-07T11:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
25x
organisation
Identified Entity
DaemonSet
entity
18x
timeline
Temporal Reference
the second half of 2025
date
7x
tactic
Cyber Operation Type
Wiper
tactic
2x
malware
Malware Payload
CanisterWorm
tool
2x
campaign
Campaign
ShadowRay
operation
2x
attribution
Attributing Entity
IronErn
authority
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
industry
Targeted Sector
Technology
sector
Contextual Telemetry
Context Block
7 METRICS
target region
Target Country
Iran, Islamic Republic of
country
general metric
Shadowray
2
shadowray
threat actor
APT Group
TeamPCP
actor
general metric
%
100
%
data breach
November
4
november
source region
Origin Country
Iran, Islamic Republic of
country
general metric
Software Packages
1,000
software packages
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.