TeamPCP Active Since 2020, Oligo Security Finds

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- TeamPCP has been active since 2020, compromising internet-facing infrastructure years before pivoting to supply chain attacks, per Oligo Security researchers Avi Lumelsky and Gal Elbaz, who cite overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft as evidence.
- Oligo Security linked TeamPCP to two H2 2025 campaigns: ShadowRay 2.0 (IronErn), which hijacked AI infrastructure into a self-propagating botnet, and TA-NATALSTATUS, which targeted Redis servers to deliver cryptocurrency miners.
- TA-NATALSTATUS is assessed to be an evolution of a Trend Micro-documented April 2020 campaign that targeted Redis servers for malware deployment, indicating the threat actor had been hitting Ray, Docker, Redis, and React infrastructure long before branding itself as TeamPCP.
- Operation PCPcat, first detailed late last year, exploited security flaws in React Server Components and Next.js to extract credentials and sensitive data from compromised environments.
- Flare researchers documented a separate campaign in which TeamPCP systematically targeted cloud native environments to build distributed proxy and scanning infrastructure for ransomware, extortion, and cryptocurrency mining.
- TeamPCP has weaponized GitHub Actions and token theft abuse to poison popular open-source libraries, infecting developer systems en masse through cascading supply chain compromises.
- "Kamikaze" wiper functionality, added to TeamPCP's "kube.py" Python script as recently as March 2026, checks for the Iran timezone and wipes Kubernetes clusters via DaemonSet — while deploying the CanisterWorm backdoor on non-Iran nodes and a "poison_pill()" file-system eraser on non-Kubernetes Iranian systems.
Why it matters: TeamPCP's true operational history now spans at least six years across Ray, Docker, Redis, and React infrastructure, with the supply chain pivot amplifying blast radius across developer ecosystems. The Iran-timezone-triggered wiper adds a geopolitical targeting layer to what earlier coverage had framed as a purely financially motivated operation.



