TeamPCP

MITRE ATT&CK: G1056 View on attack.mitre.org

Aliases: Altered Spider, TeamPCP, PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058, UNC6780

Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Last IoC activity
2026-07-05 04:25:04
Profile updated
2026-08-15 03:00:02

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Context

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.(Citation: Wiz TeamPCP Profile MAY 2026)(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Trend Micro TeamPCP MAY 2026)

Malware & tools used

Reports & references

  • Trend Micro — Teampcp Telnyx Attack Marks A Shift In Tactics (report)
  • Trend Micro — Inside Litellm Supply Chain Compromise (report)
  • tracebit.com — Detecting Cicd Supply Chain Attacks With Canary Credentials (report)
  • CrowdStrike — Altered Spider (report)
  • ic3.gov — 260702 (report)
  • flare.io — Teampcp Cloud Native Ransomware (report)
  • cstromblad.com — Threat Actor Profile Teampcp (report)
  • MITRE ATT&CK — G1056 (report)
  • cloud.google.com — Ai Vulnerability Exploitation Initial Access (report)
  • github.com — Ghsa 69Fq Xp46 6X23 (report)
  • threats.wiz.io — Teampcp (report)
  • Palo Alto Unit 42 — Teampcp Supply Chain Attacks (report)
  • aquasec.com — Trivy Supply Chain Attack What You Need To Know (report)
  • Trend Micro — Analyzing Teampcp Supply Chain Attacks (report)
  • wiz.io — Trivy Compromised Teampcp Supply Chain Attack (report)

External references