TeamPCP
MITRE ATT&CK: G1056 View on attack.mitre.org
Aliases: Altered Spider, TeamPCP, PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058, UNC6780
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Last IoC activity
- 2026-07-05 04:25:04
- Profile updated
- 2026-08-15 03:00:02
Targeted industries: technology-and-telecommunications government-and-public-sector financial-services
Context
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.(Citation: Wiz TeamPCP Profile MAY 2026)(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Trend Micro TeamPCP MAY 2026)
Malware & tools used
- CanisterWorm (malware)
- Mini Shai-Hulud (malware)
- TeamPCP Cloud Stealer (malware)
Reports & references
- Trend Micro — Teampcp Telnyx Attack Marks A Shift In Tactics (report)
- Trend Micro — Inside Litellm Supply Chain Compromise (report)
- tracebit.com — Detecting Cicd Supply Chain Attacks With Canary Credentials (report)
- CrowdStrike — Altered Spider (report)
- ic3.gov — 260702 (report)
- flare.io — Teampcp Cloud Native Ransomware (report)
- cstromblad.com — Threat Actor Profile Teampcp (report)
- MITRE ATT&CK — G1056 (report)
- cloud.google.com — Ai Vulnerability Exploitation Initial Access (report)
- github.com — Ghsa 69Fq Xp46 6X23 (report)
- threats.wiz.io — Teampcp (report)
- Palo Alto Unit 42 — Teampcp Supply Chain Attacks (report)
- aquasec.com — Trivy Supply Chain Attack What You Need To Know (report)
- Trend Micro — Analyzing Teampcp Supply Chain Attacks (report)
- wiz.io — Trivy Compromised Teampcp Supply Chain Attack (report)