logo

TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform

ID: 1afb5b20-761f-5a86-ae57-21e9585c5d21

STIX ID: report--1afb5b20-761f-5a86-ae57-21e9585c5d21

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**TeamPCP cloud-native campaign (Dec 2025):** A large-scale criminal campaign exploited exposed Docker APIs, Kubernetes, Ray dashboards, Redis, and React2Shell to deploy self-propagating malicious containers that converted compromised cloud hosts (predominantly Azure and AWS) into persistent scanning/proxy/cryptomining/ransomware nodes; investigators observed 185 compromised servers with clear C2 indicators and public data leaks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.