TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform
ID: 1afb5b20-761f-5a86-ae57-21e9585c5d21
STIX ID: report--1afb5b20-761f-5a86-ae57-21e9585c5d21
Feed Name: cybersecurityNews.com
Threat Score
**TeamPCP cloud-native campaign (Dec 2025):** A large-scale criminal campaign exploited exposed Docker APIs, Kubernetes, Ray dashboards, Redis, and React2Shell to deploy self-propagating malicious containers that converted compromised cloud hosts (predominantly Azure and AWS) into persistent scanning/proxy/cryptomining/ransomware nodes; investigators observed 185 compromised servers with clear C2 indicators and public data leaks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
