PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
ID: bb69171e-8df5-5315-b211-f2df74219a41
STIX ID: report--bb69171e-8df5-5315-b211-f2df74219a41
Threat Score
SentinelLABS describes PCPJack, a modular credential-harvesting worm that spreads across exposed cloud infrastructure (Docker, Kubernetes, Redis, MongoDB, RayML, vulnerable web apps) by scanning cloud IP ranges and parsing Common Crawl parquet data; it evicts TeamPCP artifacts, harvests a wide range of secrets, exfiltrates data via Telegram and typosquatted domains, employs Sliver beacons for C2, and includes detailed indicators (IPs, domains, file hashes) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
