logo

Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

ID: 1faebc74-dd6b-5745-b82e-4fd1b41953f3

STIX ID: report--1faebc74-dd6b-5745-b82e-4fd1b41953f3

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2026-03-20

Date Updated: 2026-08-27

Author: Ruben Groenewoud

...
...

This report presents an applied detection-engineering walkthrough of the TeamPCP cloud-native attack chain (cryptojacking / cloud-native ransomware-associated), tracing stages from initial download-and-execute to Kubernetes discovery, lateral movement using stolen service-account tokens, privileged DaemonSet creation and node-escape attempts, tunneling/proxy deployment, base64-encoded payload execution, and final miner deployment; it maps each stage to D4C runtime telemetry and Kubernetes audit detections, provides detection rules, sample commands/IOCs, and shows how correlated alerts form a coherent attack narrative.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.