TeamPCP Cloud-Native Campaign Targeting Exposed Control Planes (Campaign)
ID: d4b26134-a98f-5772-ae99-4883d9369ff2
STIX ID: report--d4b26134-a98f-5772-ae99-4883d9369ff2
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-02-05
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
TeamPCP is running an active cloud-native campaign that abuses unauthenticated or weakly protected orchestration and management interfaces (exposed Docker/Kubernetes APIs, Redis, and a React/Next.js CVE-2025-29927) to deploy a bootstrap script (proxy.sh). The script installs tunneling/proxy tools (FRPS, gost), scanners, and persistent services, and when Kubernetes is present uses kube.py to enumerate resources, propagate to pods, and deploy a privileged DaemonSet that mounts host filesystems; additional tooling supports cryptomining, data theft, and Sliver C2 for operator-managed access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
