TeamPCP Turns Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform
ID: b34753fd-01fe-5bc3-b6eb-05c9f1591bdb
STIX ID: report--b34753fd-01fe-5bc3-b6eb-05c9f1591bdb
Feed Name: GBHackers
Threat Score
Operation PCPcat (TeamPCP) is a cloud-native, worm-capable cybercrime campaign that leverages exposed Docker/Kubernetes APIs and the React2Shell vulnerability to rapidly compromise cloud workloads, deploy cryptominers and Sliver-based C2, harvest credentials and secrets, and persist via privileged DaemonSets; the campaign reportedly compromised tens of thousands of servers in 48 hours and has publicly leaked stolen datasets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
