After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets
ID: d3562615-054a-5899-ab97-cbb35a30d2c3
STIX ID: report--d3562615-054a-5899-ab97-cbb35a30d2c3
Feed Name: Dark Reading
PCPJack is a modular Python-based cloud worm reported by SentinelLabs that steals a wide range of secrets (cloud, container, developer, productivity, financial services, and crypto wallets) and removes competing TeamPCP tooling; it establishes persistence via a bootstrap module, disguises activity through monitoring, sorts stolen secrets, moves laterally across Kubernetes, Docker, SSH and Redis, and uniquely leverages Common Crawl parquet files for pre-validated target discovery — it lacks cryptomining and appears optimized for rapid credential and wallet theft, so organizations should enforce secret vaults, MFA for service accounts, and cloud security best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
