PCPJack Campaign Boots TeamPCP Off Compromised Machines
ID: eeb27cc8-f9fa-55a7-acc6-0637cf7486c6
STIX ID: report--eeb27cc8-f9fa-55a7-acc6-0637cf7486c6
Feed Name: Infosecurity Magazine (News)
### Executive summary Security researchers reported PCPJack, a cloud-focused credential-theft framework that worms through exposed cloud infrastructure, removes traces of the TeamPCP group, and harvests credentials from Docker, Kubernetes, Redis, MongoDB, RayML and vulnerable web apps. SentinelOne links the activity to actors familiar with TeamPCP tooling and warns the campaign prioritizes monetization via stolen access rather than cryptocurrency mining; recommended mitigations include secrets management, MFA for service accounts, IMDSv2 enforcement, and least-privilege for cloud and Kubernetes resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
