logo

PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems

ID: 0773afd3-2678-586b-94fb-385bae46cc3f

STIX ID: report--0773afd3-2678-586b-94fb-385bae46cc3f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: [email protected] (The Hacker News)

...
...

PCPJack is a newly disclosed credential-theft framework that targets exposed cloud and container infrastructure (Docker, Kubernetes, Redis, MongoDB, RayML and vulnerable web apps). Operators use a bootstrap script and six Python payloads (orchestrator, parser, lateral movement, crypto utility, cloud ranges, and cloud scanner) to harvest and encrypt credentials, exploit known CVEs for propagation, and exfiltrate data via Telegram C2; the campaign appears financially motivated and exhibits worm-like lateral spread with ties to the TeamPCP cluster.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.