TeamPCP Worm Exploits Cloud Infrastructure to Build Criminal Infrastructure
ID: 50dcce73-a158-5d30-a06e-b6d1175b38d5
STIX ID: report--50dcce73-a158-5d30-a06e-b6d1175b38d5
Feed Name: The Hacker News
Threat Score
**TeamPCP (aka DeadCatx3/PCPcat/ShellForce) conducted a worm-driven, cloud-native campaign beginning December 2025 that leveraged exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, vulnerable React/Next.js apps (notably CVE-2025-55182, CVSS 10.0) and misconfigurations to deploy proxy/tunneling infrastructure, scanners, and post-exploitation payloads for widespread propagation, data exfiltration, ransomware/extortion, and cryptomining.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
