LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1056: TeamPCP

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.[1][2][3][4][5][6]

EnterpriseG1056GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1056: TeamPCP describes [TeamPCP](https://attack.mitre.org/groups/G1056) is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, [TeamPCP](https://attack.mitre.org/groups/G1056) shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. [TeamPCP](https://attack.mitre.org/groups/G1056) has monetized access through exto...

Executive priority

G1056: TeamPCP is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1056: TeamPCP by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1056: TeamPCP appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

TeamPCP

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.[1][2][3][4][5][6]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

36 rows
DomainIDNameRelationship / procedure
EnterpriseT1027.003SteganographySub-technique

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.CitationAikido TeamPCP Telnyx MAR 2026[5]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits.[4] TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.CitationAikido TeamPCP Telnyx MAR 2026[5]

EnterpriseT1543.002Systemd ServiceSub-technique

TeamPCP has used the systemd user service for malware persistence in targeted environments.CitationWiz TeamPCP KICS MAR 2026

EnterpriseT1555.006Cloud Secrets Management StoresSub-technique

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.CitationSysdig TeamPCP MAR 2026CitationAikido TeamPCP Telnyx MAR 2026[5]CitationFBI TeamPCP JUL 2026

EnterpriseT1583.001DomainsSub-technique

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints.[2][3][4]CitationSysdig TeamPCP MAR 2026CitationWiz TeamPCP KICS MAR 2026CitationWiz Mini Shai-Hulud MAY 2026[6]CitationPhoenix TeamPCP 20 MAY 2026 TeamPCP has also set up a dark web leak site to post stolen data.[5]CitationFBI TeamPCP JUL 2026

EnterpriseT1528Steal Application Access Token

TeamPCP has used malware to steal access tokens from targeted cloud and developer environments.[2][4][5][6]CitationFBI TeamPCP JUL 2026

EnterpriseT1059.006PythonSub-technique

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.CitationHunt.io TeamPCP Toolkit MAY 2026CitationAikido TeamPCP Telnyx MAR 2026[6]CitationHunt.io TeamPCP Toolkit MAY 2026

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

TeamPCP has dropped malware into the Windows Startup folder to establish persistence.CitationAikido TeamPCP Telnyx MAR 2026

EnterpriseT1552.004Private KeysSub-technique

TeamPCP has used malware to extract SSH and GPG keys from victim environments.[2][5]CitationFBI TeamPCP JUL 2026

EnterpriseT1105Ingress Tool Transfer

TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.CitationWiz TeamPCP KICS MAR 2026CitationAikido TeamPCP Telnyx MAR 2026

EnterpriseT1486Data Encrypted for Impact

TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums.[5]

EnterpriseT1190Exploit Public-Facing Application

TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.[4]CitationAikido TeamPCP Telnyx MAR 2026[5]CitationWiz Mini Shai-Hulud MAY 2026

EnterpriseT1078Valid Accounts

TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.CitationAikido TeamPCP Telnyx MAR 2026

EnterpriseT1587.001MalwareSub-technique

TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud.[2]

EnterpriseT1583.006Web ServicesSub-technique

TeamPCP has set up Clouflare Tunnels for malware C2.[2][4]CitationAikido TeamPCP Telnyx MAR 2026[6] TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via  *.getsession[.]org to recipient  ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`.CitationWiz Mini Shai-Hulud MAY 2026

EnterpriseT1195.001Compromise Software Dependencies and Development ToolsSub-technique

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.[2][3]CitationWiz TeamPCP KICS MAR 2026CitationAikido TeamPCP Telnyx MAR 2026[5]CitationWiz Mini Shai-Hulud MAY 2026[6]CitationHunt.io TeamPCP Toolkit MAY 2026CitationPhoenix TeamPCP 20 MAY 2026CitationFlashpoint Mini Shai-Hulud MAY 2026CitationFBI TeamPCP JUL 2026[7]

EnterpriseT1098Account Manipulation

TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.[4]

EnterpriseT1550.001Application Access TokenSub-technique

TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments.[2]CitationAikido TeamPCP Telnyx MAR 2026[5]

EnterpriseT1684.001ImpersonationSub-technique

TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository.[2][4]

EnterpriseT1078.004Cloud AccountsSub-technique

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.[2][3][4]CitationWiz TeamPCP KICS MAR 2026[5]CitationWiz Mini Shai-Hulud MAY 2026[6][6]CitationPhoenix TeamPCP 20 MAY 2026

EnterpriseT1546.016Installer PackagesSub-technique

TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads.CitationWiz Mini Shai-Hulud MAY 2026

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.CitationAikido TeamPCP Telnyx MAR 2026

EnterpriseT1485Data Destruction

TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.[5]

EnterpriseT1683.001Written ContentSub-technique

TeamPCP has created Dune-themed GitHub repositories using stolen tokens.CitationWiz Mini Shai-Hulud MAY 2026

EnterpriseT1585.001Social Media AccountsSub-technique

TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications.[5][6]CitationPhoenix TeamPCP 20 MAY 2026

EnterpriseT1059.007JavaScriptSub-technique

TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.CitationWiz TeamPCP KICS MAR 2026[6]

EnterpriseT1553.002Code SigningSub-technique

TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing.[6]

EnterpriseT1005Data from Local System

TeamPCP has stolen source code from victim environments including Mistral AI.CitationFlashpoint Mini Shai-Hulud MAY 2026

EnterpriseT1657Financial Theft

TeamPCP has engaged in cryptocurrency mining and theft.[5][6] TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware.CitationFlashpoint Mini Shai-Hulud MAY 2026CitationPhoenix TeamPCP 20 MAY 2026CitationFBI TeamPCP JUL 2026

EnterpriseT1059.013Container CLI/APISub-technique

TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement.CitationPhoenix TeamPCP 20 MAY 2026CitationWiz TeamPCP KICS MAR 2026

EnterpriseT1059.004Unix ShellSub-technique

TeamPCP has leveraged malware capable of execution via the Linux CLI.CitationHunt.io TeamPCP Toolkit MAY 2026

EnterpriseT1583.004ServerSub-technique

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.CitationHunt.io TeamPCP Toolkit MAY 2026CitationFBI TeamPCP JUL 2026

EnterpriseT1608.001Upload MalwareSub-technique

TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.[3]

EnterpriseT1677Poisoned Pipeline Execution

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.[2][3][3][4]CitationSysdig TeamPCP MAR 2026CitationWiz TeamPCP KICS MAR 2026CitationAikido TeamPCP Telnyx MAR 2026[5][5]CitationWiz Mini Shai-Hulud MAY 2026[6]CitationHunt.io TeamPCP Toolkit MAY 2026CitationPhoenix TeamPCP 20 MAY 2026CitationFlashpoint Mini Shai-Hulud MAY 2026CitationFBI TeamPCP JUL 2026[7]

EnterpriseT1583Acquire Infrastructure

In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.CitationFlashpoint Mini Shai-Hulud MAY 2026

EnterpriseT1176.002IDE ExtensionsSub-technique

TeamPCP has compromised VS Code and Open VSX IDE extensions.CitationWiz TeamPCP KICS MAR 2026CitationAikido TeamPCP Telnyx MAR 2026[6]CitationPhoenix TeamPCP 20 MAY 2026CitationFlashpoint Mini Shai-Hulud MAY 2026

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S9042: CanisterWorm

CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns since at least 2026. CanisterWorm has used npm credentials to infect software packages and propagate across developer ecosystems. CanisterWorm has a targeted wiper component and can use decentralized C2 infrastructure implemented via an Internet Computer Protocol (ICP) blockchain canister.[1][2][3][4]

ContainersLinux
MalwareEnterprise

S9043: Mini Shai-Hulud

Mini Shai-Hulud is a credential stealer and self-replicating supply chain worm, derived from Shai-Hulud, that has been used by TeamPCP to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026. Mini Shai-Hulud can compromise credentials across multiple cloud, container, and AI configuration file paths and can use stolen npm and GitHub OIDC tokens to spread to other packages maintained by the compromised user. Mini Shai-Hulud also has a targeted wiper component and has used multiple C2 and data exfiltration mechanisms.[1][2][3][4][5][6]

ContainersIaaSLinux
MalwareEnterprise

S9041: TeamPCP Cloud Stealer

The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The TeamPCP Cloud Stealer was the primary payload used by TeamPCP in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.[1][2][3][4][5][6][7][8]

ContainersLinuxmacOS
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
a02afca0e255f6ff...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundlea02afca0e255…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Wiz TeamPCP Profile MAY 2026

    Wiz. (2026, May 20). TeamPCP. Retrieved July 16, 2026.

    Open source URL
  2. [2]
    Wiz Trivy Compromise MAR 2026

    McCarthy, R. (2026, March 20). Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack. Retrieved July 1, 2026.

    Open source URL
  3. [3]
    Aqua Security Trivy Compromise MAR 2026

    Aqua Security . (2026, March 21). Trivy ecosystem supply chain temporarily compromised. Retrieved July 1, 2026.

    Open source URL
  4. [4]
    Aqua Security Blog Trivy Compromise APR 2026

    Aqua Team. (2026, April 1). Update: Ongoing Investigation and Continued Remediation. Retrieved July 1, 2026.

    Open source URL
  5. [5]
    Palo Alto TeamPCP MAR 2026

    Unit 42. (2026, March 31). Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure. Retrieved July 1, 2026.

    Open source URL
  6. [6]
    Trend Micro TeamPCP MAY 2026

    Santos, J. and Navato, J.R. (2026, May 13). Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft. Retrieved July 16, 2026.

    Open source URL
  7. [7]
    Google AI Threat Tracker MAY 2026

    Google Threat Intelligence Group. (2026, May 11). GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access. Retrieved July 7, 2026.

    Open source URL
  8. [8]
    DeadCatx3

    (Citation: Palo Alto TeamPCP MAR 2026)

  9. [9]
    PCPCat

    (Citation: Palo Alto TeamPCP MAR 2026)

  10. [10]
    ShellForce

    (Citation: Palo Alto TeamPCP MAR 2026)

  11. [11]
    UNC6780

    (Citation: Google AI Threat Tracker MAY 2026)

  12. [12]
    mitre-attackG1056
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.