G1056: TeamPCP
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.[1][2][3][4][5][6]
Security context for executives and security teams
G1056: TeamPCP describes [TeamPCP](https://attack.mitre.org/groups/G1056) is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, [TeamPCP](https://attack.mitre.org/groups/G1056) shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. [TeamPCP](https://attack.mitre.org/groups/G1056) has monetized access through exto...
Executive priority
G1056: TeamPCP is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1056: TeamPCP by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1056: TeamPCP appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
TeamPCP
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.[1][2][3][4][5][6]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1027.003 | SteganographySub-technique | |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | |
| Enterprise | T1543.002 | Systemd ServiceSub-technique | TeamPCP has used the systemd user service for malware persistence in targeted environments.CitationWiz TeamPCP KICS MAR 2026 |
| Enterprise | T1555.006 | Cloud Secrets Management StoresSub-technique | |
| Enterprise | T1583.001 | DomainsSub-technique | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints.[2][3][4]CitationSysdig TeamPCP MAR 2026CitationWiz TeamPCP KICS MAR 2026CitationWiz Mini Shai-Hulud MAY 2026[6]CitationPhoenix TeamPCP 20 MAY 2026 TeamPCP has also set up a dark web leak site to post stolen data.[5]CitationFBI TeamPCP JUL 2026 |
| Enterprise | T1528 | Steal Application Access Token | |
| Enterprise | T1059.006 | PythonSub-technique | |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | TeamPCP has dropped malware into the Windows Startup folder to establish persistence.CitationAikido TeamPCP Telnyx MAR 2026 |
| Enterprise | T1552.004 | Private KeysSub-technique | |
| Enterprise | T1105 | Ingress Tool Transfer | TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.CitationWiz TeamPCP KICS MAR 2026CitationAikido TeamPCP Telnyx MAR 2026 |
| Enterprise | T1486 | Data Encrypted for Impact | |
| Enterprise | T1190 | Exploit Public-Facing Application | |
| Enterprise | T1078 | Valid Accounts | TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.CitationAikido TeamPCP Telnyx MAR 2026 |
| Enterprise | T1587.001 | MalwareSub-technique | TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud.[2] |
| Enterprise | T1583.006 | Web ServicesSub-technique | TeamPCP has set up Clouflare Tunnels for malware C2.[2][4]CitationAikido TeamPCP Telnyx MAR 2026[6] TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`.CitationWiz Mini Shai-Hulud MAY 2026 |
| Enterprise | T1195.001 | Compromise Software Dependencies and Development ToolsSub-technique | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.[2][3]CitationWiz TeamPCP KICS MAR 2026CitationAikido TeamPCP Telnyx MAR 2026[5]CitationWiz Mini Shai-Hulud MAY 2026[6]CitationHunt.io TeamPCP Toolkit MAY 2026CitationPhoenix TeamPCP 20 MAY 2026CitationFlashpoint Mini Shai-Hulud MAY 2026CitationFBI TeamPCP JUL 2026[7] |
| Enterprise | T1098 | Account Manipulation | |
| Enterprise | T1550.001 | Application Access TokenSub-technique | |
| Enterprise | T1684.001 | ImpersonationSub-technique | |
| Enterprise | T1078.004 | Cloud AccountsSub-technique | |
| Enterprise | T1546.016 | Installer PackagesSub-technique | TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads.CitationWiz Mini Shai-Hulud MAY 2026 |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.CitationAikido TeamPCP Telnyx MAR 2026 |
| Enterprise | T1485 | Data Destruction | |
| Enterprise | T1683.001 | Written ContentSub-technique | TeamPCP has created Dune-themed GitHub repositories using stolen tokens.CitationWiz Mini Shai-Hulud MAY 2026 |
| Enterprise | T1585.001 | Social Media AccountsSub-technique | |
| Enterprise | T1059.007 | JavaScriptSub-technique | |
| Enterprise | T1553.002 | Code SigningSub-technique | |
| Enterprise | T1005 | Data from Local System | TeamPCP has stolen source code from victim environments including Mistral AI.CitationFlashpoint Mini Shai-Hulud MAY 2026 |
| Enterprise | T1657 | Financial Theft | TeamPCP has engaged in cryptocurrency mining and theft.[5][6] TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware.CitationFlashpoint Mini Shai-Hulud MAY 2026CitationPhoenix TeamPCP 20 MAY 2026CitationFBI TeamPCP JUL 2026 |
| Enterprise | T1059.013 | Container CLI/APISub-technique | TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement.CitationPhoenix TeamPCP 20 MAY 2026CitationWiz TeamPCP KICS MAR 2026 |
| Enterprise | T1059.004 | Unix ShellSub-technique | TeamPCP has leveraged malware capable of execution via the Linux CLI.CitationHunt.io TeamPCP Toolkit MAY 2026 |
| Enterprise | T1583.004 | ServerSub-technique | TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.CitationHunt.io TeamPCP Toolkit MAY 2026CitationFBI TeamPCP JUL 2026 |
| Enterprise | T1608.001 | Upload MalwareSub-technique | |
| Enterprise | T1677 | Poisoned Pipeline Execution | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.[2][3][3][4]CitationSysdig TeamPCP MAR 2026CitationWiz TeamPCP KICS MAR 2026CitationAikido TeamPCP Telnyx MAR 2026[5][5]CitationWiz Mini Shai-Hulud MAY 2026[6]CitationHunt.io TeamPCP Toolkit MAY 2026CitationPhoenix TeamPCP 20 MAY 2026CitationFlashpoint Mini Shai-Hulud MAY 2026CitationFBI TeamPCP JUL 2026[7] |
| Enterprise | T1583 | Acquire Infrastructure | In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.CitationFlashpoint Mini Shai-Hulud MAY 2026 |
| Enterprise | T1176.002 | IDE ExtensionsSub-technique |
Groups, software, and campaigns
S9042: CanisterWorm
CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns since at least 2026. CanisterWorm has used npm credentials to infect software packages and propagate across developer ecosystems. CanisterWorm has a targeted wiper component and can use decentralized C2 infrastructure implemented via an Internet Computer Protocol (ICP) blockchain canister.[1][2][3][4]
S9043: Mini Shai-Hulud
Mini Shai-Hulud is a credential stealer and self-replicating supply chain worm, derived from Shai-Hulud, that has been used by TeamPCP to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026. Mini Shai-Hulud can compromise credentials across multiple cloud, container, and AI configuration file paths and can use stolen npm and GitHub OIDC tokens to spread to other packages maintained by the compromised user. Mini Shai-Hulud also has a targeted wiper component and has used multiple C2 and data exfiltration mechanisms.[1][2][3][4][5][6]
S9041: TeamPCP Cloud Stealer
The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The TeamPCP Cloud Stealer was the primary payload used by TeamPCP in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.[1][2][3][4][5][6][7][8]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | a02afca0e255… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Wiz TeamPCP Profile MAY 2026
Wiz. (2026, May 20). TeamPCP. Retrieved July 16, 2026.
Open source URL - [2]Wiz Trivy Compromise MAR 2026
McCarthy, R. (2026, March 20). Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack. Retrieved July 1, 2026.
Open source URL - [3]Aqua Security Trivy Compromise MAR 2026
Aqua Security . (2026, March 21). Trivy ecosystem supply chain temporarily compromised. Retrieved July 1, 2026.
Open source URL - [4]Aqua Security Blog Trivy Compromise APR 2026
Aqua Team. (2026, April 1). Update: Ongoing Investigation and Continued Remediation. Retrieved July 1, 2026.
Open source URL - [5]Palo Alto TeamPCP MAR 2026
Unit 42. (2026, March 31). Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure. Retrieved July 1, 2026.
Open source URL - [6]Trend Micro TeamPCP MAY 2026
Santos, J. and Navato, J.R. (2026, May 13). Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft. Retrieved July 16, 2026.
Open source URL - [7]Google AI Threat Tracker MAY 2026
Google Threat Intelligence Group. (2026, May 11). GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access. Retrieved July 7, 2026.
Open source URL - [8]DeadCatx3
(Citation: Palo Alto TeamPCP MAR 2026)
- [9]PCPCat
(Citation: Palo Alto TeamPCP MAR 2026)
- [10]ShellForce
(Citation: Palo Alto TeamPCP MAR 2026)
- [11]UNC6780
(Citation: Google AI Threat Tracker MAY 2026)
- [12]mitre-attackG1056Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
