PCP Cat is a threat actor associated with a large-scale credential theft campaign targeting exposed Next.js servers. The group has been linked to rapid mass exploitation of critical Next.js vulnerabilities, including CVE-2025-29927 and CVE-2025-66478, to obtain remote code execution on internet-facing systems. Reported tradecraft includes broad scanning of public-facing applications, exploitation of vulnerable web services, validation of code execution, harvesting of sensitive secrets from compromised hosts, and installation of persistence and tunneling components to retain access and enable follow-on operations. Observed post-compromise activity includes theft of environment secrets, SSH material, cloud configuration data, container-related credentials, source-control credentials, and shell history, indicating a strong focus on credential access and downstream account compromise. PCP Cat has also been associated with deployment of proxying and reverse-tunneling tooling, creation of persistent services, and abuse of exposed Docker management interfaces for persistence and pivoting. The actor has used malware referred to as react.py to distribute scanners and support exploitation at scale. The campaign has been publicly associated with Telegram-based branding and coordination under the PCP Cat name. Available reporting supports financially motivated operations centered on credential harvesting, cloud account takeover, and potential resale of stolen access. High-confidence behaviors include reconnaissance and scanning, initial access through exploitation of public-facing applications, credential theft, exfiltration, persistence, lateral or network pivot enablement through tunneling, and broader post-exploitation activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.