PCP Cat is a threat actor attributed in the provided content to a large-scale credential theft campaign targeting vulnerable public-facing Next.js servers. The campaign reportedly compromised 59,128 servers in less than 48 hours by exploiting CVE-2025-29927 and CVE-2025-66478, with a reported 64.6% success rate across 91,505 scanned targets. The operation is attributed to “PCP Cat” via Telegram channels including t.me/teampcp, and campaign artifacts also referenced t.me/Persy_PCP. According to the content, PCP Cat used react.py malware to scan for and exploit remote code execution conditions, including prototype pollution in JSON payloads leading to execution via child_process.execSync(). Operators reportedly validated code execution with an "id" command before extracting credentials. Stolen data included .env files, SSH keys, AWS configuration files, Docker tokens, Git credentials, and bash history. The content states harvested credentials were intended for cloud account takeover or resale. Post-compromise activity included downloading proxy.sh from 67.217.57.240:666, installing GOST SOCKS5 proxy and FRP reverse tunneling tooling, and creating persistent systemd services such as pcpcat-gost.service. The command-and-control infrastructure reportedly included 67.217.57.240 on ports 5656, 666, and 888. The exposed API supported functions such as GET /domains?client=<ID> for tasking and POST /result for exfiltration. FRP tunneling over port 888 enabled network pivoting, and honeypot observations also noted Docker API abuse on port 2375 for persistence. The activity maps in the provided content to MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) and T1552 (Unsecured Credentials). Key artifacts mentioned include files under /opt/pcpcat/, the marker ~/.pcpcat_installed, processes such as gost and frpc, and log strings including “UwU PCP Cat was here~”. Known alias in the provided content is PCPcat/pcp_cat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.