TeamPCP is an Australia-based, financially motivated cybercriminal group associated with large-scale software supply-chain compromise, cloud-service exploitation, credential theft, data exfiltration, and cryptocurrency mining. Australian authorities allege that two Western Australian members participated in operations affecting more than 1,000 organizations worldwide and enabling theft of over 500,000 credentials and at least 300 GB of data. The group is known by aliases including DeadCatx3, PCPcat, Persy_PCP, ShellForce, and UNC6780. TeamPCP initially conducted opportunistic exploitation of exposed cloud and application services, including container-management interfaces, Kubernetes environments, Ray clusters, Redis services, and vulnerable web applications. It deployed containers for scanning, proxying, and Monero mining, and conducted ransomware and data-extortion activity. It later expanded into software supply-chain operations, compromising trusted development and security tooling and abusing CI/CD environments to distribute credential-stealing malware. The group has been linked to the Shai-Hulud worm and supply-chain compromises involving Trivy and LiteLLM. Its supply-chain tradecraft harvests source-control, package-registry, cloud, Kubernetes, CI/CD, SSH, and other development credentials from compromised developer workstations and build runners. Stolen publishing credentials and valid accounts are then used to alter repositories or publish malicious package releases, creating self-propagating downstream compromise. TeamPCP has also used Python package-installation mechanisms for persistence, including path-configuration execution, and has deployed Kubernetes workloads for propagation and persistence. Reported TeamPCP activity includes broad scanning and exploitation of internet-facing services, credential and session theft, command-and-control-based exfiltration, resource hijacking, persistence, and defense evasion. Available reporting identifies operational overlap with activity tracked as TA-NATALSTATUS and IronErn, but does not conclusively establish that these designations represent identical operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
The chain that reached the widest set of victims ran through Trivy into LiteLLM... The ecosystem flaw is tracked as CVE-2026-33634 and was added to CISA’s Known Exploited Vulnerabilities catalog on 26 March 2026.
During February, the group expanded its exploitation to include CVE-2025-29927 and CVE-2025-55182. In December 2025, TeamPCP's PCPcat operation targeted React2Shell-vulnerable applications and exposed Docker APIs with ransomware.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
During February, masscan[.]cloud again resolved to 44.252.85.168 and 67.217.57.240. During this period, the group expanded its exploitation to include CVE-2025-29927 and CVE-2025-55182, targeting a broad range of internet-facing technologies including AWS, Anyscale’s Ray, Docker, Kubernetes, Linux, Meta React, Microsoft Azure, Redis, and Vercel Next.js.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
601 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group associated with earlier software supply-chain attacks and opportunistic operations involving exposed-service scanning, container deployment, cryptocurrency mining, and theft of credentials from build-pipeline and software-development environments.
Alleged cybercriminal group whose operations involved creating and distributing open-source malware to compromise organizations and steal data. The reported impact includes more than 1,000 organizations compromised globally, over 500,000 credentials stolen, and at least 300 GB of data exfiltrated.
Mentioned solely as unconfirmed contextual background; the content does not attribute Trinitite to TeamPCP or describe TeamPCP activity in this incident.
Mentioned only as unconfirmed contextual background to the Trinitite/Mini Shai-Hulud npm supply-chain incident; the activity is not conclusively attributed to TeamPCP.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.