TA-NATALSTATUS is a financially motivated intrusion activity cluster active from at least 2020 through August 2025. It targeted exposed Redis servers and other internet-facing infrastructure through automated exploitation, deploying cryptocurrency-mining payloads on compromised systems. The activity reused a distinctive malware-staging and backend infrastructure framework over multiple campaigns. It has substantial operational overlap with activity later identified as TeamPCP and with the ShadowRay 2.0/IronErn campaign, including shared staging patterns, infrastructure, and post-compromise tradecraft. Available evidence supports continuity or close collaboration within this operational ecosystem, but does not conclusively establish that TA-NATALSTATUS, TeamPCP, and IronErn are identical operators. ShadowRay 2.0 compromised exposed Ray clusters to construct a self-propagating botnet; later TeamPCP-linked activity expanded into cloud-infrastructure exploitation and software supply-chain compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A defender-tracked activity cluster targeting exposed internet-facing services. The report assesses it as operationally continuous with, closely affiliated with, or sharing infrastructure with TeamPCP, although it cannot establish a direct rebrand with complete certainty.
Campaign assessed as part of the same operational ecosystem, targeting exposed Redis servers to deploy cryptocurrency miners and described as an evolution of an earlier Redis-focused malware campaign.
Earlier tracked activity cluster linked by shared domains, deployment paths, and backend infrastructure to TeamPCP operations dating back to 2020.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.