Security researchers reported multiple malware operations abusing exposed cloud services and misconfigurations to seize control of Kubernetes and containerized environments. FortiGuard Labs said the P2PInfect botnet compromised Google Kubernetes Engine clusters by targeting internet-exposed Redis instances, abusing replication through the SLAVEOF command and, in some cases, leveraging CVE-2022-0543 for remote code execution. The Rust-based malware uses a decentralized peer-to-peer architecture, non-standard ports, and long-lived dormant infections that can persist for months, creating a foothold for later delivery of ransomware, cryptominers, or other payloads.
Separate reporting tied the activity to a broader rise in cloud-focused criminal operations that exploit known flaws and weak configurations rather than zero-days. Cyble profiled TeamPCP as a large-scale actor targeting Docker APIs, Kubernetes components, Ray dashboards, and Redis to convert victim infrastructure into proxy, command-and-control, ransomware, and Monero mining nodes. Researchers also described a newer framework, PCPJack, that appears to piggyback on already compromised cloud environments by wiping TeamPCP artifacts, stealing secrets from AWS, Docker, Kubernetes, GitHub, Slack, Office 365, and other services, and exfiltrating encrypted data to Telegram while spreading worm-like across exposed Docker, Kubernetes, Redis, MongoDB, and RayML services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A follow-up report said P2PInfect operators appeared to be running a botnet-for-hire model and had expanded beyond Redis misconfigurations to exploit the Metro4Shell vulnerability, with low-confidence speculation about possible RediShell use. The findings reinforced concerns that access obtained through the botnet could be sold to other criminals for ransomware or cryptomining deployment.
Researchers disclosed a new malware framework called PCPJack that targets exposed cloud environments, steals a wide range of credentials and secrets, and removes evidence of prior TeamPCP infections before taking over compromised systems. PCPJack was described as worm-like, spreading through exposed Docker, Kubernetes, Redis, MongoDB, and RayML services and exfiltrating encrypted data to Telegram.
Fortinet's FortiGuard Labs publicly reported that P2PInfect had expanded from earlier Redis-focused activity into Kubernetes environments, warning that compromised nodes could later be used for ransomware or cryptomining. The report also noted the botnet's decentralized peer-to-peer architecture and recommended reducing Redis exposure, tightening Kubernetes controls, and improving runtime monitoring.
Cyble published a threat actor profile describing TeamPCP's cloud-native intrusion methods, tooling, and monetization, and said the campaign had affected organizations across multiple countries and sectors, especially BFSI, consumer goods, and professional services. The profile emphasized opportunistic targeting of cloud-reliant environments and use of tools such as FRP, GO Simple Tunnel, Sliver, and XMRig.
FortiGuard Labs reported that at least one P2PInfect intrusion inside a GKE cluster remained active for roughly six months, showing the botnet's ability to maintain long-term access in enterprise cloud environments. The malware stayed largely dormant after enrollment, reducing the chance of detection while preserving access for later monetization.
From November 2025 through February 2026, FortiGuard Labs observed P2PInfect intrusions in Google Kubernetes Engine environments at several companies. Attackers abused internet-exposed Redis instances, including misconfigured replication via the SLAVEOF command and CVE-2022-0543, to gain code execution and enroll hosts into the botnet.
TeamPCP, also tracked as DeadCatx3, PCPcat, PersyPCP, and ShellForce, emerged in late 2025 as a cloud-focused threat actor exploiting exposed cloud infrastructure and common misconfigurations at scale. The group targeted services such as Docker APIs, Kubernetes components, Ray dashboards, and Redis, then repurposed compromised systems for proxying, scanning, command-and-control, ransomware, and Monero mining.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecysecurity.news
Open sourcecybersecuritynews.com
Open sourcefortinet.com
Open sourcefeeds.fortinet.com
Open sourcecyble.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.