Technology News

TeamPCP Linked to Redis Attacks Since 2020, Expands to Supply Chain Campaign

A recent analysis traces the threat actor known as TeamPCP back to 2020, revealing a long history of targeting internet‑facing systems before shifting focus to software supply chains.

A new analysis has traced the threat actor known as TeamPCP back to at least 2020, indicating a long history of compromising internet‑facing infrastructure.

Early activity focused on exploiting misconfigured Redis instances to exfiltrate data, a technique that remains in use across the group’s campaigns.

Researchers highlighted that the same domains, malware deployment paths, and staging techniques appear in recent supply‑chain incidents, pointing to a single operator or tightly coordinated team.

Overlapping backend infrastructure further supports the connection between the two phases of the threat actor’s operations.

TeamPCP’s shift toward the software supply chain began in late 2021, with attackers targeting build systems and package repositories.

The analysis identified a pattern of injecting malicious code into legitimate build artifacts, allowing the group to compromise downstream customers.

This transition illustrates a broader trend of cybercriminals moving from opportunistic infrastructure attacks to more targeted supply‑chain exploitation.

Security teams should review their build pipelines and third‑party dependencies for signs of tampering, especially when using public registries.

The findings underscore the importance of monitoring misconfigured services, such as unsecured Redis instances, which can serve as a foothold for later supply‑chain attacks.

Ongoing analysis will continue to map TeamPCP’s activity and provide actionable guidance for defenders.

TeamPCP Linked to Redis Attacks Since 2020, Expands to Supply Chain Campaign

A new analysis has traced the threat actor known as TeamPCP back to at l…

A new analysis has traced the threat actor known as TeamPCP back to at l…

A new analysis has traced the threat actor known as TeamPCP back to at least 2020, indicating a long history of compromising internet‑facing infrastructure.

Early activity focused on exploiting misconfigured Redis instances to exfiltrate data, a technique that remains in use across the group’s campaigns.

Researchers highlighted that the same domains, malware deployment paths,…

Researchers highlighted that the same domains, malware deployment paths,…

Researchers highlighted that the same domains, malware deployment paths, and staging techniques appear in recent supply‑chain incidents, pointing to a single operator or tightly coordinated team.

Overlapping backend infrastructure further supports the connection between the two phases of the threat actor’s operations.

TeamPCP’s shift toward the software supply chain began in late 2021, wit…

TeamPCP’s shift toward the software supply chain began in late 2021, wit…

TeamPCP’s shift toward the software supply chain began in late 2021, with attackers targeting build systems and package repositories.

The analysis identified a pattern of injecting malicious code into legitimate build artifacts, allowing the group to compromise downstream customers.

This transition illustrates a broader trend of cybercriminals moving fro…

This transition illustrates a broader trend of cybercriminals moving fro…

This transition illustrates a broader trend of cybercriminals moving from opportunistic infrastructure attacks to more targeted supply‑chain exploitation.

Security teams should review their build pipelines and third‑party dependencies for signs of tampering, especially when using public registries.

The findings underscore the importance of monitoring misconfigured servi…

The findings underscore the importance of monitoring misconfigured servi…

The findings underscore the importance of monitoring misconfigured services, such as unsecured Redis instances, which can serve as a foothold for later supply‑chain attacks.

Ongoing analysis will continue to map TeamPCP’s activity and provide actionable guidance for defenders.