ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1056×

36 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupTeamPCP

TeamPCP has stolen source code from victim environments including Mistral AI.

T1027.003
Steganography
GroupTeamPCP

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamPCP

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.

T1059.004
Unix Shell
GroupTeamPCP

TeamPCP has leveraged malware capable of execution via the Linux CLI.

T1059.006
Python
GroupTeamPCP

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.

T1059.007
JavaScript
GroupTeamPCP

TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.

T1059.013
Container CLI/API
GroupTeamPCP

TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement.

T1078
Valid Accounts
GroupTeamPCP

TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.

T1078.004
Cloud Accounts
GroupTeamPCP

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.

T1098
Account Manipulation
GroupTeamPCP

TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.

T1105
Ingress Tool Transfer
GroupTeamPCP

TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.

T1176.002
IDE Extensions
GroupTeamPCP

TeamPCP has compromised VS Code and Open VSX IDE extensions.

T1190
Exploit Public-Facing Application
GroupTeamPCP

TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.

T1195.001
Compromise Software Dependencies and Development Tools
GroupTeamPCP

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

T1485
Data Destruction
GroupTeamPCP

TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.

T1486
Data Encrypted for Impact
GroupTeamPCP

TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums.

T1528
Steal Application Access Token
GroupTeamPCP

TeamPCP has used malware to steal access tokens from targeted cloud and developer environments.

T1543.002
Systemd Service
GroupTeamPCP

TeamPCP has used the systemd user service for malware persistence in targeted environments.

T1546.016
Installer Packages
GroupTeamPCP

TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamPCP

TeamPCP has dropped malware into the Windows Startup folder to establish persistence.

T1550.001
Application Access Token
GroupTeamPCP

TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments.

T1552.004
Private Keys
GroupTeamPCP

TeamPCP has used malware to extract SSH and GPG keys from victim environments.

T1553.002
Code Signing
GroupTeamPCP

TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing.

T1555.006
Cloud Secrets Management Stores
GroupTeamPCP

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.

T1564.001
Hidden Files and Directories
GroupTeamPCP

TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.

T1583
Acquire Infrastructure
GroupTeamPCP

In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.

T1583.001
Domains
GroupTeamPCP

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data.

T1583.004
Server
GroupTeamPCP

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.

T1583.006
Web Services
GroupTeamPCP

TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via  *.getsession[.]org to recipient  ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`.

T1585.001
Social Media Accounts
GroupTeamPCP

TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications.

T1587.001
Malware
GroupTeamPCP

TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud.

T1608.001
Upload Malware
GroupTeamPCP

TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.

T1657
Financial Theft
GroupTeamPCP

TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware.

T1677
Poisoned Pipeline Execution
GroupTeamPCP

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.

T1683.001
Written Content
GroupTeamPCP

TeamPCP has created Dune-themed GitHub repositories using stolen tokens.

T1684.001
Impersonation
GroupTeamPCP

TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.