Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupTeamPCP | TeamPCP has stolen source code from victim environments including Mistral AI. |
| T1027.003 Steganography |
GroupTeamPCP | TeamPCP has hidden malicious payloads in the frame data of WAV audio files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamPCP | TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads. |
| T1059.004 Unix Shell |
GroupTeamPCP | TeamPCP has leveraged malware capable of execution via the Linux CLI. |
| T1059.006 Python |
GroupTeamPCP | TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection. |
| T1059.007 JavaScript |
GroupTeamPCP | TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions. |
| T1059.013 Container CLI/API |
GroupTeamPCP | TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement. |
| T1078 Valid Accounts |
GroupTeamPCP | TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to. |
| T1078.004 Cloud Accounts |
GroupTeamPCP | TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines. |
| T1098 Account Manipulation |
GroupTeamPCP | TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public. |
| T1105 Ingress Tool Transfer |
GroupTeamPCP | TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2. |
| T1176.002 IDE Extensions |
GroupTeamPCP | TeamPCP has compromised VS Code and Open VSX IDE extensions. |
| T1190 Exploit Public-Facing Application |
GroupTeamPCP | TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints. |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupTeamPCP | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1485 Data Destruction |
GroupTeamPCP | TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts. |
| T1486 Data Encrypted for Impact |
GroupTeamPCP | TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums. |
| T1528 Steal Application Access Token |
GroupTeamPCP | TeamPCP has used malware to steal access tokens from targeted cloud and developer environments. |
| T1543.002 Systemd Service |
GroupTeamPCP | TeamPCP has used the systemd user service for malware persistence in targeted environments. |
| T1546.016 Installer Packages |
GroupTeamPCP | TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamPCP | TeamPCP has dropped malware into the Windows Startup folder to establish persistence. |
| T1550.001 Application Access Token |
GroupTeamPCP | TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments. |
| T1552.004 Private Keys |
GroupTeamPCP | TeamPCP has used malware to extract SSH and GPG keys from victim environments. |
| T1553.002 Code Signing |
GroupTeamPCP | TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing. |
| T1555.006 Cloud Secrets Management Stores |
GroupTeamPCP | TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure. |
| T1564.001 Hidden Files and Directories |
GroupTeamPCP | TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware. |
| T1583 Acquire Infrastructure |
GroupTeamPCP | In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests. |
| T1583.001 Domains |
GroupTeamPCP | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data. |
| T1583.004 Server |
GroupTeamPCP | TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982. |
| T1583.006 Web Services |
GroupTeamPCP | TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`. |
| T1585.001 Social Media Accounts |
GroupTeamPCP | TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications. |
| T1587.001 Malware |
GroupTeamPCP | TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud. |
| T1608.001 Upload Malware |
GroupTeamPCP | TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains. |
| T1657 Financial Theft |
GroupTeamPCP | TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1683.001 Written Content |
GroupTeamPCP | TeamPCP has created Dune-themed GitHub repositories using stolen tokens. |
| T1684.001 Impersonation |
GroupTeamPCP | TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.