Aqua Team. (2026, April 1). Update: Ongoing Investigation and Continued Remediation. Retrieved July 1, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.007 Proc Filesystem |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens. |
| T1008 Fallback Channels |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset. |
| T1016 System Network Configuration Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to enumerate network interfaces. |
| T1033 System Owner/User Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamPCP | TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads. |
| T1041 Exfiltration Over C2 Channel |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org. |
| T1057 Process Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can locate GitHub Actions runner processes. |
| T1059.006 Python |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence. |
| T1070.004 File Deletion |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration. |
| T1078.004 Cloud Accounts |
GroupTeamPCP | TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines. |
| T1082 System Information Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`. |
| T1083 File and Directory Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify files containing environment variables, SSH keys, cloud credentials, access tokens, and cryptocurrency wallets. |
| T1098 Account Manipulation |
GroupTeamPCP | TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public. |
| T1105 Ingress Tool Transfer |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems. |
| T1119 Automated Collection |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify and collect credentials across over 50 file paths in Cloud, CI/CD, developer tooling, and container enviornments. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution. |
| T1190 Exploit Public-Facing Application |
GroupTeamPCP | TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints. |
| T1213.003 Code Repositories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials. |
| T1213.006 Databases |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf. |
| T1480 Execution Guardrails |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube. |
| T1526 Cloud Service Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search GitHub for Actions runner processes. |
| T1528 Steal Application Access Token |
GroupTeamPCP | TeamPCP has used malware to steal access tokens from targeted cloud and developer environments. |
| T1543.002 Systemd Service |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a systemd unit to execute a python script for persistence. |
| T1548.003 Sudo and Sudo Caching |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `sudo` for code execution. |
| T1552.001 Credentials In Files |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments. |
| T1552.003 Shell History |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners. |
| T1552.004 Private Keys |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys. |
| T1555 Credentials from Password Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys. |
| T1555.006 Cloud Secrets Management Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials. |
| T1560.001 Archive via Utility |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration. |
| T1567.001 Exfiltration to Code Repository |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials. |
| T1583.001 Domains |
GroupTeamPCP | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data. |
| T1583.006 Web Services |
GroupTeamPCP | TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`. |
| T1609 Container Administration Command |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes. |
| T1613 Container and Resource Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials. |
| T1657 Financial Theft |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1678 Delay Execution |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution. |
| T1684.001 Impersonation |
GroupTeamPCP | TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.