FBI. (2026, July 2). Cyber Criminal Group TeamPCP. Retrieved July 7, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupTeamPCP | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1528 Steal Application Access Token |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens. |
| T1528 Steal Application Access Token |
MalwareCanisterWorm | CanisterWorm has gathered cloud access tokens. |
| T1528 Steal Application Access Token |
GroupTeamPCP | TeamPCP has used malware to steal access tokens from targeted cloud and developer environments. |
| T1552.001 Credentials In Files |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments. |
| T1552.004 Private Keys |
GroupTeamPCP | TeamPCP has used malware to extract SSH and GPG keys from victim environments. |
| T1555 Credentials from Password Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys. |
| T1555.006 Cloud Secrets Management Stores |
MalwareCanisterWorm | CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. |
| T1555.006 Cloud Secrets Management Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials. |
| T1555.006 Cloud Secrets Management Stores |
GroupTeamPCP | TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure. |
| T1583.001 Domains |
GroupTeamPCP | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data. |
| T1583.004 Server |
GroupTeamPCP | TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982. |
| T1657 Financial Theft |
GroupTeamPCP | TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.