ATT&CKReferencesFBI TeamPCP JUL 2026

FBI TeamPCP JUL 2026

FBI. (2026, July 2). Cyber Criminal Group TeamPCP. Retrieved July 7, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1195.001
Compromise Software Dependencies and Development Tools
GroupTeamPCP

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

T1528
Steal Application Access Token
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens.

T1528
Steal Application Access Token
MalwareCanisterWorm

CanisterWorm has gathered cloud access tokens.

T1528
Steal Application Access Token
GroupTeamPCP

TeamPCP has used malware to steal access tokens from targeted cloud and developer environments.

T1552.001
Credentials In Files
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments.

T1552.004
Private Keys
GroupTeamPCP

TeamPCP has used malware to extract SSH and GPG keys from victim environments.

T1555
Credentials from Password Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys.

T1555.006
Cloud Secrets Management Stores
MalwareCanisterWorm

CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.

T1555.006
Cloud Secrets Management Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials.

T1555.006
Cloud Secrets Management Stores
GroupTeamPCP

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.

T1583.001
Domains
GroupTeamPCP

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data.

T1583.004
Server
GroupTeamPCP

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.

T1657
Financial Theft
GroupTeamPCP

TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware.

T1677
Poisoned Pipeline Execution
GroupTeamPCP

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.