By Interestana AI Editorial — AI-drafted, human-overseen. How we report
TeamPCP Linked to Redis Attacks Dating Back to 2020 and Later Supply Chain Campaign

A recent analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. This connection is supported by overlapping domains, malware deployment paths, staging techniques, and backend infrastructure utilized by the group across its various campaigns. The findings suggest TeamPCP has been a persistent threat actor for at least four years, demonstrating a notable evolution in its tactics, techniques, and procedures (TTPs) over time.
Initially, TeamPCP's operations appeared to center on exploiting vulnerabilities in internet-facing systems. These systems, often exposed to the public internet, are prime targets for attackers seeking to gain unauthorized access. The likely objectives during this phase would have been data exfiltration, establishing persistent access for future operations, or leveraging compromised resources for other malicious activities. The shift towards supply chain attacks represents a significant escalation in their modus operandi. Supply chain attacks are particularly insidious because they can have a far wider and more devastating impact than direct attacks on individual organizations. By compromising a trusted software vendor or a widely used development tool, attackers can infect numerous downstream organizations that rely on that software. This strategy allows attackers to reach a large number of potential victims indirectly, often bypassing traditional perimeter defenses.
The analysis highlights the sophisticated and adaptive nature of TeamPCP, indicating a well-resourced and organized threat group. The consistent use of overlapping infrastructure and techniques across different attack campaigns suggests a deliberate strategy to maintain operational security, enhance efficiency, and evade detection by cybersecurity defenses. The longevity of their activity, spanning multiple years, underscores the persistent challenges faced by security professionals in identifying, tracking, and mitigating advanced persistent threats (APTs) like TeamPCP.
While the specific motivations behind TeamPCP's attacks remain under investigation, the targeting of both internet-facing infrastructure and the software supply chain suggests potential goals such as financial gain through ransomware or data theft, espionage by state-sponsored actors, or large-scale disruption of critical services. The group's demonstrated ability to maintain operations for an extended period and adapt its attack vectors points to a significant and evolving threat to organizations that rely heavily on internet-connected systems and third-party software. The findings serve as a critical reminder for businesses to continuously strengthen their defenses against sophisticated and evolving cyber threats. This includes implementing robust monitoring of network traffic, conducting regular vulnerability assessments, and diligently managing supply chain risks by vetting vendors and scrutinizing software updates.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.