Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

6060da100b5cd587131a1c11a20d6e0108604744

TLP:CLEAR
Active

SHA-1 Hash

Description

PCPJack is a sophisticated credential theft framework that propagates across exposed cloud infrastructure while systematically removing artifacts linked to TeamPCP, a threat actor behind notable 2026 supply chain compromises. The toolset harvests credentials from cloud platforms, containers, developer tools, productivity applications, and financial services, exfiltrating data through attacker-controlled infrastructure. It targets exposed Docker, Kubernetes, Redis, MongoDB, RayML services and vulnerable web applications, enabling external propagation and lateral movement. Unlike typical cloud malware, PCPJack deploys no cryptominers, focusing instead on credential theft for monetization through fraud, spam campaigns, extortion, or access resale. The framework uses modular Python scripts orchestrated by a central component, employs Common Crawl data for target selection, and utilizes Telegram for command and control communications.

Sightings (0)

No sightings recorded yet

Details

Name / Label
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
Pattern Type
STIX
Confidence
75%
Valid From
May 10, 2026 05:43
Total Sightings
0
Added
May 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 6060da100b5cd587131a1c11a20d6e0108604744

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.