Oligo Security researchers Avi Lumelsky and Gal Elbaz have published an analysis connecting the threat actor TeamPCP to cybercrime activities as early as 2020. This predates the group's known focus on software supply chain compromises, indicating a longer operational history than previously understood. The connection is supported by shared domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft.
The analysis identifies two campaigns from the second half of 2025, ShadowRay 2.0 (also known as IronErn), which involved hijacking AI infrastructure for a self-propagating botnet, and TA-NATALSTATUS, which targeted exposed Redis servers to deploy cryptocurrency miners. TA-NATALSTATUS is considered an evolution of a 2020 campaign detailed by Trend Micro that also targeted Redis servers. This suggests the threat actor actively targeted internet-accessible infrastructure across Ray, Docker, Redis, and React before adopting the TeamPCP moniker.
TeamPCP was first identified late last year for exploiting security flaws in React Server Components (RSC) and Next.js to extract credentials and sensitive data in an operation codenamed PCPcat. Earlier this year, Flare detailed a campaign by the group targeting cloud-native environments to establish malicious infrastructure for data exfiltration, ransomware deployment, extortion, and cryptocurrency mining. The group has since moved into supply chain compromises, infecting developer systems by poisoning open-source libraries through GitHub Actions and token theft.
A strong operational link identified by Oligo is the overlap between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0 and TeamPCP's later infrastructure. Correlating GitLab authentication logs, command-and-control infrastructure, reverse-shell activity, and malware staging further establishes these connections.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
New analysis by Oligo Security researchers links the threat actor TeamPCP to Redis server compromises dating back to 2020, predating their known supply chain attacks. This connection is based on overlapping infrastructure, malware deployment, and operational techniques, indicating a long-standing presence in cybercrime before targeting software supply chains.