← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

TeamPCP Linked to Redis Attacks Since 2020 and Supply Chain Campaigns

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • TeamPCP activity traced back to 2020 Redis server attacks.
  • Overlapping domains, infrastructure, and techniques link past and present campaigns.
  • Group evolved from targeting internet-facing infrastructure to supply chain attacks.
  • Past campaigns include ShadowRay 2.0 and TA-NATALSTATUS.

Tracing TeamPCP's Origins

Oligo Security researchers Avi Lumelsky and Gal Elbaz have published an analysis connecting the threat actor TeamPCP to cybercrime activities as early as 2020. This predates the group's known focus on software supply chain compromises, indicating a longer operational history than previously understood. The connection is supported by shared domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft.

Early Campaigns and Evolution

The analysis identifies two campaigns from the second half of 2025, ShadowRay 2.0 (also known as IronErn), which involved hijacking AI infrastructure for a self-propagating botnet, and TA-NATALSTATUS, which targeted exposed Redis servers to deploy cryptocurrency miners. TA-NATALSTATUS is considered an evolution of a 2020 campaign detailed by Trend Micro that also targeted Redis servers. This suggests the threat actor actively targeted internet-accessible infrastructure across Ray, Docker, Redis, and React before adopting the TeamPCP moniker.

Transition to Supply Chain Attacks

TeamPCP was first identified late last year for exploiting security flaws in React Server Components (RSC) and Next.js to extract credentials and sensitive data in an operation codenamed PCPcat. Earlier this year, Flare detailed a campaign by the group targeting cloud-native environments to establish malicious infrastructure for data exfiltration, ransomware deployment, extortion, and cryptocurrency mining. The group has since moved into supply chain compromises, infecting developer systems by poisoning open-source libraries through GitHub Actions and token theft.

Operational Links

A strong operational link identified by Oligo is the overlap between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0 and TeamPCP's later infrastructure. Correlating GitLab authentication logs, command-and-control infrastructure, reverse-shell activity, and malware staging further establishes these connections.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

New analysis by Oligo Security researchers links the threat actor TeamPCP to Redis server compromises dating back to 2020, predating their known supply chain attacks. This connection is based on overlapping infrastructure, malware deployment, and operational techniques, indicating a long-standing presence in cybercrime before targeting software supply chains.