TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Summary
A recent analysis indicates that the threat actor known as TeamPCP has been involved in cybercrime since at least 2020, initially focusing on compromising internet-facing infrastructure. More recently, the group has shifted its attention to targeting the software supply chain, with overlapping domains, malware deployment paths, and infrastructure supporting this connection.
IFF Assessment
TeamPCP's long-term activity and targeting of infrastructure and supply chains represent a significant threat to defenders.
Defender Context
This analysis highlights the persistent threat posed by TeamPCP, emphasizing the need for robust defenses against both direct infrastructure compromises and sophisticated supply chain attacks. Defenders should remain vigilant for indicators of compromise related to TeamPCP's TTPs and prioritize securing internet-facing services and software development pipelines.