TeamPCP Cloud Stealer
MITREOther
Unknown
Unknown
The [TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The [TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) was the primary payload used by [TeamPCP](https://attack.mitre.org/groups/G1056) in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Google AI Threat Tracker MAY 2026)(Citation: FBI TeamPCP JUL 2026)
Tecniche Associate (47)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1003.007 | Proc Filesystem | - |
| T1008 | Fallback Channels | - |
| T1016 | System Network Configuration Discovery | - |
| T1020 | Automated Exfiltration | - |
| T1027.013 | Encrypted/Encoded File | - |
| T1033 | System Owner/User Discovery | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1041 | Exfiltration Over C2 Channel | - |
| T1049 | System Network Connections Discovery | - |
| T1057 | Process Discovery | - |
| T1059.004 | Unix Shell | - |
| T1059.006 | Python | - |
| T1059.007 | JavaScript | - |
| T1070.004 | File Deletion | - |
| T1071.001 | Web Protocols | - |
Alias (71)
Usato da Attori (1)
Metadata
| ID: | 327644 |
| Created: | 06/08/2026 04:00 |
| Updated: | 11/09/2026 04:00 |