TeamPCP
MISPUnknown
Unknown
Unknown
[TeamPCP](https://attack.mitre.org/groups/G1056) is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, [TeamPCP](https://attack.mitre.org/groups/G1056) shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. [TeamPCP](https://attack.mitre.org/groups/G1056) has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.(Citation: Wiz TeamPCP Profile MAY 2026)(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Trend Micro TeamPCP MAY 2026)
Techniques Used (36)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1005 | Data from Local System | - |
| T1027.003 | Steganography | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1059.004 | Unix Shell | - |
| T1059.006 | Python | - |
| T1059.007 | JavaScript | - |
| T1059.013 | Container CLI/API | - |
| T1078 | Valid Accounts | - |
| T1078.004 | Cloud Accounts | - |
| T1098 | Account Manipulation | - |
| T1105 | Ingress Tool Transfer | - |
| T1176.002 | IDE Extensions | - |
| T1190 | Exploit Public-Facing Application | - |
| T1195.001 | Compromise Software Dependencies and Development Tools | - |
| T1485 | Data Destruction | - |
Aliases (1053)
Related Malware (3)
Metadata
| ID: | 1038 |
| Created: | 09/04/2026 16:00 |
| Updated: | 11/09/2026 04:00 |