Full Report
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. "The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure,
Analysis Summary
# Threat Actor: TeamPCP
## Attribution & Identity
* **Primary Identifier:** TeamPCP
* **Aliases:** None explicitly stated in the provided text, though identified as a distinct cybercrime entity.
* **Identity:** A persistent threat group active since at least 2020, previously focused on infrastructure compromise before pivoting to supply chain attacks.
## Activity Summary
* **Historical Context:** Active for at least four years (starting in 2020) focusing on compromising internet-facing infrastructure.
* **Recent Campaigns:** The actor has recently transitioned into software supply chain attacks.
* **Connection Evidence:** Analysts linked current operations to historical activity through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure.
## Tactics, Techniques & Procedures
* **Software Supply Chain Compromise:** Training sights on the software development lifecycle to distribute malicious payloads.
* **Infrastructure Exploitation:** Exploiting internet-facing servers and infrastructure.
* **Staging Techniques:** Use of multi-stage deployment paths for malware.
* **Infrastructure Management:** Consistent use of specific backend infrastructure and naming conventions for domains.
## Targeting
* **Sectors:** Software development, IT infrastructure providers, and general internet-facing services.
* **Geography:** Global (implied by the nature of internet-facing infrastructure and supply chain targeting).
* **Victims:** Organizations with vulnerable internet-facing servers and users of compromised software supply chains.
## Tools & Infrastructure
* **Malware Families:** Specific malware names are not mentioned in the snippet, but the actor utilizes custom malware deployment paths.
* **Infrastructure:**
* **C2/Domains:** Overlapping domain infrastructure used across multiple years (specific defanged examples not provided in the source text).
* **Backend:** Shared backend server environments used for staging and command-and-control.
## Implications
* **Evolution of Maturity:** TeamPCP has demonstrated a significant evolution from opportunistic infrastructure exploitation to sophisticated, high-impact software supply chain attacks.
* **Persistence:** Their ability to operate for years without full discovery suggests high operational security (OPSEC) and a long-term strategic approach to cybercrime.
* **Risk Profile:** The pivot to supply chain attacks increases the risk of "one-to-many" compromises, where one successful breach by TeamPCP can lead to thousands of downstream victims.
## Mitigations
* **Supply Chain Security:** Implement Software Bill of Materials (SBOM) and rigorous integrity checks for all third-party software and libraries.
* **Vulnerability Management:** Prioritize patching of all internet-facing infrastructure to prevent initial access.
* **Egress Filtering:** Monitor and restrict outbound traffic from sensitive build environments to prevent communication with unauthorized C2 infrastructure.
* **Domain Monitoring:** Track and block communication with domains exhibiting naming conventions or registration patterns linked to TeamPCP backend infrastructure.