As cited
Copy frozen at (site build).
threat intel
Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild
TeamPCP is using credentials and secrets stolen from recent supply chain attacks to gain unauthorized access to cloud environments. The group is exploiting these compromised credentials post-breach to establish persistence and lateral movement within cloud infrastructure.
Why it matters: Cloud infrastructure teams and incident responders need to understand how supply chain compromises create downstream cloud threats: you should audit cloud access logs for suspicious activities from recently affected vendors and review credential rotation policies.
- Source published
- First seen by Cybersecurity Tracker