As cited
Copy frozen at (site build).
ransomware
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.
Why it matters: Cloud infrastructure teams and developers must audit exposed Docker, Kubernetes, and database services for credential theft and apply network restrictions immediately, as this active worm actively spreads across environments and is associated with significant supply chain attack activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.
Why it matters: Cloud infrastructure teams and developers must audit exposed Docker, Kubernetes, and database services for credential theft and apply network restrictions immediately, as this active worm actively spreads across environments and is associated with significant supply chain attack activity.
- Source published
- First seen by Cybersecurity Tracker