CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 606

As cited

Copy frozen at (site build).

ransomware

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.

Why it matters: Cloud infrastructure teams and developers must audit exposed Docker, Kubernetes, and database services for credential theft and apply network restrictions immediately, as this active worm actively spreads across environments and is associated with significant supply chain attack activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.

Why it matters: Cloud infrastructure teams and developers must audit exposed Docker, Kubernetes, and database services for credential theft and apply network restrictions immediately, as this active worm actively spreads across environments and is associated with significant supply chain attack activity.

VendorsAmazon Web ServicesSlackMongoDBDockerKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary