SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

TeamPCP

❔ UnknownLast active: 2026-08-12First seen: 2026-07-16G1056
0
linked CVEs
Also known as
Altered SpiderPCPcatShellForceDeadCatx3CanisterWormSHADOW-WATER-058UNC6780
Targeted industries
Technology
TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and LiteLLM to deploy credential-stealing malware. They employed techniques like credential harvesting, lateral movement within Kubernetes environments, and audio steganography to evade detection. The group has demonstrated the ability to leverage stolen credentials to propagate attacks across multiple ecosystems, including npm and PyPI, using a self-propagating worm known as CanisterWorm. Their operations have included the use of AES-256 encryption and RSA-4096 for exfiltration of sensitive data.
Source: misp_galaxy · Collected: 2026-08-12
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used36 techniques
Across 12 tactics
Execution5 techniques
Initial Access4 techniques
Persistence7 techniques
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to by…
T1078.004Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and con…
T1098Account Manipulation
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised acc…
T1176.002IDE Extensions
Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems.(Citation: Mnemonic misuse visual studio) IDEs such as Visual Studio Code,…
T1543.002Systemd Service
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon…
T1546.016Installer Packages
Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content. Installer packages are OS specific and contain the resources an operat…
T1547.001Registry Run Keys / Startup Folder
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause th…
Privilege Escalation6 techniques
Resource Development8 techniques
T1583Acquire Infrastructure
Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure…
T1583.001Domains
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquir…
T1583.004Server
Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise ac…
T1583.006Web Services
Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later sta…
T1585.001Social Media Accounts
Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be used to build a persona to further operations. Pe…
T1587.001Malware
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoor…
T1608.001Upload Malware
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, b…
T1683.001Written Content
Adversaries may create or tailor written materials to support targeting and malicious operations. Content may include phishing lures, fraudulent financial communications, fabricated job postings, fabr…
Stealth6 techniques
🛰️ Infrastructure & IOCs13
sha2569fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc2026-08-12
md54140f7e17e6f97f83aa3472473e01add2026-08-12
domainnpm-cache.com2026-08-12
sha256fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb2026-08-12
md57bcf8d9f6834c44450eac145a967d2f22026-08-12
domaincopilot-instructions.md2026-08-12
sha135a672cf34b996b91f3e1c28cbf3a05a37e036e42026-08-12
domainawqhnjewqjkl.icu2026-08-12
sha1f525d52ceb966516686b482d3dc0137028cc6a632026-08-12
urlhttps://npm-cache.com:443/router2026-08-12
md5f92ee93a0af971a3966bfa8efa9c26252026-08-11
sha1e65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c2026-08-11
sha25654dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b3506682026-08-11