Quick Summary
The Securityish Brief
Cybersecurity researchers have recently highlighted a large-scale operation by the threat actor TeamPCP, which has been active since at least November 2025. This group has been exploiting cloud-native environments, particularly targeting misconfigured Docker APIs, Kubernetes clusters, and the React2Shell vulnerability (CVE-2025-55182, CVSS score: 10.0). The campaign was first observed around December 25, 2025, and has been linked to a Telegram channel with over 700 members, where stolen data from victims in Canada, Serbia, South Korea, the U.A.E., and the U.S. is published.
TeamPCP’s operations focus on building a distributed proxy and scanning infrastructure to compromise servers for data exfiltration, ransomware deployment, and cryptocurrency mining. The group employs established attack techniques, utilizing known vulnerabilities and misconfigurations to automate the exploitation process, creating a self-propagating criminal ecosystem. Their activities have been described as opportunistic, primarily targeting cloud infrastructures like Amazon Web Services (AWS) and Microsoft Azure.
Understanding TeamPCP’s Techniques
The exploitation methods used by TeamPCP include deploying various payloads such as:
- scanner.py, which finds misconfigured Docker APIs and Ray dashboards while offering options to run a cryptocurrency miner.
- kube.py, which harvests Kubernetes credentials and deploys a backdoor on accessible pods.
- react.py, which exploits the React flaw (CVE-2025-29927) for remote command execution.
- pcpcat.py, which discovers exposed Docker APIs and deploys malicious containers across large IP ranges.
These payloads are designed to enhance the group’s ability to infiltrate and exploit cloud environments effectively. The C2 server linked to TeamPCP has also been associated with the Sliver framework, indicating a sophisticated level of operation.
The implications of TeamPCP’s activities are significant, as they demonstrate a complete lifecycle of cybercrime that includes scanning, exploitation, persistence, and monetization. This hybrid model not only allows for data theft but also enables the group to generate multiple revenue streams, making them a persistent threat to organizations operating cloud infrastructure.
Key Takeaways
- Regularly audit your cloud configurations, especially Docker and Kubernetes settings, to prevent exploitation.
- Implement strict access controls and monitoring for APIs to limit unauthorized access.
- Stay informed about vulnerabilities like CVE-2025-55182 and apply patches promptly.
- Consider using security tools that can detect and mitigate threats targeting cloud environments.
- Educate your team on recognizing signs of data exfiltration and ransomware attacks.
Key Terms & Concepts
- TeamPCP: In this article, TeamPCP refers to a threat actor group known for exploiting cloud infrastructure for cybercrime.
- CVE-2025-55182: CVE-2025-55182 is a vulnerability in React that allows for remote command execution and has a CVSS score of 10.0.
- Docker API: The Docker API is an interface that allows users to interact with Docker containers and manage their lifecycle.
- Kubernetes: Kubernetes is an open-source platform for automating the deployment, scaling, and management of containerized applications.
- C2 server: A C2 server, or command-and-control server, is used by attackers to maintain communication with compromised systems.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.