← All Threat Actors
Threat Actor Profile

TeamPCP

Altered Spider CipherForce DeadCatx3 PCPcat Persy_PCP ShellForce storm_2999 UNC6780
⚠ Critical Threat
Shai-Hulud / Mini Shai-Hulud, Trivy/LiteLLM Cascade, Grafana Labs GitHub Breach
Origin Russia/CIS
Sponsor criminal organization
Motivation financial (extortion, ransomware, and sale of exfiltrated intellectual property)

Target Sectors

Software Development Ecosystems (npm, PyPI, Docker Hub, Packagist) AI/ML Tooling (e.g., LiteLLM, Mistral AI, Guardrails AI) Cybersecurity Tooling (e.g., Trivy, Checkmarx) Cloud-Native Infrastructure (Kubernetes, Docker APIs, Ray dashboards, Redis) CI/CD Pipelines and GitHub Repositories

Known TTPs

Self-propagating supply chain worms (Shai-Hulud/Mini Shai-Hulud)
OIDC token extraction from GitHub Actions runner memory to forge SLSA provenance
GitHub Actions cache poisoning
Abuse of exposed cloud-native APIs (Docker, Ray, Redis)
IDE extension abuse (VS Code extensions) for credential theft
Credential stealing via SANDCLOCK and FIRESCALE malware
Partnership with Ransomware-as-a-Service (RaaS) operators (Vect)
Git tag manipulation and workflow injection
AI-driven payload generation and prompt injection to evade scanners

External Resources

CISA Advisories ↗

LINK COPIED TO CLIPBOARD