Oligo Security found that TeamPCP has been active since 2020, linking it to multiple campaigns using the same infrastructure and aliases like TA-NATALSTATUS and IronErn. The group’s rapid, AI-assisted attacks have targeted open-source software and AI infrastructure, including a ShadowRay exploitation campaign that helped create a self-propagating botnet. #TeamPCP #TA-NATALSTATUS #IronErn #ShadowRay
Keypoints
- TeamPCP activity dates back to 2020, not just this year.
- Oligo Security linked the group to TA-NATALSTATUS and IronErn.
- The same IPs, domains, and servers tied multiple TeamPCP campaigns together.
- A ShadowRay exploitation campaign led to a self-propagating botnet on hijacked AI infrastructure.
- TeamPCP used AI to rapidly adapt payloads and scale attacks across open-source software.
Read More: https://cyberscoop.com/teampcp-long-active-history-2020-oligo-security/