TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign — Ravie LakshmananAug 07, 2026Cybercrime / Vulnerability [https://blogge
What’s new: TeamPCP, a threat actor linked to various cybercrime activities since 2020, has been identified as responsible for attacks targeting Redis servers and other internet-facing infrastructure. Recent campaigns include ShadowRay 2.0, which hijacked AI infrastructure, and TA-NATALSTATUS, which deployed cryptocurrency miners on exposed Redis servers. The group has evolved to conduct software supply chain attacks, exploiting vulnerabilities in React, Docker, and Kubernetes.
Who’s affected
Organizations using Redis, Docker, React, and Kubernetes are at risk, particularly those with exposed internet-facing services. Developers relying on popular open-source libraries may also be impacted due to supply chain compromises.
What to do
- Audit and secure Redis, Docker, and Kubernetes deployments to ensure they are not exposed to the internet.
- Implement strict access controls and monitoring for cloud-native environments.
- Regularly update software dependencies and libraries to mitigate vulnerabilities.
- Review and enhance incident response plans to address potential supply chain attacks.



