Hackers swap roles: the new group PCPJack takes over infected networks.

Hackers swap roles: the new group PCPJack takes over infected networks.

55 software

New hacker group PCPJack “outruns” TeamPCP

*SentinelOne* discovered an unknown cybercriminal group that has already infiltrated systems previously infected by the TeamPCP gang and is pushing its members out. The new group – PCPJack – removes TeamPCP malware and installs its own tools for credential theft.

How PCPJack Works
1. Infiltration

Hackers enter already infected TeamPCP systems, where they deploy their own malicious payloads.

2. Spread

The malware spreads across victims’ cloud infrastructure like a network worm and steals credentials.

3. Data Exfiltration

Stolen information is sent to the attackers’ servers.

4. Target Tracking

PCPJack tools keep a counter of targets; as a result, they have already displaced TeamPCP members.

What Is Known About TeamPCP
TeamPCP attracted attention for a series of high‑profile attacks:

- breach of the European Commission’s cloud infrastructure,
- large‑scale attack on the popular vulnerability scanner Trivy that affected companies such as LiteLLM and the startup Mercor.

Who is Behind PCPJack?
Alex Delamotte (senior researcher, SentinelOne) has not identified the organizers yet. She offered three hypotheses:

1. disgruntled former TeamPCP members;
2. a competing group;
3. a third party that created its own tools based on TeamPCP’s model.

> “The services targeted by PCPJack largely overlap with the targets of December and January TeamPCP attacks, preceding the alleged roster change in February‑March,” Delamotte notes.

The group also scans the internet for open services (Docker, MongoDB), but its primary goal is to push competitors out of TeamPCP.

Financial Motivation
PCPJack’s goals are purely financial:

1. Resale of stolen credentials;
2. Selling access to compromised systems;
3. Direct extortion of victims.

Hackers do not use cryptocurrency mining – that strategy takes longer to yield profit, according to Delamotte. In some attacks they employ phishing domains and fake technical support sites.

Thus, PCPJack is an aggressive “dog” that not only seizes already infected TeamPCP systems but also actively seeks new cloud vulnerabilities to monetize stolen data.

Comments (0)

Share your thoughts — please be polite and stay on topic.

No comments yet. Leave a comment — share your opinion!

To leave a comment, please log in.

Log in to comment