Hackers swap roles: the new group PCPJack takes over infected networks.
New hacker group PCPJack “outruns” TeamPCP
*SentinelOne* discovered an unknown cybercriminal group that has already infiltrated systems previously infected by the TeamPCP gang and is pushing its members out. The new group – PCPJack – removes TeamPCP malware and installs its own tools for credential theft.
How PCPJack Works
1. Infiltration
Hackers enter already infected TeamPCP systems, where they deploy their own malicious payloads.
2. Spread
The malware spreads across victims’ cloud infrastructure like a network worm and steals credentials.
3. Data Exfiltration
Stolen information is sent to the attackers’ servers.
4. Target Tracking
PCPJack tools keep a counter of targets; as a result, they have already displaced TeamPCP members.
What Is Known About TeamPCP
TeamPCP attracted attention for a series of high‑profile attacks:
- breach of the European Commission’s cloud infrastructure,
- large‑scale attack on the popular vulnerability scanner Trivy that affected companies such as LiteLLM and the startup Mercor.
Who is Behind PCPJack?
Alex Delamotte (senior researcher, SentinelOne) has not identified the organizers yet. She offered three hypotheses:
1. disgruntled former TeamPCP members;
2. a competing group;
3. a third party that created its own tools based on TeamPCP’s model.
> “The services targeted by PCPJack largely overlap with the targets of December and January TeamPCP attacks, preceding the alleged roster change in February‑March,” Delamotte notes.
The group also scans the internet for open services (Docker, MongoDB), but its primary goal is to push competitors out of TeamPCP.
Financial Motivation
PCPJack’s goals are purely financial:
1. Resale of stolen credentials;
2. Selling access to compromised systems;
3. Direct extortion of victims.
Hackers do not use cryptocurrency mining – that strategy takes longer to yield profit, according to Delamotte. In some attacks they employ phishing domains and fake technical support sites.
Thus, PCPJack is an aggressive “dog” that not only seizes already infected TeamPCP systems but also actively seeks new cloud vulnerabilities to monetize stolen data.
Comments (0)
Share your thoughts — please be polite and stay on topic.
Log in to comment