← Back to news

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

SentinelOne Labs07/05/2026, 10:00
Read full article →

Summary

AI-Generated

Key Points:

  • PCPJack is a credential theft framework that targets exposed cloud infrastructure, specifically designed to evict artifacts associated with the TeamPCP threat actor group while harvesting credentials from various services.
  • The impact includes significant data exposure and potential financial fraud, affecting systems like Docker, Kubernetes, MongoDB, and Redis. The toolset facilitates lateral movement and external propagation within victim environments.
  • Recommended actions include implementing strict credential management practices, enforcing multi-factor authentication (MFA), and ensuring the use of IMDSv2 in AWS environments to prevent unauthorized access.

Technical Details: PCPJack exploits vulnerabilities such as CVE-2025-29927 (Next.js auth bypass) and CVE-2025-55182 (React deserialization) to propagate across networks. It utilizes Telegram for command and control (C2) communication.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1190 - Exploit Public-Facing Application (Initial Access)
  • T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
  • T1021.001 - Remote Services: Remote Desktop Protocol (Lateral Movement)

IOCs Mentioned:

  • Domains: cdn[.]cloudfront-js[.]com, lastpass-login-help[.]com
  • IP Addresses: 161.97.129[.]25, 161.97.135[.]154, 161.97.163[.]87, 161.97.186[.]175, 161.97.187[.]42, 193.187.129[.]143, 213.136.80[.]73, 38.242.204[.]245, 38.242.237[.]196, 38.242.245[.]147, 83.171.249[.]231
  • File Hashes: SHA-1 hashes for various components including update.bin and bootstrap.sh

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.