PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
SentinelLABS has uncovered PCPJack, a sophisticated cloud worm and credential theft framework that actively evicts tools from the TeamPCP threat actor group before establishing its own foothold. The framework spreads across exposed Docker, Kubernetes, Redis, MongoDB, and RayML services by exploiting multiple high-severity CVEs (including Next.js auth bypass and React Server Actions deserialization). It harvests credentials from dozens of financial, messaging, cloud, and enterprise services, encrypts them with X25519/ChaCha20-Poly1305, and exfiltrates via Telegram C2. Unlike typical cloud malware, PCPJack deploys no cryptominers — suggesting monetization through fraud, spam, extortion, or credential resale. A second toolset on the same server deploys Sliver C2 beacons compiled with garble obfuscation, targeting additional services including OpenAI, Anthropic, and HashiCorp Vault keys. Mitigations include enforcing IMDSv2, requiring MFA for service accounts, using enterprise secret vaults, and restricting Docker/Kubernetes management API access.