RESEARCH from Oligo Security has linked the hacking group TeamPCP to a cryptojacking operation initiated in 2020, showcasing a continuum of malicious cyber activities, including recent supply chain attacks on open-source developer tools. The group shares infrastructure and malware paths with a previously tracked entity known as TA-NATALSTATUS.
Key findings include indications of mass exploitation of internet resources, evolution into more sophisticated attacks involving GitHub and Kubernetes, plus an alarming transition to destructive strategies targeting specific regional infrastructure during times of heightened geopolitical tension. The investigation involved collaboration with Mandiant and GitLab, which has since banned related accounts. Oligo suggests that TeamPCP represents a longstanding operational framework rather than a new threat actor.