Meta tags:
Headings (most frequently used words):
software, teampcp, cloud, stealer, associated, descriptions, techniques, used, groups, that, use, this, references, enterprise, layer,
Text of the page (most frequently used words):
teampcp (61), cloud (61), #stealer (55), enterprise (44), and (41), the (28), can (28), has (25), 2026 (21), for (21), credentials (20), data (18), files (12), discovery (12), att (11), all (11), july (11), file (10), github (9), from (9), exfiltration (9), use (8), software (8), retrieved (8), python (8), execution (8), over (7), 001 (7), march (6), supply (6), chain (6), used (6), container (6), system (6), information (6), extract (6), encrypted (6), create (6), collected (6), script (6), ics (5), mobile (5), none (5), compromised (5), that (5), keys (5), ability (5), paths (5), search (5), persistence (5), mitre (4), domains (4), techniques (4), access (4), trivy (4), actions (4), credential (4), name (4), unsecured (4), victim (4), hosts (4), shell (4), runners (4), identify (4), developer (4), using (4), runner (4), process (4), cryptocurrency (4), wallets (4), including (4), payloads (4), scripts (4), additional (4), exfiltrate (4), post (4), interpreter (4), command (4), version (4), groups (3), cti (3), defenses (3), threat (3), attack (3), action (3), kubernetes (3), 007 (3), 004 (3), history (3), 003 (3), across (3), environments (3), user (3), systems (3), network (3), memory (3), tokens (3), targeted (3), secrets (3), filesystem (3), encoded (3), download (3), encrypt (3), via (3), repository (3), stolen (3), code (3), service (3), channel (3), prior (3), curl (3), repositories (3), 006 (3), scripting (3), sudo (3), corporation (2), are (2), resources (2), reference (2), campaigns (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), group (2), unit (2), multi (2), stage (2), security (2), infrastructure (2), mccarthy (2), read (2), team (2), aqua (2), about (2), references (2), harvesting (2), api (2), searched (2), ssh (2), target (2), self (2), hosted (2), enumerate (2), configuration (2), machine (2), also (2), worker (2), plaintext (2), application (2), processes (2), proc (2), with (2), backdoor (2), named (2), resource (2), location (2), staged (2), hidden (2), directory (2), home (2), linux (2), such (2), compress (2), attacker (2), controlled (2), domain (2), method (2), fails (2), own (2), account (2), github_token (2), upload (2), web (2), scan (2), aquasecurtiy (2), org (2), before (2), minutes (2), pth (2), establish (2), startup (2), event (2), triggered (2), malicious (2), pre (2), install (2), within (2), package (2), json (2), payload (2), hybrid (2), rsa (2), 4096 (2), aes (2), 256 (2), encryption (2), cryptography (2), 002 (2), deobfuscate (2), leveraged (2), created (2), staging (2), multiple (2), cnf (2), sensitive (2), management (2), stores (2), harvest (2), keystores (2), systemd (2), get (2), engage (2), automated (2), tooling (2), archive (2), layer (2), sandclock (2), associated (2), s9041 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, fbi, cyber, criminal, google, intelligence, may, gtig, tracker, adversaries, leverage, vulnerability, exploitation, augmented, operations, initial, weaponizing, protectors, haughom, kics, strikes, again, sysdig, research, expands, compromise, spreads, checkmarx, april, update, ongoing, investigation, continued, remediation, ecosystem, temporarily, everything, you, need, know, latest, g1056, this, query, tls, private, check, stored, other, t1552, current, whoami, owner, t1033, webhook, urls, connecting, slack, discord, connections, t1049, interfaces, t1016, detected, checking, environmental, variable, github_actions, true, identified, readable, regions, enumerated, uname, hostname, t1082, steal, token, t1528, t1518, locate, t1057, scrape, reading, pid, mem, dumping, t1003, double, base64, evade, static, analysis, obfuscated, 013, t1027, installed, sysmon, match, legitimate, masquerading, 005, t1036, ingress, tool, transfer, t1105, remove, after, deletion, indicator, removal, t1070, folder, write, directories, hide, artifacts, t1564, filesystems, bitcoin, litecoin, dogecoin, zcash, dash, ripple, monero, financial, theft, t1657, containing, environment, variables, t1083, public, uploads, release, asset, fallback, channels, t1008, t1567, exfiltrated, typosquat, t1041, checked, running, rather, than, executing, polled, every, aborted, returned, value, contained, youtube, guardrails, t1480, due, automatic, processing, hooks, 018, inject, installer, packages, 016, t1546, asymmetric, symmetric, t1573, decode, t1140, will, sleep, five, delay, t1678, tmp, local, t1074, database, pgpass, mongorc, etc, mysql, databases, git, repos, t1213, aws, gcp, azure, identity, iam, ethereum, cardano, solana, validator, keypairs, ledger, device, anchor, deploy, password, t1555, execute, modify, t1543, docker, t1613, kubectl, administration, t1609, infected, victims, through, javascript, abused, entrypoint, setup, ast, unix, t1059, t1526, generic, t1580, attempts, repo, there, t1020, collect, enviornments, collection, t1119, bundled, into, tpcp, tar, utility, t1560, protocols, protocol, t1071, caching, abuse, elevation, control, mechanism, t1548, view, navigator, layers, description, descriptions, live, permalink, last, modified, containers, macos, saas, windows, platforms, malware, type, comprehensive, was, primary, during, early, stages, cascading, campaign, targeting, workflows, open, join, october, mclean, hotel, details, found, register, here, blog, contribute, benefactors, legal, branding, updates, tools, advisory, council, learn, more, started, detections,
Text of the page (random words):
teampcp cloud stealer software s9041 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software teampcp cloud stealer teampcp cloud stealer the teampcp cloud stealer is a comprehensive filesystem credential stealer that can harvest encrypt and exfiltrate credentials from over 50 sensitive file paths across ci cd cloud developer tooling and container environments the teampcp cloud stealer was the primary payload used by teampcp in march 2026 during early stages of a cascading supply chain campaign targeting ci cd workflows 1 2 3 4 5 6 7 8 id s9041 ⓘ associated software sandclock ⓘ type malware ⓘ platforms containers linux macos saas windows version 1 0 created 01 july 2026 last modified 31 july 2026 version permalink live version associated software descriptions name description sandclock 7 8 att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1548 003 abuse elevation control mechanism sudo and sudo caching teampcp cloud stealer can use sudo for code execution 3 enterprise t1071 001 application layer protocol web protocols teampcp cloud stealer has used curl to upload stolen data to attacker controlled domains 4 5 6 enterprise t1560 001 archive collected data archive via utility teampcp cloud stealer has bundled collected data into a file named tpcp tar gz for exfiltration 1 3 4 5 enterprise t1119 automated collection teampcp cloud stealer can identify and collect credentials across over 50 file paths in cloud ci cd developer tooling and container enviornments 1 3 enterprise t1020 automated exfiltration teampcp cloud stealer can compress and encrypt data and exfiltrate it via post to scan aquasecurtiy org if that method fails it attempts to use a stolen github_token to create a repo and exfiltrate the data there 1 enterprise t1580 cloud infrastructure discovery teampcp cloud stealer has the ability to search for generic github runners 5 enterprise t1526 cloud service discovery teampcp cloud stealer can search github for actions runner processes 3 2 1 5 enterprise t1059 004 command and scripting interpreter unix shell teampcp cloud stealer has abused the shell script files entrypoint sh in trivy action and setup sh in ast github action 2 3 28 for discovery and credential harvesting 4 6 006 command and scripting interpreter python teampcp cloud stealer has leveraged python scripts to download additional payloads engage in discovery and to establish persistence 1 3 5 5 6 007 command and scripting interpreter javascript teampcp cloud stealer has infected victims through malicious pre and post install scripts within the package json file 6 enterprise t1609 container administration command teampcp cloud stealer can use kubectl get secrets to extract credentials from kubernetes 3 enterprise t1613 container and resource discovery teampcp cloud stealer can identify docker and kubernetes environments for credentials 3 5 enterprise t1543 002 create or modify system process systemd service teampcp cloud stealer can create a systemd unit to execute a python script for persistence 1 3 5 enterprise t1555 credentials from password stores teampcp cloud stealer can harvest credentials from cryptocurrency wallets and keystores such as ethereum keystores cardano keys solana validator keypairs ledger device files and anchor deploy keys 2 3 8 006 cloud secrets management stores teampcp cloud stealer can enumerate multiple filesystem paths to extract credentials for aws gcp and azure including identity access management iam credentials 1 2 3 4 5 5 6 8 7 enterprise t1213 003 data from information repositories code repositories teampcp cloud stealer can target sensitive file paths in git repos to extract credentials 1 3 006 data from information repositories databases teampcp cloud stealer can extract credentials from multiple database configuration files including pgpass my cnf mongorc js and etc mysql my cnf 3 enterprise t1074 001 data staged local data staging teampcp cloud stealer has created a staging file in tmp for collected data 5 enterprise t1678 delay execution teampcp cloud stealer has leveraged a persistence script that will sleep for five minutes before additional execution 1 3 5 enterprise t1140 deobfuscate decode files or information teampcp cloud stealer can deobfuscate an encoded python script prior to execution 3 enterprise t1573 001 encrypted channel symmetric cryptography teampcp cloud stealer has encrypted collected data using a hybrid aes 256 and rsa 4096 encryption prior to exfiltration over curl 1 2 4 5 002 encrypted channel asymmetric cryptography teampcp cloud stealer has encrypted collected data using a hybrid rsa 4096 and aes 256 encryption prior to exfiltration over curl 1 2 4 5 enterprise t1546 016 event triggered execution installer packages teampcp cloud stealer can inject malicious pre or post install scripts within package json for payload execution 6 018 event triggered execution python startup hooks teampcp cloud stealer has used pth files to establish persistence on compromised hosts due to the python interpreter s automatic processing of pth files at startup 6 enterprise t1480 execution guardrails teampcp cloud stealer has checked if it is running on a developer machine rather than github actions before executing a python script for persistence the script has also polled c2 every 50 minutes for additional payloads and aborted if the returned value contained youtube 3 5 enterprise t1041 exfiltration over c2 channel teampcp cloud stealer has exfiltrated collected data to typosquat c2 domains including scan aquasecurtiy org 1 3 4 5 enterprise t1567 001 exfiltration over web service exfiltration to code repository teampcp cloud stealer can create a repository in the victim s github account using the victim s own github_token to upload stolen credentials 1 2 3 4 5 6 enterprise t1008 fallback channels teampcp cloud stealer can compress and encrypt data and exfiltrate it via post to an attacker controlled domain if that method fails it can use the victim s own github account to create a public repository and uploads the encrypted data as a release asset 1 2 3 5 6 enterprise t1083 file and directory discovery teampcp cloud stealer can identify files containing environment variables ssh keys cloud credentials access tokens and cryptocurrency wallets 1 2 3 5 enterprise t1657 financial theft teampcp cloud stealer can search filesystems for cryptocurrency wallets such as bitcoin litecoin dogecoin zcash dash ripple and monero 1 2 3 enterprise t1564 001 hide artifacts hidden files and directories teampcp cloud stealer can create a hidden directory in the user s home folder on linux hosts to write a python backdoor 5 enterprise t1070 004 indicator removal file deletion teampcp cloud stealer has the ability to remove all staged files after exfiltration 3 enterprise t1105 ingress tool transfer teampcp cloud stealer has the ability to download additional payloads to targeted systems 1 3 5 6 enterprise t1036 005 masquerading match legitimate resource name or location teampcp cloud stealer has installed a backdoor named sysmon py on targeted systems 5 enterprise t1027 013 obfuscated files or information encrypted encoded file teampcp cloud stealer has used multi stage payloads with double base64 encoded scripts to evade static analysis 1 2 6 enterprise t1003 007 os credential dumping proc filesystem teampcp cloud stealer can scrape memory from the runner worker process by reading proc pid mem to extract secrets including plaintext tokens 1 2 3 4 5 6 enterprise t1057 process discovery teampcp cloud stealer can locate github actions runner processes 3 1 2 5 enterprise t1518 software discovery teampcp cloud stealer has searched for cryptocurrency wallets on targeted hosts 1 2 enterprise t1528 steal application access token teampcp cloud stealer can read runner worker process memory to extract plaintext tokens 6 4 5 6 8 7 enterprise t1082 system information discovery teampcp cloud stealer has detected if it is on a developer machine by checking if the environmental variable github_actions true 1 teampcp cloud stealer has also identified readable memory regions on ci cd runners and enumerated system information using hostname and uname a 3 enterprise t1016 system network configuration discovery teampcp cloud stealer has the ability to enumerate network interfaces 1 3 enterprise t1049 system network connections discovery teampcp cloud stealer can search compromised systems for webhook urls connecting to slack and discord 4 enterprise t1033 system owner user discovery teampcp cloud stealer can use whoami on self hosted runners to identify the current user 3 enterprise t1552 001 unsecured credentials credentials in files teampcp cloud stealer has the ability to check over 50 file paths for credentials stored in files across ci cd cloud container and other environments 1 2 3 5 8 7 003 unsecured credentials shell history teampcp cloud stealer can target credentials in shell history on self hosted runners 3 004 unsecured credentials private keys teampcp cloud stealer has searched victim hosts for tls and ssh keys 1 2 3 5 007 unsecured credentials container api teampcp cloud stealer can query the kubernetes api for credentials 5 6 groups that use this software id name references g1056 teampcp teampcp has used teampcp cloud stealer in credential harvesting and exfiltration 1 2 3 4 5 6 references mccarthy r 2026 march 20 trivy compromised everything you need to know about the latest supply chain attack retrieved july 1 2026 aqua security 2026 march 21 trivy ecosystem supply chain temporarily compromised retrieved july 1 2026 aqua team 2026 april 1 update ongoing investigation and continued remediation retrieved july 1 2026 sysdig threat research team 2026 march 23 teampcp expands supply chain compromise spreads from trivy to checkmarx github actions retrieved july 1 2026 mccarthy r haughom j read b 2026 march 23 kics github action compromised teampcp strikes again in supply chain attack retrieved july 1 2026 unit 42 2026 march 31 weaponizing the protectors teampcp s multi stage supply chain attack on security infrastructure retrieved july 1 2026 google threat intelligence group 2026 may 11 gtig ai threat tracker adversaries leverage ai for vulnerability exploitation augmented operations and initial access retrieved july 7 2026 fbi 2026 july 2 cyber criminal group teampcp retrieved july 7 2026 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|