Worm-driven TeamPCP campaign compromises cloud native infrastructure at scale

by

A worm-driven campaign attributed to TeamPCP targeted cloud native environments worldwide around December 25, 2025 and used exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers and a critical React flaw to build large proxy and scanning infrastructure.

KEY FACTS

  • Incident Worm-driven campaign to set up malicious cloud infrastructure around Dec 25, 2025
  • Actor TeamPCP, also known as DeadCatx3, PCPcat and ShellForce, with a Telegram channel over 700 members
  • Vectors Exposed Docker APIs, Kubernetes APIs, Ray dashboards, Redis and vulnerable React/Next.js apps (CVE-2025-55182)
  • Payloads Proxy and scanning tools, credential harvesting, persistent privileged pods and cryptocurrency mining

A technical analysis by Flare said the operation built a distributed proxy and scanning infrastructure to enable data theft, extortion, ransomware deployment and cryptocurrency mining.

The campaign automated exploitation of misconfigurations and known vulnerabilities to industrialize propagation. Compromised hosts receive next stage shell and Python scripts that install tunneling utilities and continuous scanners for additional targets.

Core components include a script named proxy.sh that performs environment fingerprinting and branches when it detects a Kubernetes cluster to deploy cluster specific payloads. Other tools include scanners and Kubernetes routines to harvest credentials and deploy privileged pods to mount host resources.

One scanner downloads CIDR lists from the DeadCatx3 GitHub account and seeks exposed Docker APIs and Ray dashboards. Identified control infrastructure includes an IP address 67.217.57.240 associated with an open source C2 framework.

WHY IT MATTERS

The campaign shows how common cloud misconfigurations and known vulnerabilities can be combined to convert exposed infrastructure into a self-propagating criminal ecosystem that yields multiple revenue streams for operators.