Compute & Cloud
PCPJack hackers are targeting systems already compromised by TeamPCP
A new hacking campaign, PCPJack, is targeting systems already compromised by the cybercrime group TeamPCP, evicting the original attackers to steal credentials and monetize access.
An unknown group of hackers is targeting systems already compromised by TeamPCP, a prolific cybercrime group. According to a report by the cybersecurity firm SentinelOne, the attackers behind this new hacking campaign, dubbed PCPJack, are actively kicking out TeamPCP and removing their tools. Once they secure control of these compromised systems, the PCPJack hackers use their access to deploy code designed to replicate across cloud infrastructure.
The identity of the actors behind the PCPJack campaign remains unclear. Alex Delamotte, a senior researcher at SentinelOne, reported that the hackers’ goals appear to be purely financial, though who is running the campaign is unknown. Delamotte’s theories on the attackers’ identity range from disgruntled former members of TeamPCP to rival cybercrime groups. The campaign has targeted high-profile entities, including the European Commission, as well as various tech firms like LiteLLM and Mercor. These organizations were previously affected by TeamPCP’s breaches, which included a cyberattack against Trivvy, a vulnerability scanner—a tool used to find security weaknesses. Delamotte noted that the PCPJack campaign closely mirrors earlier activity. “The services targeted by PCPJack strongly resemble the December-January TeamPCP campaigns, before the alleged change in group membership that happened in February-March,” Delamotte said. Beyond targeting TeamPCP’s victims, the hackers also scan the internet for exposed services, including the virtual machine cloud platform Docker and databases running MongoDB.
Rather than installing software to mine cryptocurrency—which they likely avoid because it requires more time to yield financial returns—the hackers are focusing on credential theft. They operate as initial access brokers, which are hackers who break into systems and sell access to other buyers. To gather these credentials, the hackers are using domains that suggest they are phishing for password manager credentials and deploying fake help desk websites to monetize their access.
Why it matters
This incident highlights a shift in cybercrime where attackers are increasingly competing for control over compromised infrastructure, turning victims into battlegrounds for rival hacking groups.