Threat Intelligence

Hacking Group 'TeamPCP' Has Been Quietly Attacking Servers Since 2020, Researchers Find

The Hacker News · 7 Aug 2026
Key Takeaway Regularly audit any internet-facing systems and software dependencies for exposure, since attackers often use small, unnoticed compromises as stepping stones to larger supply chain attacks.

New research has revealed that a cybercrime group known as TeamPCP has been active far longer than previously believed, with evidence tying it to attacks on internet-facing systems dating back to 2020. The group initially targeted poorly secured Redis database servers exposed to the internet, using these compromises to build out infrastructure for later campaigns.

Researchers connected the earlier Redis attacks to a more recent and concerning development: TeamPCP's involvement in a software supply chain campaign. This shift suggests the group evolved from opportunistic server compromises to more sophisticated attacks that could affect software used by many downstream businesses. The link was established through overlapping domains, similar malware deployment methods, matching staging techniques, and shared backend infrastructure used across both waves of activity.

For Australian small businesses, this case is a reminder that threat actors often start small — exploiting misconfigured or exposed systems — before graduating to attacks with wider impact, such as compromising software vendors that many businesses rely on. Even if your business doesn't run Redis directly, the software you use may depend on components affected by such supply chain intrusions.

supply chain security Redis threat actor infrastructure security cyber threat intelligence
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.