The recent findings from Oligo Security reveal that the group responsible for a series of significant supply chain attacks on open-source development tools earlier this year is linked to a history of cyberattacks going back to 2020. This group, known as TeamPCP, has amassed a reputation for leveraging hijacked artificial intelligence infrastructure to create a self-propagating botnet, the first of its kind.
In a research report published on August 5, Oligo Security articulated how TeamPCP shares various domains and malware deployment routes with past activities tracked under the label TA-NATALSTATUS from 2020 through August 2025. This connection adds layers to the understanding of the cyber threat landscape, illustrating how seemingly disparate attacks may be part of a more extensive, interconnected network of malicious activities.
Collaboration efforts among Oligo Security, Mandiant, and GitLab were instrumental in uncovering these connections. As a result of their investigation, GitLab took action by banning the accounts associated with the attackers. This joint effort between cybersecurity firms highlights the importance of cooperative strategies in addressing the ever-evolving threats faced by the tech community.
Further scrutiny by Oligo indicates that TeamPCP orchestrated the ShadowRay 2.0 campaign—an initiative documented in November 2025 that specifically targeted exposed Ray clusters. Initially credited to an actor identified as IronErn440, this relationship emphasizes the fluidity and adaptability present within cybercriminal methodologies.
Oligo’s findings suggest a persistent reuse of deployment frameworks that have been in place for years, marking a strategic continuity in TeamPCP’s operations. Notably, they identified masscan[.]cloud as a recurring infrastructure element seen across both TA-NATALSTATUS activities and TeamPCP operations. This domain, supposedly recognized in certificate transparency records as early as May 11, 2025, was eventually listed as the official website of TeamPCP on their GitHub account. This points to a well-established infrastructure that supports the group’s cyber operations and strategies.
In a particularly alarming revelation, a compromised Ray cluster was found to have logged a malicious download stemming from this same infrastructure on July 26, 2025, which occurred five months prior to the public emergence of TeamPCP. The connection was further solidified by an incident with GitLab, where an IP address received reverse shells from a compromised Ray cluster between October 15 and November 2. Following this, the ironern440 account authenticated to GitLab from the same IP address that hosted the campaign’s tools, reinforcing the linkage between past and present activities.
To understand the evolution of TeamPCP’s tactics, Oligo outlined a timeline that indicates these operators began exploiting vulnerable internet-connected infrastructures as early as 2020, employing automated and wormable techniques. Their activities escalated from cryptojacking to extensive exploitation through abuses of GitHub Actions and token theft. This trajectory reached a peak with the PCPcat campaign during Christmas 2025, which targeted React2Shell vulnerabilities and exploited exposed Docker APIs.
Moreover, the group’s infrastructure expanded beyond mere exploitation, revealing additional avenues such as credential phishing, payment fraud, and impersonation of services like Zendesk. In a chilling shift in tactics, Oligo documented that, by late March, a second-stage Kubernetes payload acquired a destructive component. This particular script was designed to check whether the victim’s system was configured to Iran’s timezone. If it was, the script would deploy a destructive workload capable of wiping filesystems and rebooting the machine—a worrying indication that specific targets are being singled out based on geographic and political factors.
As Oligo delved deeper, they exercised caution regarding how far their attribution could extend. They acknowledged that the continuity seen in operations could stem from a direct rebrand, a shared set of operators, or close collaboration among various malicious entities. Ultimately, their research suggests that TeamPCP is not a new player on the cyber battlefield, but rather a continuation of an existing operational ecosystem that has adapted and evolved over the years, posing ongoing threats within the digital landscape.
This intricate web of cybercrime highlights the necessity for ongoing vigilance, cooperation, and innovation within the cybersecurity community. As technology evolves, so too must the strategies employed to safeguard systems against entrenched and emerging threats.
