Research · curated 7 Aug 2026
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
First reported oligo.security
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
TeamPCP represents an actor that has evolved from exploiting internet-facing infrastructure to weaponizing AI compute clusters and open-source AI supply chains, giving defenders a documented operational lineage and fresh IoCs to hunt.
Oligo Security published new intelligence linking the threat actor TeamPCP (aka IronErn) to the ShadowRay 2.0 campaign — the first known attack hijacking AI infrastructure (exposed Ray clusters) into a self-propagating botnet — and traced the group's activity back to 2020 through overlapping domains, malware staging, C2 infrastructure, and TTPs. The report also connects TeamPCP to Redis-targeting activity attributed to TA-NATALSTATUS and to supply-chain compromises of projects including Trivy, Checkmarx, and BerriAI/LiteLLM via GitHub Actions abuse and token theft.