The cybercriminal group responsible for the supply chain attacks on open-source developer tools in March has been linked to a series of infrastructure attacks dating back to 2020. Additionally, they have been connected to the creation of the first known self-propagating botnet built from hijacked AI infrastructure.
Recent research conducted by Oligo Security on August 5 revealed that the group known as TeamPCP shares domains, malware deployment paths, and backend infrastructure with activity previously attributed to TA-NATALSTATUS between 2020 and August 2025. Working in collaboration with Mandiant and GitLab, Oligo Security was able to identify and ban the accounts associated with the malicious activities.
One of the key findings of the investigation was the reuse of a deployment framework by TeamPCP for several years. The infrastructure link was traced back to a domain named masscan[.]cloud, which featured prominently in TA-NATALSTATUS activity, ShadowRay 2.0 campaign, and subsequent TeamPCP operations. The consistent use of a distinctive directory path and staging scripts across these campaigns provided further evidence of the group’s continuity.
Further evidence linking TeamPCP to their past activities was discovered through GitLab records. An IP address that received reverse shells from a compromised Ray cluster during a specific timeframe was later found to be associated with the ironern440 account, which authenticated to GitLab from the same address. This IP address hosted the campaign’s tooling, further solidifying the connection between the different operations.
The evolution of TeamPCP’s tactics over the years was also documented by Oligo Security. Starting with exploits on internet-facing infrastructure in 2020, the group progressed to abuse GitHub Actions, token theft, and eventually targeted attacks on specific software like React2Shell and Docker APIs. The malicious activities also expanded to include credential phishing, payment fraud, and impersonation of legitimate services like Zendesk.
In a particularly concerning development, a destructive branch was added to a second-stage Kubernetes payload deployed by TeamPCP in late March. This script targeted systems set to the Iran timezone, executing a destructive workload that deleted filesystems and rebooted the machine. The disruption in Iranian connectivity at the time limited visibility into the impact of this destructive payload.
While the exact nature of the relationship between TeamPCP and previous malicious actors remains unclear, the evidence suggests that TeamPCP is not a new group that emerged in late 2025 but rather a continuation of an existing operational ecosystem. The thorough investigation conducted by Oligo Security sheds light on the sophisticated tactics employed by these cybercriminals and underscores the importance of ongoing vigilance in cybersecurity efforts.
