TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A Highly Skilled Threat Actor Group Has Been Linked to a Series of Redis Attacks, Starting in 2020 and Continuing Through Supply Chain Campaigns, Exposing Thousands of Organizations to Identity-Based Breach Routes.

The team behind TeamPCP, a sophisticated threat actor group known for its advanced attack tactics and techniques, has been quietly exploiting vulnerabilities in Redis, an open-source in-memory data store used by thousands of organizations worldwide. According to recent research, TeamPCP’s activities date back to 2020, with the group continually updating its arsenal to evade detection and maximize impact.

TeamPCP’s modus operandi involves targeting Redis instances through cross-domain privilege escalation attacks. This technique allows attackers to map breach routes across multiple domains, essentially turning a single vulnerability into a catastrophic security failure. By exploiting vulnerabilities in the Redis configuration or using social engineering tactics to gain administrative access, TeamPCP can then leverage its knowledge of Redis’s internal workings to create backdoors and establish permanent footholds within compromised networks.

The sheer scale of TeamPCP’s activities is staggering. Researchers have identified thousands of organizations that have been affected by the group’s attacks since 2020, with many more likely remaining unknown. The breadth of targets suggests a sophisticated supply chain campaign, where TeamPCP has used stolen credentials and exploited vulnerabilities to gain access to sensitive environments. This approach allows the group to move laterally within networks, using Redis as a hub to pivot between compromised systems.

The implications of these attacks are far-reaching. With thousands of organizations relying on Redis for data storage and processing, the potential damage is immense. Moreover, the fact that TeamPCP has been operating undetected for so long raises serious questions about the effectiveness of current security measures and the need for more proactive threat hunting strategies.

As the cybersecurity landscape continues to evolve, one thing is clear: organizations must remain vigilant against the ever-changing tactics employed by sophisticated threat actor groups like TeamPCP. To mitigate the risk of Redis-based attacks, administrators should prioritize regular vulnerability scanning, implement robust access controls, and maintain a strong security posture that includes ongoing monitoring and incident response planning.

In conclusion, the discovery of TeamPCP’s long-running campaign highlights the importance of proactive security measures in today’s threat-rich environment. By staying informed about emerging threats and taking steps to fortify their defenses, organizations can reduce the likelihood of falling victim to sophisticated attacks like those orchestrated by TeamPCP.


Source: The Hacker News — 2026-08-07