TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A notorious hacking group, TeamPCP, has been linked to a wave of attacks targeting Redis databases that began as far back as 2020. These campaigns have not only compromised sensitive data but also served as a springboard for more sophisticated supply chain attacks. The alarming revelation raises serious concerns about the persistence and adaptability of this threat actor.

At the heart of these attacks lies the exploitation of cross-domain privilege escalation vulnerabilities in Redis, an open-source in-memory data store widely used by web applications to manage user sessions and other sensitive information. By manipulating system permissions, attackers can gain access to privileged accounts and elevate their privileges within the Redis instance, creating a backdoor for further malicious activity.

According to security experts, TeamPCP’s Redis attacks were initially detected in 2020 but continued unabated until at least this year, with the group leveraging compromised Redis instances as stepping stones for more complex supply chain attacks. These latter campaigns have been characterized by the exploitation of vulnerabilities in third-party libraries and dependencies used by affected organizations. By targeting these vulnerable components, TeamPCP has been able to extend its reach into larger networks and compromise sensitive data.

The sophistication of TeamPCP’s tactics and techniques suggests a highly organized and motivated threat actor with significant resources at its disposal. The group’s ability to exploit Redis vulnerabilities across multiple domains further highlights the importance of patch management and robust security configurations in modern web applications.

In addition, the discovery of these attacks underscores the ongoing challenges posed by cross-domain privilege escalation vulnerabilities in cloud-based services. As more organizations transition their infrastructure to the cloud, they must remain vigilant against threats that can traverse domain boundaries and compromise sensitive data.

Practically speaking, this revelation serves as a stark reminder of the importance of maintaining up-to-date security configurations and patching systems in a timely manner. By prioritizing robust security controls and regularly reviewing system permissions, organizations can reduce their exposure to privilege escalation vulnerabilities and minimize the risk of these types of attacks.


Source: The Hacker News — 2026-08-07