TeamPCP traced to Redis intrusions and later software supply-chain activity
Source headline: TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Intelligence Summary
A threat cluster tracked as TeamPCP has been linked to Redis-related compromises reaching back to 2020. The activity suggests the group spent years attacking internet-facing systems before shifting toward supply-chain targeting. Analysts cite overlaps in domains, malware delivery routes, and staging methods used across the campaigns. This indicates a persistent capability to compromise exposed services and then leverage follow-on access. Organizations using Redis or integrating third-party software should review exposure and ensure supply-chain controls are tightly enforced.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.