← Back to blog

TeamPCP's Long Game: Redis Attacks and Supply Chain Intrusions Revealed

Threat actor TeamPCP has been active since at least 2020, targeting internet-facing systems before shifting focus to software supply chains. New research links years of Redis-based attacks to this group through shared infrastructure and tactics.

TL;DR

  • TeamPCP has been active since 2020, initially targeting Redis servers
  • The group later expanded to software supply chain attacks
  • Analysis connects campaigns via shared domains, malware paths, and staging methods
  • Targets include exposed infrastructure and development pipelines
  • Organizations should review Redis configurations and supply chain dependencies

Cybersecurity researchers have uncovered evidence that the threat group known as TeamPCP has been operating since at least 2020, with a focus on compromising internet-facing infrastructure. Initially concentrating on Redis server vulnerabilities, the group has evolved its tactics to target software supply chains in more recent campaigns.

The connection between these various attack waves is supported by consistent use of overlapping domains, similar malware deployment strategies, and matching staging techniques. This suggests a coordinated effort by TeamPCP to maintain persistent access while expanding their operational scope over several years.

Redis Attack Patterns

  • Initial campaigns targeted misconfigured Redis instances exposed to the internet
  • Attackers used common exploitation techniques to gain unauthorized access to database systems
  • Compromised Redis servers were used for data exfiltration and establishing backdoor access
  • Infrastructure analysis revealed consistent command and control patterns across multiple incidents

Supply Chain Evolution

  • Later operations shifted toward compromising software development and distribution pipelines
  • Similar malware delivery mechanisms were identified in both attack phases
  • Shared backend infrastructure and domain registration patterns link the campaigns
  • The evolution suggests increasing sophistication and strategic targeting of higher-value assets

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

TeamPCP's Long Game: Redis Attacks and Supply Chain Intrusions Revealed — Agent Breach Blog | Agent Breach