
In a surprising twist in the world of cybercrime, hackers have become victims of their own kind. An unidentified group has launched a campaign against systems already infiltrated by the notorious TeamPCP, a cybercrime organization making headlines for its recent high-profile breaches. According to a report from cybersecurity firm SentinelOne, the new attackers swiftly expelled TeamPCP members from compromised systems and dismantled their tools. This unprecedented move allowed the intruders to deploy malicious code designed to replicate itself across cloud infrastructures, akin to a self-replicating worm. Their activities involved stealing various credentials and transmitting the illicitly obtained data back to their servers. TeamPCP has garnered attention in recent weeks due to its involvement in significant security breaches, including an attack on the European Commission’s cloud resources and a widespread assault on the vulnerability scanning tool Trivvy, affecting numerous companies like LiteLLM and the AI recruiting startup Mercor. Alex Delamotte, a senior researcher at SentinelOne who discovered this new hacking initiative dubbed “PCPJack,” expressed uncertainty regarding the identity of the attackers. Delamotte proposed three potential scenarios: the hackers could be former TeamPCP members seeking revenge, part of a rival faction, or a third party mimicking TeamPCP’s tactics. Delamotte noted that the targeted services by PCPJack closely resemble TeamPCP’s earlier campaigns from December to January, prior to a notable shift in group membership. Interestingly, the PCPJack hackers are not only focused on TeamPCP’s targets; they are actively scanning for exposed services on the internet, including Docker virtual machine platforms and MongoDB databases. The report indicates that while PCPJack primarily targets TeamPCP, they are also keeping track of their hacking successes, sending data back to their infrastructure about the number of systems from which they successfully ousted TeamPCP. The motivations behind the PCPJack hackers appear to be financially driven, with a focus on credential theft for profit. They engage in various forms of monetization, including reselling stolen credentials, offering access to hacked systems, and extorting victims directly. Interestingly, they do not seem to engage in cryptocurrency mining on the compromised systems, likely due to the longer time frame required for such operations. Additionally, the hackers are employing deceptive tactics, such as creating domains that imply they are phishing for password manager credentials and setting up fake help desk websites, further complicating the cybersecurity landscape.
The landscape of money is transforming beyond just cash or bank balances, and TechCrunch Disrupt 2026 is set to spotligh...
TechCrunch | Jul 24, 2026, 22:40
For the past three years, Uber and Waymo, the autonomous vehicle division of Alphabet, have collaborated to provide driv...
CNBC | Jul 24, 2026, 21:55
It has been a challenging week for Elon Musk, as both Tesla and SpaceX experienced substantial stock declines. Tesla sha...
CNBC | Jul 24, 2026, 20:40
Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...
Business Today | Jul 25, 2026, 01:00
In a significant legal development, the U.S. Department of Justice has brought securities fraud charges against two engi...
TechCrunch | Jul 24, 2026, 20:30