Observed Signal · May 7, 2026 · Security Incident · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

Rival hackers evict TeamPCP, deploy worm 'PCPJack'

Executive Signal Summary

An unknown hacking group, tracked by SentinelOne as “PCPJack,” has been compromising systems previously breached by the cybercrime group TeamPCP. According to a SentinelOne report, the attackers break into TeamPCP‑compromised environments, remove TeamPCP’s tooling, evict its operators, then deploy self‑propagating code that steals credentials and exfiltrates data. The group appears focused on cloud infrastructure and also scans the public internet for exposed services such as Docker and MongoDB. SentinelOne researcher Alex Delamotte said the motives appear financial — stolen credentials are monetized via resale, initial‑access brokering, or direct extortion — and proposed theories including disgruntled ex‑TeamPCP members, rival operators, or imitators modeling TeamPCP’s tools. The campaign is notable for targeting previously compromised environments and using phishing domains (including password‑manager themed sites) and fake help‑desk pages as part of its activity.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Cloud‑focused credential‑theft campaigns and initial‑access brokerage increase systemic risk to enterprise cloud infrastructure and downstream supply chains; the tactic of evicting prior attackers and reusing compromised environments is an emergent threat pattern relevant to many organizations.

SIGNAL RADAR

Track SentinelOne Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • SentinelOne published a report describing a hacking campaign it calls “PCPJack.”
  • PCPJack targets systems previously compromised by the cybercriminal group TeamPCP, evicting TeamPCP operators and removing their tools.
  • After takeover, PCPJack deploys self‑spreading code across cloud infrastructure, steals credentials, and exfiltrates data back to its infrastructure.
  • Stolen credentials are monetized via resale, initial access brokering, or extortion; the group does not appear to install crypto‑mining software.
  • PCPJack also scans for exposed services (e.g., Docker, MongoDB) and uses phishing domains and fake help‑desk sites to harvest credentials.

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: May 7, 2026
Original Coverage Title: “Hackers hack victims hacked by other hackers”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Platform Security / Data BreachMay 20, 2026

Team‑PCP steals 3,800 internal GitHub repositories

The hacker group Team‑PCP accessed approximately 3,800 internal GitHub repositories between May 18 and May 19, 2026, and is attempting to sell the stolen data. GitHub confirmed the incident on X and said no customer data was affected. According to GitHub, attackers used a compromised employee device that had a malicious Visual Studio Code extension installed; the impacted endpoint was isolated and incident response measures were taken. Team‑PCP, previously linked to a March 2026 supply‑chain attack and said to collaborate with the Ransomware‑as‑a‑Service operator Vect, is offering the GitHub data for sale and reportedly coordinated with the LAPSUS$ group in later negotiations.

Read assessment
InfrastructureAug 27, 2026

Australian arrests alleged TeamPCP hackers in supply‑chain attacks

Australian Federal Police arrested two people in Perth accused of membership in TeamPCP, a hacking group blamed for widespread software supply‑chain attacks. The suspects face more than a dozen charges including hacking and money laundering; authorities say the group tampered with popular open‑source projects to deploy malicious code that stole credentials and data for extortion. The FBI estimates the intrusions impacted more than 1,000 organizations and that over half a million credentials were stolen. Investigations began in April 2026 after tips from cybersecurity firms. Independent reporter Brian Krebs has identified one alleged suspect as Ruben Thomson (handle “Ellis”), who told Krebs he led TeamPCP until March 2026. Australian officials said they seized devices and stolen data and plan to notify victims; extradition by the US Department of Justice is not yet clear.

Read assessment
InfrastructureJul 6, 2026

AI-Agent 'Jadepuffer' Runs Adaptive Ransomware

Security researchers at Sysdig uncovered a novel ransomware attacker dubbed “Jadepuffer” that appears to be controlled by an AI agent. The agent used natural-language-driven code and rapid iterative problem-solving — in one case completing an adaptation in 31 seconds — to place ransomware. It exploited a vulnerability in the open-source Langflow framework to harvest unencrypted cloud credentials and API keys, which enabled lateral movement and persistent tasks. Jadepuffer targeted MySQL servers running the Alibaba Nacos configuration service, creating admin accounts and encrypting 1,342 configuration files before deleting originals. The attacker generated a ransom table with a Bitcoin wallet and Proton‑Mail contact; analysts report the wallet moved roughly 46 BTC across about 73 transactions. Researchers warn AI agents lower the skill barrier for automated, adaptive cyberattacks against unpatched systems.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.