Atlas360
Technology

Cloud Credentials Under Attack: New Malware Seizes Access, Expels Rivals

A new malware framework, PCPJack, is stealing cloud credentials and actively removing rival TeamPCP infections from compromised systems.

Jason Kwon
Cloud Credentials Under Attack: New Malware Seizes Access, Expels Rivals

A new malware framework, PCPJack, is actively stealing credentials from exposed cloud infrastructure. This framework simultaneously removes the presence of TeamPCP, a known cloud-focused threat group, from compromised systems.

The targeted services include Docker, Kubernetes, Redis, MongoDB, RayML, and vulnerable web applications.

PCPJack infects Linux-based cloud systems via a shell script, establishing persistence and launching an orchestrator. During initial execution, it specifically identifies and deletes TeamPCP processes, services, containers, files, and persistence artifacts.

The malware's primary function is credential thesources, targeting cloud environments, developer systems, messaging applications, financial services, and databases. Exfiltrated credentials are encrypted and transmitted to Telegram channels.

Propagation occurs through scanning external cloud infrastructure for exposed services and exploiting known vulnerabilities. These vulnerabilities include CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, and CVE-2025-48703.

Lateral movement within compromised environments is achieved by harvesting SSH keys and credentials, enumerating clusters, and executing on internal hosts.

Mitigation recommendations include enforcing multi-factor authentication, utilizing IMDSv2 in AWS, ensuring proper authentication for Docker and Kubernetes, adhering to least-privilege principles, and avoiding plaintext storage of secrets.

More stories

Latest news