EXPLORE
← Back to Actors

TeamPCP

TeamPCPPCPCatShellForceDeadCatx3SHADOW-WATER-058UNC6780

[TeamPCP](https://attack.mitre.org/groups/G1056) is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, [TeamPCP](https://attack.mitre.org/groups/G1056) shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. [TeamPCP](https://attack.mitre.org/groups/G1056) has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherF...

36
Techniques
30
Covered
6
Gaps
83%
Coverage
Coverage30/36