← Back to Actors
TeamPCP
TeamPCPPCPCatShellForceDeadCatx3SHADOW-WATER-058UNC6780
[TeamPCP](https://attack.mitre.org/groups/G1056) is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, [TeamPCP](https://attack.mitre.org/groups/G1056) shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. [TeamPCP](https://attack.mitre.org/groups/G1056) has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherF...
36
Techniques
30
Covered
6
Gaps
83%
Coverage
Coverage30/36
GAPS (6)
COVERED (30)
T1005Data from Local System51 det.T1027.003Steganography5 det.T1036.005Match Legitimate Resource Name or Location45 det.T1059.004Unix Shell169 det.T1059.006Python53 det.T1059.007JavaScript64 det.T1059.013Container CLI/API1 det.T1078Valid Accounts306 det.T1078.004Cloud Accounts188 det.T1098Account Manipulation245 det.T1105Ingress Tool Transfer191 det.T1190Exploit Public-Facing Application233 det.T1195.001Compromise Software Dependencies and Development Tools8 det.T1485Data Destruction97 det.T1486Data Encrypted for Impact394 det.T1528Steal Application Access Token53 det.T1543.002Systemd Service13 det.T1546.016Installer Packages9 det.T1547.001Registry Run Keys / Startup Folder53 det.T1550.001Application Access Token43 det.T1552.004Private Keys23 det.T1553.002Code Signing4 det.T1555.006Cloud Secrets Management Stores8 det.T1564.001Hidden Files and Directories25 det.T1583Acquire Infrastructure2 det.T1583.001Domains68 det.T1583.006Web Services1 det.T1587.001Malware10 det.T1608.001Upload Malware3 det.T1657Financial Theft15 det.