TeamPCP has stolen source code from victim environments including Mistral AI.7
group
TeamPCP G1056
- Created
- 16 July 2026
- Last modified
- 31 July 2026
- Aliases
- TeamPCP · PCPCat · ShellForce · DeadCatx3 · SHADOW-WATER-058 · UNC6780
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.[1][2][3][4][5][6]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1056
TeamPCP has hidden malicious payloads in the frame data of WAV audio files.89
TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits.10 TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.1112
TeamPCP has leveraged malware capable of execution via the Linux CLI.13
TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.14151614
TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.1819
Standing G1056
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
73rd percentile · 73% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
73rd percentile · 73% of 176 ATT&CK groups have this many tactics spanned or fewer.
47th percentile · 53% of 176 ATT&CK groups have more tools and malware.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
11th percentile · 89% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G1056
913 distinct rules cover the 36 techniques recorded for this group. The 954 technique-to-rule mappings resolve to 913 distinct rules, because one rule can cover several techniques. 587 Sigma · 326 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org