Cybersecurity researchers have identified a “massive campaign” (TeamPCP) that systematically targets cloud native environments to create malicious infrastructure for subsequent exploitation. The activity, observed around December 25, 2025 and described as “worm-driven,” exploited exposed Docker APIs, Kubernetes clusters, Ray dashboards , and Redis servers, along with the recently disclosed React2Shell vulnerability (CVE-2025-55182, CVSS score: 10.0).
See also: Shai-Hulud & Co.: The software supply chain as a weakness

The campaign has been attributed to a threat group known as TeamPCP (also known as DeadCatx3, PCPcat, PersyPCP, and ShellForce).
TeamPCP has been active since at least November 2025, with the first activity on Telegram dating back to July 30, 2025.The TeamPCP Telegram channel currently has over 700 members, where the group posts stolen data from various victims in Canada, Serbia, South Korea, the UAE, and the U.S. Details of the threat actor were first documented by Beelzebub in December 2025 under the name Operation PCPcat.
“ The objectives of the operation were to create a distributed proxy and scanning infrastructure at scale, then compromise servers for data extraction, ransomware deployment, extortion, and cryptocurrency mining ,” Flare security researcher Assaf Morag said in a report published last week.
TeamPCP operates as a cloud-native cybercrime platform, exploiting poorly configured Docker APIs, Kubernetes APIs, Ray dashboards, Redis servers, and vulnerable React/Next.js as primary infection routes to compromise modern cloud infrastructure and facilitate data theft and extortion.
The compromised infrastructure is used for a wide range of purposes, including cryptocurrency mining, data hosting, and proxy and command-and-control (C2) relays.
Rather than using new techniques, TeamPCP relies on tried and tested attack techniques, such as existing tools, known vulnerabilities, and widespread misconfigurations, to create an exploitation platform that automates and industrializes the entire process. This turns the exposed infrastructure into a “self-perpetuating criminal ecosystem,” Flare noted.
See also: New version of Shai-Hulud worm spreads via npm, GitHub

Successful exploitation paves the way for the deployment of next-stage payloads from external servers, including shell-based and Python scripts that seek out new targets for further expansion. One of the key components is “proxy.sh,” which installs proxy, peer-to-peer (P2P) and tunneling utilities, and provides various scanners to continuously search the internet for vulnerable and misconfigured servers.
A brief description of the other payloads is as follows:
– **scanner.py**: Designed to find misconfigured Docker APIs and Ray dashboards by downloading CIDR lists from a GitHub account named “DeadCatx3“, while also having options to run a cryptocurrency miner (“mine.sh”).
– **kube.py**: Includes Kubernetes-specific functionality for collecting cluster credentials and discovering resources via APIs, such as pods and namespaces, followed by dropping “proxy.sh” into accessible pods for wider dissemination and installing a persistent backdoor by deploying a privileged pod on each node that attaches to the host.
– **react.py**: Designed to exploit the React vulnerability (CVE-2025-29927) to achieve remote command execution at scale.
See also: Python-based WhatsApp worm spreads Eternidade Stealer

– **pcpcat.py**: Designed to discover exposed Docker APIs and Ray dashboards across large IP address ranges and automatically deploy a malicious payload.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
