Shared from twixb · bleepingcomputer.com

New PCPJack worm steals credentials, cleans TeamPCP infections

bleepingcomputer.com·May 7, 2026

A new malware framework called PCPJack is targeting cloud infrastructure to steal credentials while simultaneously removing access for the TeamPCP threat group. It exploits vulnerabilities in services like Docker and Kubernetes, and is believed to be developed by a former TeamPCP member, focusing on large-scale credential theft for financial fraud and extortion.

The most valuable insight for a professional in cybersecurity is that the new PCPJack malware framework is specifically targeting cloud infrastructure to steal credentials while removing competing malware infections, such as those from TeamPCP. To mitigate the risk posed by PCPJack, it is crucial to enforce multi-factor authentication (MFA), ensure proper authentication for cloud services like Docker and Kubernetes, and follow least-privilege principles to prevent unauthorized access and lateral movement within networks.

Powered by twixb

Want more content like this?

twixb tracks your favorite blogs and social media, filters by keywords, and delivers personalized key learnings — straight to your inbox.

More from Cybersecurity News

Recent stories curated alongside this one.