TeamPCP
Also known as ShadowRay 2.0, IronErn, TA-NATALSTATUS, xploitrsturtle2, CipherForce, Mini Shai-Hulud, Replicating Marauder, UNC6780, PCPCat, SHADOW-WATER-058, pcpcats, Shellforce
Reports
50
First seen
Mar 26, 2026
Last seen
Aug 7, 2026
Motivation
Financial, Notoriety, Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×1×14
United States×14
Brazil×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1195 Supply Chain Compromise ×34T1041 Exfiltration Over C2 Channel ×28T1555 Credentials from Password Stores ×25T1005 Data from Local System ×21T1078 Valid Accounts ×19T1190 Exploit Public-Facing Application ×13T1003 OS Credential Dumping ×13T1486 Data Encrypted for Impact ×11T1566 Phishing ×10T1204 User Execution ×9T1059 Command and Scripting Interpreter ×8T1547 Boot or Logon Autostart Execution ×7
Indicators
cve ×135domain ×47filename ×41ip_v4 ×25hash_sha1 ×13url ×6hash_sha256 ×5email ×2
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-55182 (exploited)CVE-2026-0300 (exploited)CVE-2026-33017 (exploited)CVE-2026-45585 (exploited)CVE-2024-1212CVE-2024-21626 (exploited)CVE-2024-3400 (exploited)CVE-2024-9643 (exploited)CVE-2025-29635 (exploited)CVE-2025-29927 (exploited)CVE-2025-48703 (exploited)CVE-2025-5777 (exploited)CVE-2025-9501 (exploited)CVE-2026-1357 (exploited)CVE-2026-20127 (exploited)CVE-2026-20182 (exploited)CVE-2026-20223CVE-2026-22719 (exploited)CVE-2026-28950CVE-2026-33626 (exploited)
Recent reports
High