The hacking crew behind a big supply-chain attack has been busy since 2020

New research links TeamPCP, the group behind a recent software supply-chain campaign, to years of quiet break-ins on exposed servers.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial scene of a dimly lit apartment workstation in a generic Eastern European city at night, multiple monitors glowing with abstract code and ter
Share

Key points

  • Researchers have tied a hacking group called TeamPCP to online attacks going back to 2020, years before its recent software supply-chain campaign.
  • The group targeted internet-facing servers, meaning computers left directly reachable from the public internet, including Redis database systems.
  • Investigators matched the group's old and new activity through shared web domains, malware file paths, and backend servers.
  • The findings suggest the same small crew has been quietly building infrastructure for years before graduating to higher-profile attacks.

A hacking group known as TeamPCP has been breaking into internet-connected servers since at least 2020, well before it turned up in a recent software supply-chain attack, according to new analysis first reported by The Hacker News.

That matters because supply-chain attacks, where criminals poison the software that other companies rely on, are usually the loud, headline-grabbing end of a much longer story. This one appears to have started years earlier, on the quieter end of the internet.

Who is TeamPCP?

TeamPCP is the label researchers use for a cybercrime crew that has been hitting exposed servers for roughly five years. The name is a tracking tag, not something the group calls itself. Their earlier work focused on machines left open to the public internet, particularly Redis, a popular piece of database software used by websites and apps to store information quickly.

When Redis is set up carelessly and left reachable from anywhere, attackers can walk in and run commands on the server. That is the sort of low-effort, high-volume target the group appears to have specialised in for years.

How did investigators connect the old attacks to the new one?

By matching fingerprints. Researchers found the same web domains, the same file paths used to drop malware (malicious software that gives attackers control of a machine), the same staging tricks, and the same backend servers turning up across incidents years apart.

In plain terms: the crew reused its tools and its plumbing. That is a common mistake among criminal groups, and it is how defenders often stitch a scattered history together into a single named actor.

Think of it like a burglar who keeps parking the same van outside every job. Each job on its own looks unrelated. Line them up and the pattern is obvious.

What changed with the supply-chain campaign?

The group moved upmarket. Instead of hunting individual exposed servers, they went after software that other organisations install and trust. That shift, from opportunistic server break-ins to poisoning the supply chain, is a familiar path for cybercrime crews that want bigger paydays or broader access.

It is also a reminder that many of the groups behind splashy 2024 and 2025 incidents did not appear from nowhere. They spent years grinding on unglamorous targets first.

What TeamPCP's history looks like

Period Main activity Typical target
2020 onward Break-ins on exposed servers Redis and similar internet-facing systems
Middle years Reused domains and malware paths Same backend servers across campaigns
Recent Software supply-chain campaign Software vendors and their downstream users

Should ordinary people be worried?

Not directly, but the businesses they rely on should be. If you run a company that exposes databases to the internet, or installs third-party software without checking it, this is your problem. For everyday customers, the practical advice is the usual: keep software updated, and be wary of unexpected password reset emails from services you use, in case a supplier further up the chain has been hit.

The wider lesson for defenders is simpler. A group that has been quietly compromising servers for five years is not going to stop because one campaign got named. Watching for repeated infrastructure, not just repeated malware, is how you catch the next chapter early.

© 2026 Threat Vectr