TeamPCP ShadowRay 2.0 and TA-NATALSTATUS campaigns
Campaign
Summary
Hide ▲
Show ▼
The TeamPCP campaign lineage now ties together ShadowRay 2.0/IronErn and TA-NATALSTATUS, showing a multi-year operation that abused AI infrastructure and Redis servers for botnet and miner deployment. The activity spans 2020-2026 and evolved from internet-facing compromise into broader cloud-native and software supply chain targeting. That continuity points to a persistent operator ecosystem that repeatedly reused overlapping domains, staging paths, backend infrastructure, and tradecraft across campaigns.
Related Happenings
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
TeamPCP supply-chain ecosystem shift and extortion partnerships
Threat Actor Meta
H score15
First: 22.05.2026 14:55
Last: 22.05.2026 14:55
Sources 1
About this happening:
TeamPCP has expanded its supply-chain abuse model across open-source ecosystems, raising the risk of downstream compromise and extortion at scale. The group has corrupted hu...
TeamPCP supply-chain ecosystem shift and extortion partnerships
Threat Actor MetaAbout this happening: TeamPCP has expanded its supply-chain abuse model across open-source ecosystems, raising the risk of downstream compromise and extortion at scale. The group has corrupted hu...
Contagious Interview cryptocurrency social-engineering and malware-delivery campaign
Campaign
H score37
First: 23.03.2026 20:09
Last: 23.03.2026 20:09
Sources 1
About this happening:
A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...
Contagious Interview cryptocurrency social-engineering and malware-delivery campaign
CampaignAbout this happening: A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...
TeamPCP cloud-native exploitation campaign
Campaign
H score33
First: 09.02.2026 10:37
Last: 09.02.2026 10:37
Sources 1
How related:
TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware.
About this happening:
TeamPCP is a cloud-native supply-chain campaign that has used exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell (C...
TeamPCP cloud-native exploitation campaign
CampaignHow related: TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware.
About this happening: TeamPCP is a cloud-native supply-chain campaign that has used exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell (C...
Latest development: 06.08.2026 17:15
Oligo Security linked TeamPCP to TA-NATALSTATUS activity dating back to 2020 by matching domains, malware deployment paths and backend infrastructure, including masscan[.]cloud, and said the same operator ecosystem also encompassed ShadowRay 2.0 against exposed Ray clusters; GitLab banned the accounts involved.
Timeline
-
07.08.2026 09:50 2 articles · 10h ago
TeamPCP ShadowRay 2.0 and TA-NATALSTATUS campaigns
Initial DisclosureThe linked operation traces back to 2020 and centers on repeated compromise of internet-facing infrastructure. Its later phases surfaced as ShadowRay 2.0/IronErn and TA-NATALSTATUS, both using exposed services as footholds.
Show sources
- TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign — thehackernews.com — 07.08.2026 09:50
- TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign — thehackernews.com — 07.08.2026 09:50