A compromised Ray cluster logged a download from the group's infrastructure on July 26, 2025 — five months before the name TeamPCP surfaced publicly.
Oligo Security ties TeamPCP to TA‑NATALSTATUS activity (2020–August 2025)
New research published by Oligo Security on August 5 connects the operators behind March 2026's cascading supply‑chain compromises of open‑source developer tools to an operational history stretching back to 2020. Oligo reports that TeamPCP shares domains, malware deployment paths and backend infrastructure with activity previously tracked as TA‑NATALSTATUS between 2020 and August 2025. The firm worked with Mandiant and GitLab on the investigation; GitLab banned the accounts involved.
masscan[.]cloud and a deployment framework reused for years
Oligo identified masscan[.]cloud as the strongest infrastructure link. The domain appears across TA‑NATALSTATUS activity, ShadowRay 2.0 and later TeamPCP operations. Certificate transparency records date masscan[.]cloud to May 11, 2025, and TeamPCP's own GitHub account later listed it as the group's official website.
Alongside masscan[.]cloud, Oligo found a distinctive deployment framework reused over multiple campaigns: a specific directory path and a set of staging scripts that show up unchanged in payloads attributed to TA‑NATALSTATUS and in TeamPCP activity. That same infrastructure served tooling downloaded by a compromised Ray cluster on July 26, 2025.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageDirect operational links: reverse shells and GitLab authentication
Oligo documents one of the most direct ties in GitLab telemetry. Between October 15 and November 2, an IP address received reverse shells from a compromised Ray cluster. All shells terminated on November 2. Between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling. The firm assessed that TeamPCP ran ShadowRay 2.0 — the November 2025 campaign against exposed Ray clusters that had been attributed at the time to an actor called IronErn440.
Evolution of tradecraft: cryptojacking, supply‑chain abuse and destructive code
Oligo's timeline traces a gradual operational evolution. The operators exploited internet‑facing infrastructure as early as 2020, frequently using automated and wormable techniques, then expanded into GitHub Actions abuse and token theft. That progression ran through PCPcat — which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs — and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
The group's infrastructure also diversified beyond exploitation. Oligo observed subdomains used to support credential phishing, payment fraud and Zendesk impersonation. In late March a second‑stage Kubernetes payload incorporated a destructive branch: the script checked whether the victim system was set to the Iran timezone and, if so, deployed a workload that deleted filesystems and rebooted the machine. Oligo noted that Iranian connectivity was heavily disrupted at the time, limiting visibility into whether that destructive branch ever executed.
First known self‑propagating AI botnet and longstanding ecosystem
The investigation links TeamPCP to earlier infrastructure attacks and to what Oligo describes as the first known self‑propagating botnet built from hijacked AI infrastructure. While Oligo is careful not to assert a definitive organizational identity — stating the continuity could reflect a rebrand, a shared operator set or close collaboration — the technical continuity shows TeamPCP continuing an existing operational ecosystem rather than being a new group that suddenly appeared in late 2025.
What this means for open‑source maintainers, cloud and AI operators, and platform vendors
- Open‑source maintainers: The March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM underline the exposure risk in developer tooling and CI/CD pathways, especially where GitHub Actions and token theft can be abused.
- Cloud and AI infrastructure operators: The history of wormable techniques, exposed Ray clusters, and a Ray cluster download on July 26, 2025 highlights the need to inventory and harden internet‑facing clusters and to monitor for reused staging scripts and domains such as masscan[.]cloud.
- Platform vendors and incident responders (GitLab, Mandiant): The GitLab telemetry that tied reverse shells to subsequent authentications demonstrates how account activity and IP correlation can produce strong operational links; GitLab's account bans are already part of the response recorded by Oligo.
Oligo's work stitches together years of activity into a single operational picture: an actor or set of collaborators advancing from cryptojacking to automated exploitation, then to supply‑chain abuse and a destructive option triggered by timezone checks. The investigation leaves open a concrete, consequential question rooted in the facts reported here — did the destructive Kubernetes branch execute in Iran while connectivity was degraded? — and it underscores that the infrastructure and tooling identified by Oligo will remain essential evidence for responders tracing future activity.
https://www.infosecurity-magazine.com/news/teampcp-shadowray-ta-natalstatus/




