Find notable cyber news and cases, enriched with sources, timelines, and signals.

TeamPCP ShadowRay 2.0 and TA-NATALSTATUS campaigns

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The TeamPCP campaign lineage now ties together ShadowRay 2.0/IronErn and TA-NATALSTATUS, showing a multi-year operation that abused AI infrastructure and Redis servers for botnet and miner deployment. The activity spans 2020-2026 and evolved from internet-facing compromise into broader cloud-native and software supply chain targeting. That continuity points to a persistent operator ecosystem that repeatedly reused overlapping domains, staging paths, backend infrastructure, and tradecraft across campaigns.

Related Happenings

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

TeamPCP supply-chain ecosystem shift and extortion partnerships

Threat Actor Meta
H score15 First: 22.05.2026 14:55 Last: 22.05.2026 14:55 Sources 1

About this happening: TeamPCP has expanded its supply-chain abuse model across open-source ecosystems, raising the risk of downstream compromise and extortion at scale. The group has corrupted hu...

Contagious Interview cryptocurrency social-engineering and malware-delivery campaign

Campaign
H score37 First: 23.03.2026 20:09 Last: 23.03.2026 20:09 Sources 1

About this happening: A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...

TeamPCP cloud-native exploitation campaign

Campaign
H score33 First: 09.02.2026 10:37 Last: 09.02.2026 10:37 Sources 1

How related: TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware.

About this happening: TeamPCP is a cloud-native supply-chain campaign that has used exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell (C...

Latest development: 06.08.2026 17:15

Oligo Security linked TeamPCP to TA-NATALSTATUS activity dating back to 2020 by matching domains, malware deployment paths and backend infrastructure, including masscan[.]cloud, and said the same operator ecosystem also encompassed ShadowRay 2.0 against exposed Ray clusters; GitLab banned the accounts involved.

Timeline

  1. 07.08.2026 09:50 2 articles · 3h ago

    TeamPCP ShadowRay 2.0 and TA-NATALSTATUS campaigns

    Initial Disclosure

    The linked operation traces back to 2020 and centers on repeated compromise of internet-facing infrastructure. Its later phases surfaced as ShadowRay 2.0/IronErn and TA-NATALSTATUS, both using exposed services as footholds.

    Show sources