BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Massive Cloud-Native Malware Campaign Found Abusing Docker, Kubernetes

TeamPCP's cloud-native crime wave exploits Docker and Kubernetes for multi-pronged attacks.

  • The TeamPCP threat cluster is running a “massive campaign” targeting misconfigured cloud-native infrastructure like Docker and Kubernetes.
  • The attacks, observed since December 2025, deploy malware to steal data, deploy ransomware, and mine cryptocurrency for multiple revenue streams.
  • The group exploits known vulnerabilities like React2Shell (CVE-2025-55182) and uses a “worm-driven” approach to create a self-propagating criminal ecosystem.
  • The operation has already impacted victims across Canada, Serbia, South Korea, the U.A.E., and the U.S.

A significant “worm-driven” cybercrime campaign has targeted cloud-native environments since late December 2025, establishing malicious infrastructure for data theft, extortion, and cryptomining. Cybersecurity firm Flare attributes this sophisticated operation, which exploits exposed Docker APIs and critical vulnerabilities, to the threat cluster known as TeamPCP. “The operation’s goals were to build a distributed proxy and scanning infrastructure at scale, then compromise servers to exfiltrate data, deploy ransomware, conduct extortion, and mine cryptocurrency,” Flare researcher Assaf Morag said in a report.

- Advertisement -

Consequently, the group functions as a cloud-native cybercrime platform, misusing compromised resources for additional purposes like proxy relays and command-and-control servers. However, rather than using novel techniques, TeamPCP relies on known tools and misconfigurations to automate and industrialize exploitation. This transforms vulnerable infrastructure into a self-propagating ecosystem, according to analysis.

Successful breaches trigger payloads like “proxy.sh,” which fingerprints environments to deploy targeted malware, particularly within Kubernetes clusters. Other scripts, such as “scanner.py,” fetch target lists from a GitHub account to scan for weak Docker APIs and Ray dashboards while also deploying cryptocurrency miners.

Data shows the campaign primarily singles out Amazon Web Services (AWS) and Microsoft Azure environments in an opportunistic manner. The hybrid model allows the group to monetize both computing power and stolen information, fueling its criminal activities.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SharpLink CEO Says ETH “Winning” Amidst “Noise”

SharpLink CEO Joseph Chalom dismissed Ethereum criticism as "noise," highlighting its institutional lead in...

Gravity Bridge Drained of $5.4M, Halted After Exploit

The Gravity Bridge, a cross-chain bridge between Ethereum and Cosmos, was exploited for roughly...

Micron Stock $5k by 2030? Forecasts Show Likely Shortfall

Transforming a $500 investment in Micron stock into $5,000 by 2030 would require a...

Candidate sells 10 Bitcoin for $800K to fund campaign

Republican candidate Michael Carbonara sold 10 Bitcoin for $800,000 in USDC to self-fund his...

ARK Buys HOOD, Trims During Rally, Adds Defense Stock

Ark Invest sold $13.6 million worth of Robinhood (HOOD) shares on Friday, profit-taking as...

Must Read

7 Best Cryptocurrency Lending Platforms in 2025 (Ranked & Reviewed)

QUICK LINKSOur MethodologyHow to Choose the Best Crypto Lending Platform: Key Factors to ConsiderIn-Depth Reviews of the 7 Best Crypto Lending Platforms1. Nexo -...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading