KELA REPORT
TeamPCP Threat Actor Profile
A post arrest full technical profile of the group that compromised Trivy, Checkmarx KICS, LiteLLM and the Telnyx SDK. Tradecraft, infrastructure, indicators and MITRE ATT&CK mapping.

Most supply chain attacks find a weak dependency. TeamPCP compromised the tools that check the dependencies, then used the credentials it stole from each victim to reach the next.
This profile documents how. It covers the group’s evolution from opportunistic cloud exploitation into industrialised supply chain compromise, the specific tradecraft behind each wave, the infrastructure it built to survive takedowns, and a full MITRE ATT&CK mapping.
Key Report Highlights:
- Detailed tradecraft. Memory reading to bypass GitHub secret masking, credential validation, and execution on any Python start.
- Payload evolution. Shift from monolithic scripts to modular loaders, double-encoded Python, and audio steganography.
- Resilient infrastructure. Typosquatted C2 domains per targeted brand and an ICP canister dead-drop fallback.
- Cloud & Kubernetes techniques. AWS enumeration, privileged DaemonSets, host mounting, token harvesting, and ECS Exec abuse.
- Ecosystem analysis. KELA-exclusive research on Telegram operations, CipherForce leak site, ransomware links, and forum personas.
- Indicators & mapping. Malicious domains, onion services, contact IDs, and a complete MITRE ATT&CK mapping across 12 tactics.