Threadlinqs IntelligenceStart free

Threat actorN/ATracked since 2026-03

TeamPCP

Also known as:Altered SpiderTGR-CRI-1135UNC6780Replicating MarauderShai-HuludMiasmaMini Shai-HuludMiasma operatorMini Shai-Hulud operatorShai-Hulud lineageShai-Hulud framework authorMini Shai-Hulud operators

As of 2026-10-07, TeamPCP is a N/A-nexus threat actor tracked by Threadlinqs Intelligence across 53 threats spanning supply chain, threat intel, ransomware. Also known as Altered Spider, TGR-CRI-1135, UNC6780, Replicating Marauder. ATT&CK coverage spans 209 techniques across 15 tactics in 53 of 53 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1005 (Data from Local System), T1528 (Steal Application Access Token).

Tracked threats
5342 critical · 10 high
First seen
2026-03-20
Last seen
2026-09-30
ATT&CK techniques
209across 53 of 53 threats
Related CVEs
8Referenced by its activity
Attribution
N/ANation or origin
Nation: N/A · 53 tracked threat(s) · Categories: SUPPLY_CHAIN, THREAT_INTEL, RANSOMWARE, MALWARE, APT, VULNERABILITY

Activity timeline

TeamPCP appears in 53 tracked threats between and ; the busiest month was 2026-03 with 13 reports.

ATT&CK techniques observed

209 techniques observed across 53 of 53 tracked threats · Stealth (formerly Defense Evasion) (28), Command and Control (21), Credential Access (20), Execution (20), Persistence (19), Resource Development (18)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 44 of 53 tracked threats
  • T1005 Data from Local System — Collectionobserved in 41 of 53 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 39 of 53 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 38 of 53 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 31 of 53 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 30 of 53 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 30 of 53 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 28 of 53 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 28 of 53 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 27 of 53 tracked threats
  • T1552.001 Unsecured Credentials — Credential Accessobserved in 26 of 53 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 25 of 53 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 24 of 53 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 23 of 53 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 21 of 53 tracked threats

Tracked threats

Related CVEs

8 CVEs referenced by tracked TeamPCP activity