TeamPCP Threat Actor Active Since 2020, Leveraging AI for Rapid Payload Evolution
Research reveals the prolific threat actor TeamPCP, known for recent attacks on open-source software, has a history dating back to at least 2020 and employs AI for rapid payload adaptation.

The threat actor known as TeamPCP, which gained significant attention for its widespread attacks on open-source software earlier this year, has been operating for much longer than previously understood. New research from Oligo Security indicates that TeamPCP's activities date back to at least 2020, with evidence linking the actor to sophisticated campaigns that predate its recent notoriety.
Oligo Security's investigation uncovered multiple attacks bearing TeamPCP's hallmarks, including a late 2025 campaign that exploited a ShadowRay vulnerability. This campaign resulted in the creation of the first self-propagating botnet running on compromised AI infrastructure. Crucially, the infrastructure used in this ShadowRay 2.0 campaign, such as IP addresses and domains, was also linked to earlier attacks, suggesting a consistent operational footprint over several years.
A particularly concerning aspect of TeamPCP's operations is the speed at which its malicious payloads evolve. Uri Katz, director of research at Oligo Security, noted that the payloads demonstrated rapid adaptation to their target environments, a pace far exceeding typical attack evolution. This accelerated change is attributed to the actor's use of artificial intelligence, enabling swift adjustments to evade detection and maximize exploit effectiveness.
Further analysis by Oligo Security revealed that TeamPCP, also tracked under aliases such as TA-NATALSTATUS and IronErn, has been active across various campaigns from 2020 to late 2025. The threat actor has been relatively open about its activities, with one of the domains identified by Oligo Security appearing on TeamPCP's official GitHub profile. This transparency, coupled with its growing use of AI, has allowed TeamPCP to build a brand and become more active on social media, boasting about its successes.
The actor's growth and effectiveness are significantly bolstered by its strategic use of AI. Avi Lumelsky, an AI security researcher at Oligo, highlighted that AI assists TeamPCP in orchestrating attacks and managing its infrastructure. This capability is particularly potent given the global race to adopt AI technologies, which often creates new security vulnerabilities in AI-centric systems and open-source components that attackers can exploit.
TeamPCP's recent attacks have specifically targeted security gaps emerging from the increased reliance on AI and automated deployment systems. By compromising the open-source frameworks and software packages that underpin these systems, the actor can achieve widespread impact. Many AI infrastructures are built on open-source components, and while beneficial, they often place the onus of secure implementation on the user, creating opportunities for exploitation.
With this extended operational history now understood, researchers are more confident that TeamPCP has been involved in numerous other attacks that have yet to be attributed to it. The actor's consistent use of advanced techniques, including AI-driven payload evolution and infrastructure orchestration, suggests a significant and ongoing threat to the open-source ecosystem and AI-dependent systems.