TeamPCP Tied to Redis Attacks Dating Back to 2020

Oligo Security researchers tied the TeamPCP cluster to Redis attacks dating back to April 2020 and to its later evolution into the ShadowRay 2.0 campaign.
Table of Contents
    Add a header to begin generating the table of contents

    Oligo Security researchers Avi Lumelsky and Gal Elbaz have linked the TeamPCP cluster to Redis exploitation dating back to April 2020, establishing a longer operational history than previously known for an AI-infrastructure attack group. The same cluster evolved into the ShadowRay 2.0 campaign and is tracked under the TA-NATALSTATUS designation.

    Extending the TeamPCP Operational History to April 2020

    The research traces TeamPCP to a Redis campaign first observed in April 2020, before the cluster adopted the targeting of exposed AI and machine-learning workloads that defined its later activity. The timeline pushes the group’s documented history well before the ShadowRay-era infrastructure attacks for which it had more recently been known.

    The ShadowRay 2.0 Lineage and the TA-NATALSTATUS Tracking

    The same cluster is tracked under TA-NATALSTATUS and evolved into the ShadowRay 2.0 campaign. Oligo’s analysis ties the early Redis exploitation to the later AI-infrastructure supply-chain campaigns, unifying what might otherwise look like distinct operations under a single current of activity that has persisted for years.

    The AI Workload Targets: Ray, Docker, Redis, and React

    TeamPCP targets span distributed machine-learning deployments built on Ray, along with Docker, Redis, and React environments used to run AI workloads. The exposed services are the primary entry points the group uses for credential theft and compute abuse. The focus on the Redis and Ray surfaces is significant because both are commonly deployed with weak or absent authentication when standing up AI infrastructure quickly.

    From the 2020 Redis Campaign to the AI Supply Chain

    The research establishes that the cluster’s original Redis-centric activity predates its AI-supply-chain phase, tying early exploitation of the data store to the later compute-campaign work. The continuity matters for attribution and defensive history: indicators associated with the 2020 Redis campaign can now be understood as part of the same operational lineage rather than a separate group.

    What the TeamPCP Timeline Means for AI Platform Operators

    For operators of AI and machine-learning infrastructure, the finding raises the stakes on exposed services that are often provisioned casually. Audit internet-exposed Ray, Docker, Redis, and React endpoints, enforce authentication and network segmentation, review the ShadowRay and IronErn indicators of compromise, and monitor for anomalous job submissions on Ray clusters.

    Defenses That Span the Multi-Year Attack History

    Because the group has reused infrastructure, patterns, and credentials over several years, the recommended response draws on indicators spanning the earlier Redis campaigns as well as the newer supply-chain work. Defenders should not treat the ShadowRay-era indicators as the full historical picture; the activity rooted in the 2020 Redis operations is part of the same current and should be included in hunting and detection logic.

    The TeamPCP attribution complicates the view of AI-infrastructure attacks as a recent phenomenon. Tying the cluster to April 2020 shows that the tools and patterns behind ShadowRay have been evolving on infrastructure that the field has only recently begun to treat as critical. For AI platform operators, the practical lesson is that exposed Redis and Docker instances, especially those provisioned quickly with default settings, are not a transient nuisance but a long-standing entry point for the same group, giving defenders reason to audit not just current workloads but the historical reachability that let the attackers in.

    The research shows that attribution in the AI-infrastructure space still rests on connecting apparently separate incidents through shared operator behavior. Because the same cluster shows up across a Redis campaign from 2020 and a modern AI supply-chain operation, the value of a shared indicator base grows. Operators who hold onto older threat data, rather than discarding it as outdated, are the ones able to spot the continuity that researchers used here to tie TeamPCP to the span. That argues for treating threat intelligence as a cumulative resource, since the group’s multi-year reuse patterns mean a defensive signature written for the older campaign may still catch the newer one as it evolves.

    Related Posts