Ransomware
TeamPCP
Ransomware
Needs review
8 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog
because it self-identifies as ransomware-type malware, but no one
has curated a full summary or double-checked its reference links. Treat the details below as a starting point,
not a verified profile.
Also known as: DeadCatx3, PCPCat, SHADOW-WATER-058, ShellForce, TeamPCP, UNC6780
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (G1056) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- TeamPCP, Group G1056 — MITRE ATT&CK
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| elastic | AWS Discovery API Calls from VPN ASN for the First Time by Identity | production | 2026-09-18 |
| splunk | Python PTH File Creation During Package Installation | production | 2026-08-21 |
| suricata | ET MALWARE TeamPCP CanisterWorm - Namastex npm Campaign - Exfiltration | rev 1 | 2026-04-23 |
| snort | ET TROJAN TeamPCP CanisterWorm - Namastex npm Campaign - Exfiltration | rev 1 | 2026-04-23 |
| sigma | LiteLLM / TeamPCP Supply Chain Attack Indicators | experimental | 2026-03-30 |
| sigma | TeamPCP LiteLLM Supply Chain Attack Persistence Indicators | experimental | 2026-03-30 |
| suricata | ET MALWARE TeamPCP CnC Activity Observed | rev 1 | 2026-03-27 |
| snort | ET TROJAN TeamPCP CnC Activity Observed | rev 1 | 2026-03-27 |