Pluto SecurityPluto · Research
2026-06-01
Actor index

The cast

Most public reporting collapses the TeamPCP / UNC6780 campaign into a single actor. The picture is messier - and worth understanding precisely, because the attribution affects how defenders read every incident downstream.

TeamPCP is the core group: a 17+ person collective with a single public-facing spokesperson, a tribute-to-TeamTNT naming convention, and a stated targeting criterion that excludes hospitals, small businesses, non-profits, governments, and small developers. It works in partnership with xploitrs, a separate group that handles credential validation / enumeration / exfiltration and contributed the Bitwarden CLI vector; with Vect, a ransomware-as-a-service affiliate whose partnership has cooled; and with LAPSUS$, an extortion crew. ShinyHunters is the exception - not a partner but a hostile actor that scammed TeamPCP out of credentials in the Vect operator chat and is responsible for at least one widely-misattributed breach.

Sourced from operator interviews ( Inside Darknet TeamPCP, May 9 + Inside Darknet xploitrs, April 25 + Erez Dasa TeamPCP, May), vendor reporting (Mandiant, Unit 42, SANS, Wiz, Snyk, OX, Aikido, Beelzebub, OpenSourceMalware, ramimac), and public X posts. Updated 2026-06-01.

01Primary actorActive

TeamPCP

Also known asUNC6780 (Google GTIG) · PCPcat · ShellForce · DeadCatx3

A 17+ person collective of malware developers and 'cloud native' threat actors active since late 2025. Loose structure with a single public-facing leader. Originated in cloud-native cryptomining (PCPcat / React2Shell) and pivoted to supply-chain attacks in February 2026, ultimately reaching the May 20 GitHub-internal breach. Stated cessation signal in late May; whether genuine or misdirection is unresolved.

Structure
  • 17+ operators (per May 9 Inside Darknet interview)
  • Loose leadership: “I solely represent the alias so I am known as the ‘leader’”
  • Anyone introducing tradecraft + collaborating constructively is considered “part of the team”
  • Structure designed for arrest-resilience: “arrests do not cause any major disruptions and the aliases can just pass on”
Naming
  • PCP name: dual reference - drug (operator-stated: “a lot of people here are recovering addicts and ex vendors/dealers, cyber crime is their therapy”) + tribute to TeamTNT
  • Aliases (PCPcat / ShellForce / DeadCatx3): rotation pattern; operator declines to formally retire any
Public actor handles
  • @intelkink (X) - display name “ckasper,” verified; self-declared Saint Petersburg, Russia. TeamPCP membership confirmed by both the leader (interview corroboration) and box turtle (xploitrs, May 29 X post: “yes intelkink is teampcp member”)
  • @KivuliFox (X) - self-claimed TeamPCP membership, not yet independently corroborated
  • Tox: “the jellyfish who jumped up the mountain” - Shpongle reference per the May Erez Dasa interview (operator T)
Tooling
  • TeamPCP Cloud stealer (formal name SANDCLOCK per Google GTIG) - refactored from the PCPcat stealer; runner-memory parser + hybrid encryption for exfiltration
  • CipherForce - TeamPCP's private ransomware tool (NOT a coalition group, despite earlier Unit 42 / ramimac framing); hit ~15 companies in its first month online; not in use during the supply-chain campaign at time of interview
  • Proprietary locker (separate from Vect) - operator-stated zero public samples
  • AI internally: “they just use claude and copilot internally for everything and dont monitor anything suspicious” (box turtle, X, May 27)
Targeting (operator-stated)
  • Excluded: hospitals, small businesses, non-profits, governments, small developers, startups
  • Targeted: “multi billion dollar or large israeli company”
  • Russian-locale kill switch is anti-CIS law-enforcement avoidance, not ideological: “Some of us do not want the smoke from law enforcement, and it's largely avoidable with a few lines of code so anti CIS will be in place”
Cessation signal
  • Stated in both the May Erez Dasa interview and the May 9 Inside Darknet interview: “my risk/reward ratio tells me my time has come soon to stop operating”
  • Worth flagging against the May 12 open-sourcing of the worm code (“A Gift From TeamPCP”) and the May 18-20 publish cadence - consistent with a group lowering operational footprint while seeding successors
Verbatim · TeamPCP leader (Inside Darknet, May 9 2026)
  • We do not target hospitals, we do not target small businesses, non profits, governments, if you are a small developer or startup we do not care about your credentials, you have nothing to worry about, we will never ransom you and we will never use your keys to cause you financial harm. If you are a multi billion dollar or large israeli company then we're gunning for you and we're not going to stop any time soon.
  • There isn't any strict leadership structure, but I solely represent the alias so I am known as the 'leader'. This structure is good, it means arrests do not cause any major disruptions and the aliases can just pass on.
  • A lot of people here are recovering addicts and ex vendors/dealers, cyber crime is their therapy in a weird way, it keeps them sober... there was also a few of us who appreciated the work of another group by the name of TeamTNT and learnt tradecraft from their campaigns, so the name is also a tribute to them.
02Operational partnerActive · @xploitrsturtle2 suspended from X (May 31)

xploitrs

Also known asbox turtle (spokesperson) · canister turtl (during CanisterWorm op)

A separate group from TeamPCP, partnered since the CanisterWorm operation. xploitrs predates the TeamPCP supply-chain campaign with its own history (claimed prior compromises include BMW and other car companies). Within the TeamPCP campaigns, xploitrs handles credential validation, enumeration, and exfiltration; was the 'good partner' that taught TeamPCP git exploitation and enabled the Aqua/Trivy access pivot; and was specifically the lead on the Bitwarden CLI compromise (April 23).

Spokesperson
  • box turtle / canister turtl - public-facing operator
  • Stated employment: works professionally in red teaming
  • Stated motivation: not financial - “i make and have made no money from this nor have i asked the leader of teampcp for any”
Public handles
  • @xploitrsturtle2 (X) - suspended on 2026-05-31, four days after the May 27 Dynatrace-claim post and public partnership confession
  • @xpl0itrs (X) - posts around the May 20 GitHub-breach announced charitable donation of proceeds
Role in TeamPCP campaigns
  • Credential validation / enumeration / exfiltration across the supply-chain harvests
  • Taught TeamPCP git exploitation - the “good partner” the TeamPCP leader credits for the Aqua/Trivy access pivot
  • Bitwarden CLI (April 23): xploitrs-led compromise (confirmed by box turtle in the Apr 25 Inside Darknet interview)
  • CanisterWorm: jointly with TeamPCP per both interviews
Recent claims (Dynatrace, 5-day sequence)
  • May 27 - initial teaser: “boom goes the (dyna)mite :)” attached to a Dynatrace logo image. No data, just naming the target.
  • May 29 - second teaser: “TGI fridays on thursday nights >_<” attached to a partial directory listing showing internal repos (hard-iam, prod-iam, prod-copilot, nonprod-dtappghrunner, dyna*.e.security.threats.exploits, etc.) consistent with Dynatrace's internal IAM hardening + Copilot environments + security-product source.
  • May 31 - extortion drop: “what a large directory (171,466 files) . this directory would be deleted if an acceptable amount was donated to various charities ;) attempting contact soon” attached to a much larger directory listing.
  • May 31 (later same day) - @xploitrsturtle2 X account suspended.
  • Confidence: low-medium - single-source attacker claim, but the screenshots' repo naming is internally consistent with Dynatrace conventions. Dynatrace had not commented publicly at time of cataloguing.
Public-record contributions (pre-Dynatrace)
  • March 27 - earliest public confession of the three-way partnership, three days before the formal Vect-partnership BreachForums announcement: “vect / xploitrs / teampcp have all been partnered. you are late xd”
  • May 29 - Q&A replies disclosed mid-Dynatrace-tease window: attribution breakdown (“shai hulud was teampcp, canisterworm was a mix”), corroboration of @intelkink TeamPCP membership, signal of internal tension with the TeamPCP leader, and the tradecraft note that TeamPCP uses Claude + Copilot internally without monitoring.
Tweet by @xploitrsturtle2 on May 31, 2026 attaching a screenshot of an internal directory listing with 171,466 files and threatening deletion unless donations are made to charity. Quoted by @pyotam2.
@xploitrsturtle2 (xploitrs) on X, May 31 2026 - the extortion drop attaching the full 171,466-file directory listing. Account suspended later the same day. Quoted by @pyotam2 on X.
Verbatim · box turtle / @xploitrsturtle2 (xploitrs, X 2026-03-27)
  • vect / xploitrs / teampcp have all been partnered. you are late xd
Verbatim · box turtle / @xploitrsturtle2 (xploitrs, X 2026-05-29 Q&A replies; account since suspended)
  • xploitrs and teampcp worked closely together, shai hulud was teampcp, canisterworm was a mix but we're all friends. also yes, they just use claude and copilot internally for everything and dont monitor anything suspicious
  • yes intelkink is teampcp member. i think teampcp leader is mad with me i havent heard from them, no i wont sell their data i have a plan regarding it though.
Verbatim · box turtle (Inside Darknet, April 25 2026)
  • xploitrs is its own group, but we helped on the canister worm operation so i named myself canister turtl
  • xploitrs has been a thing, we've also hacked BMW along with other car companies. we have much more to bring but the twitter has been banned so you havent heard much news on them
  • the bad thing was lack of organization and inclusion of idiots, personally i think vect should not have been involved.
03Ransomware affiliatePartnership cooled

Vect

Also known asVect 2.0 (RaaS branding)

A ransomware-as-a-service affiliate. Partnership with TeamPCP announced on BreachForums on 2026-03-30 with one confirmed deployment at announcement. Per the May 9 TeamPCP leader interview and the April 25 xploitrs interview, the relationship has cooled - both partner groups openly criticize Vect's competence. TeamPCP now runs its own proprietary locker; xploitrs's box turtle stated: 'vect should not have been involved.'

Known issue: broken encryption
  • Vect 2.0 RaaS has a critical encryption flaw: any file over 128 KB is permanently destroyed because decryption nonces overwrite each other. Victims who pay cannot recover those files.
  • TeamPCP leader: “I think the Vect operator is a very motivated person and will improve with time, this is a vetting fault and one of his maldev teams, but he will fix it.”
Role in the partnership
  • Vect's contribution was supposed to be ransomware deployment + the red/negotiation team to process credentials
  • TeamPCP leader: “Vect never made us any money but I don't particularly like to sell data”
  • The Vect operator chat is also where ShinyHunters infiltrated and scammed TeamPCP (see ShinyHunters card below)
04Extortion crewActive partnership

LAPSUS$

Cybercriminal extortion group. The TeamPCP/LAPSUS$ partnership was first surfaced by OpenSourceMalware via a LAPSUS$ Telegram channel post (2026-03-26) reading 'TeamPCP gonna do another large Supply chain attack, be ready for it' before any public indicator appeared. Independently confirmed by Mandiant CTO Charles Carmakal at RSA Conference. Per the May 9 TeamPCP leader interview, LAPSUS$ handles the red/negotiation team to process credentials.

Attribution evidence
  • OpenSourceMalware: Telegram-channel post quoted above, dated before public indicators
  • Mandiant CTO Charles Carmakal: public confirmation at RSA Conference (first major-vendor confirmation)
  • SANS coverage: “collaborating with the LAPSUS$ extortion group to target multi-billion-dollar companies”
05Antagonist (not a partner)Hostile to TeamPCP

ShinyHunters

A data-extortion crew. Listed here because public reporting (including ours, until this update) has read the ShinyHunters–TeamPCP relationship as a clean monetization handoff. The May 9 TeamPCP leader interview clarifies it was actively hostile: a ShinyHunters member infiltrated the Vect operator chat, agreed to split profit on a credential bundle, downloaded the credentials, refused to pay, and released a mix of real and fabricated chats to discredit TeamPCP. The credentials they obtained that way were used in at least one breach widely misattributed to TeamPCP.

The chat-scam (operator account)
  • A ShinyHunters member was in the Vect operator chat
  • Asked to use a TeamPCP credential bundle in exchange for profit-split
  • TeamPCP agreed; ShinyHunters downloaded the credentials
  • ShinyHunters then refused to pay, released “a mix of real and fabricated chats” to make TeamPCP look stupid
  • TeamPCP leader: “This was all a huge display of ego and shitty business practice, we were looking forward to collaborating but they just lied and scammed because they were jealous of the attention. That being said it taught us a good opsec lesson.”
CERT-EU attribution correction
  • Public reporting widely attributed the CERT-EU breach (340 GB stolen from 42 EU departments via Trivy-derived AWS access) to TeamPCP-direct exploitation
  • TeamPCP leader denial (May 9 Inside Darknet): “We didn't exfil from cert-eu at all, we don't even target gov... they downloaded S3 buckets from their AWS”
  • Attribution per the operator: ShinyHunters, using credentials they scammed from the Vect chat
  • Treat as the most likely picture, with the standard primary-source caveat (operator framing is motivated)
Cisco breach (separate)
  • Per SANS ISC update 007: ShinyHunters used TeamPCP-harvested credentials to access Cisco's development environment - 300+ private repositories cloned, including AI products, unreleased code, customer repos from banks, BPOs, US government agencies
  • April 3 ransom deadline set by ShinyHunters; Cisco has not publicly acknowledged payment or negotiations
Verbatim · TeamPCP leader (Inside Darknet, May 9 2026) - on CERT-EU
  • We didn't exfil from cert-eu at all, we don't even target gov and was operating more as an access broker at this point but after looking through the IOCs from the first campaign I realized very quickly that trufflehog was a huge red flag and same with the mullvad ips, one of the red teamers was even using boto3 on kali which is very bad opsec, so this is avoided as much as possible.
06 · Disambiguation

Aliases vs. groups

The names below are the most-confused identifiers in TeamPCP-adjacent reporting. Group-level names cluster the same human collective; alias-level names are rotational identifiers within one group; tool-level names are pieces of software owned by one group.

NameKindBelongs toNote
TeamPCPGroupTeamPCPThe core collective. Self-named.
UNC6780GroupTeamPCPGoogle GTIG designation.
PCPcatAliasTeamPCPSelf-named; ties to the cat-themed signatures (UwU PCP Cat, ‘play around with the cats’).
ShellForceAliasTeamPCPSelf-named.
DeadCatx3AliasTeamPCPSelf-named.
CipherForceTool (private RaaS)TeamPCPEarlier framed by Unit 42 + ramimac as a coalition group; the May 9 interview corrects this - it's TeamPCP's private ransomware tool, ~15 victims pre-campaign, not in use during this campaign.
SANDCLOCKMalware familyTeamPCPGoogle GTIG designation for the TeamPCP Cloud stealer.
xploitrsGroupxploitrsSeparate group. Partnered with TeamPCP since CanisterWorm.
box turtle / canister turtlOperator aliasxploitrsSpokesperson; works professionally in red teaming.
VectGroup (RaaS)VectRansomware affiliate. Partnership cooled.
LAPSUS$GroupLAPSUS$Extortion crew. Negotiations partner.
ShinyHuntersGroupShinyHuntersAntagonist - scammed TeamPCP via the Vect chat; misattributed CERT-EU breach.
CanisterWormOperation / malware familyTeamPCP + xploitrsSelf-propagating npm worm campaign (March 2026); joint operation per both interviews.
Mini Shai-HuludOperation / malware familyTeamPCPApril-May 2026 worm; xploitrs-confirmed: “shai hulud was teampcp.”