Ransomware Gang Teams Up With Supply Chain Hackers in "Industrialized" Attack Model
Want more insights like this?
Cybersecurity firm Sophos is warning of a dangerous new partnership between ransomware group Vect and TeamPCP, a credential-theft gang whose members it says were previously affiliated with the English-speaking Com collective. Announced by the groups in late March and detailed in a July 2 blog post, the arrangement pairs TeamPCP's large-scale supply chain attacks with Vect's ransomware-as-a-service operation.
Sophos has confirmed at least one Vect deployment using TeamPCP-stolen credentials. It also found a flaw worth knowing about before anyone considers negotiating: Vect's encryption destroys files larger than 128KB rather than encrypting them, so paying up won't bring them back.
TeamPCP's side of the operation is substantial. Between March and May 2026 it compromised the Trivy, Checkmarx, LiteLLM and Telnyx developer tools, reaching more than 1,000 enterprise environments and taking around 300GB of compressed data — including over 500,000 credentials and 10,000 CI/CD workflows from Trivy alone.
The FBI issued a simultaneous FLASH warning, naming TeamPCP malware including CanisterWorm, Sandclock, Miasma, and the self-replicating worm Mini Shai-Hulud.
Source: Infosecurity Magazine