<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Ransomware Gang Teams Up With Supply Chain Hackers in "Industrialized" Attack Model

Sophos warns of a dangerous alliance between ransomware group Vect and credential-theft gang TeamPCP, escalating cyber threats.
Content Team

Cybersecurity firm Sophos is warning of a dangerous new partnership between ransomware group Vect and TeamPCP, a credential-theft gang whose members it says were previously affiliated with the English-speaking Com collective. Announced by the groups in late March and detailed in a July 2 blog post, the arrangement pairs TeamPCP's large-scale supply chain attacks with Vect's ransomware-as-a-service operation.

Sophos has confirmed at least one Vect deployment using TeamPCP-stolen credentials. It also found a flaw worth knowing about before anyone considers negotiating: Vect's encryption destroys files larger than 128KB rather than encrypting them, so paying up won't bring them back.

TeamPCP's side of the operation is substantial. Between March and May 2026 it compromised the Trivy, Checkmarx, LiteLLM and Telnyx developer tools, reaching more than 1,000 enterprise environments and taking around 300GB of compressed data — including over 500,000 credentials and 10,000 CI/CD workflows from Trivy alone.

The FBI issued a simultaneous FLASH warning, naming TeamPCP malware including CanisterWorm, Sandclock, Miasma, and the self-replicating worm Mini Shai-Hulud.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo