In this article

TeamPCP (UNC6780): From Telegram Data Broker to Supply Chain Cascade

TeamPCP, (UNC6780), evolved from a Telegram-based stolen data broker into the actor behind a supply chain cascade that has compromised Trivy, Checkmarx KICS, LiteLLM, and hundreds of downstream packages. KELA's Cyber Intelligence Center traces the group's infrastructure, aliases, and ransomware partnerships from mid-2025 through August 2026. The profile sets out what CI/CD owners should check now.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center

Updated August 27, 2026

TeamPCP: When the scanner is the attacker

Following the arrest of the alleged members of the cybercriminal group TeamPCP, also known as PCPcat, ShellForce, DeadCatx3, and PersyPCP, KELA’s Cyber Intelligence Center shares what we know about them so far.

TeamPCP, is an emerging cloud native cybercriminal operation that appeared as a large scale exploitation platform in late 2025. Unlike traditional APT groups that focus on long term persistence, TeamPCP distinguishes itself through heavy automation and industrialization of known attack techniques, converting compromised systems into a self-propagating criminal ecosystem

First seen in Telegram activity in mid-2025, the group became operationally visible in late 2025 during large scale cloud scanning campaigns and the React2Shell exploitation wave (CVE-2025-55182). In early 2026, it escalated into major supply chain attacks, including compromise of security tools such as Trivy, KICS, and LiteLLM. Between March 19-23, 2026, it heavily poisoned software supply chains, exfiltrating large datasets and hundreds of thousands of credentials, then shifted toward rapid “smash and grab” operations.

KELA assesses with high confidence that TeamPCP was likely behind the November 2025 cyberattack in Kenya, which defaced multiple government ministry websites and disrupted services. The attack was attributed to “PCP@Kenya”, a name consistent with TeamPCP patterns. Occurring one day after the Somalia eVisa breach, the timing and similarities between the incidents further suggest a likely connection to TeamPCP.

TeamPCP has rapidly built partnerships with multiple ransomware operations as they evolved their criminal enterprise. The group also has a ransomware operation called CipherForce to publish breach information. Their most significant collaboration began in March 2026 when TeamPCP partnered with the Vect ransomware group, creating a dangerous combination where TeamPCP provides initial access through stolen credentials while Vect provides encryption, extortion, and negotiation infrastructure. 

Vect’s post regarding the partnership with TeamPCP

Vect’s post regarding the partnership with TeamPCP



Activity

Telegram

Although some TeamPCP activity currently takes place on X, the group primarily used a Telegram channel as its main platform.TeamPCP’s Telegram channel was active from November 2025 to March 2026, where the admin, likely a native English speaker, facilitated data exfiltration and stolen data brokering. Activity observed in the channel indicates a broad victim set across multiple countries and sectors, including government, employment, and private sector data, alongside supply chain compromises.

During this period, the group promoted its CipherForce ransomware operation, launched a sister channel (Shellforce), and operated a stealer log search bot. To maintain resilience, it established Tor based infrastructure and later migrated to bulletproof hosting.

Contact points included Telegram (@a0164915), Session, and Tox.

Per KELA’s investigation, the channel was likely operated by at least two individuals, as Telegram activity across multiple groups indicates the involvement of an additional user, “PersyPCP.” In late March 2026, the admin (“DMT”) reportedly transferred control before the channel was shut down days later, however, it cannot be confirmed if this was a real exit by DMT, or just trying to keep a low profile.

The TeamPCP owner mentions his partner (Top), and the farewell message by DMT (Bottom
The TeamPCP owner mentions his partner (Top), and the farewell message by DMT (Bottom)

The TeamPCP owner mentions his partner (Top), and the farewell message by DMT (Bottom)

Forums

The onion domain referenced in the TeamPCP’s Telegram channel was identified in KELA’s data lake in a November 2025 post by the user “Pennywise”, who claimed to have compromised the site and associated it with a group called “blackwitch”. No additional references to this group were found.

KELA also identified prior use of the Telegram linked TOX and Session identifiers across multiple forums before the channel’s creation. These were tied to accounts including “Express” (BreachForums, March 2025), “EllisD25” (DarkForums, June 2025), and “BulkDMT” (BreachStars, September 2025). Activity from these users included attempts to sell database leaks access, VPS services branded “DMT Host”, trading firm access, and South African government credentials, as well as efforts to purchase a zero day vulnerability in OneAccess routers. The “Express” account was also exposed in the BreachForums data leak, linking it to a specific Gmail address, though OSINT investigation for this email remained limited.

Across all identified profiles, the same Telegram contact (@BulkDMT) was consistently referenced, along with related aliases such as pcpcat, persypcp, and persy_pcp, the one previously identified in KELA’s data lake and referenced earlier

The EllisD25 username, as seen on DarkForums

The EllisD25 username, as seen on DarkForums

A search for the “persy_pcp” username in KELA’s data lake identified a Python script shared via Pastebin, designed to scan cloud provider IP ranges for exposed Docker APIs and Ray clusters via proxies. The script is attributed to “Persy_PCP” and references an inactive GitHub account, “DeadCatx3”, previously linked to TeamPCP reporting, which hosted a CIDR ranges repository.

Although the GitHub account is no longer active, an archived version recovered by KELA shows 10 repositories, including Redis honeypot tools, an onion crawler named “BlackEye”, and other cybersecurity focused projects. The archive also highlights two key contact points: the domain masscan.cloud, which once hosted the TeamPCP Telegram channel link, and the former Telegram handle @JustaDeadcat, likely BulkDMT former Telegram user. Further analysis of masscan.cloud shows activity dating back to July 2025, including references to a Redis vulnerability and multiple subdomains.

An archived version of the GitHub profile of PersyPCP

An archived version of the GitHub profile of PersyPCP

Identification

KELA’s analysis of @JustaDeadcat indicates an individual profile of a young person, estimated at 20–21 years old in 2026. The user operated under multiple aliases, including Dead_Scene, MollyState, GodsChosenCyberTerrorist, and Prettyboygamingschool. Activity across 40+ Telegram groups shows strong involvement in Perth’s illegal drug market, including distribution of DMT (that was also mentioned in his current username) and other drugs. The actor was also linked to cyber enabled crime, including trade of GitLab runner tokens from South Africa, RDP access, KYC verified financial accounts, and claims of C2 infrastructure development and surveillance tooling.

KELA further identified claims of access monetization, including resale of premium leaked database data and exploitation of stolen credentials, alongside references to broader breach data. The account was active until July 2025, after which newer personas such as BulkDMT/PersyDMT appeared in August 2025, suggesting a possible identity transition.

Further analysis of the Telegram of @JustaDeadCat Telegram account enabled KELA’s to get additional identifiers linked to this specific account. OSINT correlation produced multiple associated online traces across social platforms, like PayPal (within a specific area in Perth), and a TikTok account using the alias “Ellis”, just like the DarkForums username.

Additionally, the investigation of the Telegram account led to indications of Instagram and Facebook registrations linked to a partially exposed email (s*8@gmail.com), Truecaller records for “Rueben Na New”, and a PayPal account under “Ruben Thomson”, mentioning a location in Perth, Western Australia, aligning with Telegram activity and messages.

  The PayPal profile for the Australian phone number

The PayPal profile for the Australian phone number.

A Facebook profile for Ruben Thomson from Perth was identified, with a date of birth that aligns with details he previously shared in Telegram groups. A family domain was also discovered, and leaked data revealed multiple associated family email addresses. Interestingly, in imagery from a video the actor shared on Telegram while staying in a hotel, a reflection in a mirror shows a person wearing a hat with long hair, closely resembling the individual in a Facebook profile photo.

Snapshot taken from a Telegram video (left), and Ruben’s Facebook photo (right), showing similarities in the hat and the long hair
Snapshot showing similarities in the hat and the long hair



Ruben’s family email appeared in the 2019 Aimware data leak, a video game cheats website, under the username “yolosolo17”. The same unique username appeared twice in the leak, also linked to another email address, surfinup8@gmail.com, which matches the previously identified partial email, and a phone number ending in 79, further strengthening the connection. Pivoting on the password that was found in the leaked database yielded an additional email address of Ruben of the family domain.

OSINT reverse searches across these identifiers reveal a broad but fragmented digital footprint spanning gaming, freelance, and content platforms. Social media traces include a Snapchat account under the name "Villager Productions" and a TikTok profile featuring what appears to be an image of the individual at a younger age. Additional references were found to a Dropbox account under the name of "Wack Level Films" and an inactive LinkedIn profile.

All the leads mentioned above, led to a specific suspect living in Perth, Australia.

Google Maps reviews in the Perth area, written by the alleged suspect

Google Maps reviews in the Perth area, written by the alleged suspect

Related Articles

The Role of a Threat Intelligence Analyst

The Role of a Threat Intelligence Analyst

KELA Cyber Team

December 12, 2024

5 Questions About Hamas-Israel War

5 Questions About Hamas-Israel War

KELA Cyber Team

December 19, 2023

The BreachForums Succession Wars

The BreachForums Succession Wars

KELA Cyber Intelligence Center

June 22, 2026