Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
perimeter-device-exposureinternet-exposed-servicecloud-misconfigurationbotnet-infrastructure

Threat Actors Scale Attacks on Edge and Cloud Control Planes via Exposed Services and Trusted Relationships

Updated 2mo agoFirst seen Feb 10, 20263 sources

Threat actors are increasingly targeting network edge infrastructure—including firewalls, routers, and VPN appliances—by exploiting critical vulnerabilities to gain durable footholds in environments where monitoring is often weaker than on endpoints. Reporting highlights a shift toward persistence mechanisms such as device-family-specific backdoors that can survive reboots and even firmware updates, and a growing pattern of abusing trusted services and upstream providers (the “Fail-of-Trust Model”) to pivot from compromised IT/service vendors into downstream government, military, and critical infrastructure networks.

In parallel, a separate large-scale campaign tracked as TeamPCP (aka PCPcat / ShellForce) has been compromising cloud environments using automated, worm-like propagation against misconfigured or exposed management interfaces rather than novel exploits. Analysis cited in coverage attributes at least 60,000 compromised servers worldwide to the operation, which scans for and abuses exposed services such as Docker APIs, Kubernetes control surfaces, Redis, and other cloud-adjacent interfaces, turning hijacked infrastructure into monetizable “crime bots” through industrialized exploitation of known weaknesses and misconfigurations.

Share:
Threat Actors Scale Attacks on Edge and Cloud Control Planes via Exposed Services and Trusted Relationships
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 9, 20264mo ago

China-nexus actors deploy persistent backdoors on edge devices

The report highlighted China-linked threat actors developing device-family-specific backdoors for edge infrastructure that can survive firmware updates and restarts. It also described growing use of compromised upstream providers, MSPs, cloud platforms, IoT, and NAS devices to relay traffic, obscure origins, and maintain access to downstream targets.

ShellForce leak site exposes JobsGO breach data

The TeamPCP/ShellForce operation was reported to be stealing data and extorting victims through a leak site, including publishing data from a breach of Vietnam's JobsGO. The exposed dataset reportedly contained more than two million candidate records.

TeamPCP compromises at least 60,000 servers worldwide

By early February 2026, Flare reported that TeamPCP had already compromised at least 60,000 servers globally. The operation used infected systems to scan for and infect additional vulnerable targets, with much of the observed activity affecting Azure- and AWS-hosted infrastructure.

Dec 31, 20256mo ago

TeamT5 documents widespread 2025 APT edge-device exploitation

TeamT5 reported that 2025 saw heightened APT activity against network edge devices, documenting more than 510 operations across 67 countries and identifying 27 critical vulnerabilities, mostly affecting perimeter infrastructure. The report described attackers increasingly exploiting firewalls, routers, and VPN appliances to gain durable access that can survive patching and reboots.

Dec 1, 20257mo ago

TeamPCP campaign begins targeting exposed cloud services

Flare assessed that the TeamPCP/PCPcat/ShellForce operation started in late December 2025, using automated worm-like propagation to compromise exposed and misconfigured cloud management services. The actor targeted services such as exposed Docker APIs, Kubernetes clusters, Redis, Ray dashboards, and React2Shell-vulnerable systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Threat actors
3 linked
Affected products
12 linked
ReactTelegramAmazon Web ServicesDockerDropboxKubernetesDockerDropboxDockerRayDockerMicrosoft Office
Organizations
8 linked
Teamt5ShutterstockAmazon Web ServicesMicrosoft CorporationOracleFlareGoogleJobsGO
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Threat Actors Scale Attacks on Edge and Cloud Control Planes via Exposed Services and Trusted Relationships | Mallory