Ransomware Interviews

CyberSecurityIL

Back to list

TeamPCP

May 2026

I will just say you are speaking to T, so I will speak for myself not my team members.

Q:

Your (currently banned) X account lists Israel as the location and was created in October 2023. Also, you've deployed the "Kamikaze" wiper specifically against Iranian victims. At the same time, you've compromised Israeli companies like Aqua (Trivy) and Checkmarx. Could you explain the apparent contradiction?

A:

These countries and the people they serve are simply evil. Iran is a tyrannical regime who murders protesters in cold blood and funds terrorists while the Israeli government are rampant warpigs who's security software serves countries with similar behavior which makes them a prime target. The wiper was more for the lulz, we insert it because we can and if it does some collateral damage along the way, we will sleep happily. People all say responding with pick a side, why? I don't negotiate with evil, I am upset with what these people have turned power and faith into, it reflects badly on everyone.

Q:

You've collaborated closely with LAPSUS$ and Breached. Why partner with other groups instead of handling the full life cycle in-house?

A:

There is a lot of access here, it's better to create an eco system and connections, that way it's easier to sell the data fast and move access. LAPSUS$ have been good to work with, they are very trustworthy and they bought everything together to start the op. A lot more is handled in house than you think but the end result isn't always published under our group names — usually just the quick one taps/bulk clones.

Q:

In the recent GitHub internal breach you're selling 4,000 private repos for $50k. Why not go directly to GitHub and demand a significantly higher ransom? What's the strategy behind selling the data instead?

A:

First come first serve, we do not extort we are simply here for money upfront as soon as possible. If GitHub wanted the repos private they would bid high for them like everyone else or ask our BIN price.

Q:

Most ransomware groups focus on encrypting victim files, but TeamPCP seems to prioritize credential theft, supply-chain poisoning, and data exfiltration rather than full encryption. Why did you choose this approach?

A:

TeamPCP was initially an encrypt and extort group, it's simply not necessary anymore, we get paid the same either way while taking much less time and doing far less destruction to the businesses. I would also add after the Vect failure, we are far less interested in encryption after seeing the results we can achieve without it, this stopped us from pursuing it entirely.

Q:

Since you became active, roughly how many organizations have been impacted by your campaigns? Do you think the stolen credentials and tokens lose value over time as developers realize they've been compromised and start revoking keys?

A:

Tens of thousands of companies have been impacted, the number of developers likely in the millions. Credentials that expire sooner and large orgs are prioritized. If companies mass revoked as seen previously, then it's not a worry — we would just find another way in the supply chain.

Q:

What inspired TeamPCP to start these operations in the first place? Were any of you previously on the "legal" side of cybersecurity? If yes, what made you cross over to the other side?

A:

I tried to find work doing legal offensive operations, contract type work before this campaign and my would-be employer did something extremely unethical, so I continued blackhatting separately. Otherwise this would have played out very differently but yes I wanted to previously and still would like to pursue something like this. The heat is not good to have on you and I've made enough money to eat, house myself and take care of my team. Some of us have even started donating our earnings because we simply don't need it to survive anymore and that's all that matters. We don't want to or need to be rich and we don't like causing damage to people but poor security pays.

Q:

Your campaigns show an extremely strong focus on supply-chain attacks. What practical advice would you give to organizations and developers on how to defend against attacks like these?

A:

Minimum release age, pin releases to hash, fine grain tokens, know what or limit extensions your developers are using in their IDEs. Socket will find the malware before the package is mature enough to hit your machine and publish all of the IOCs/remediation steps for you or your company's blue team should you get hit.

Q:

Threat actors like you constantly face better defenses, law enforcement pressure, and faster incident response. What's your long-term strategy for staying operational, and evolving faster than the defenders?

A:

We will always adapt against the blue team. With law enforcement, my risk/reward ratio tells me my time has come soon to stop operating.

Q:

Do you use AI tools in any part of your operations?

A:

Yes, we both code our malware by hand and with the assistance of AI. Studying the different mechanisms used in the tools we are exploiting are all done by a human. You can give any skid an LLM and they wouldn't be able to replicate these attacks even with the source code and postmortems fully public — which speaks for itself.

Q:

Is there anything else you'd like to say or share with my followers (40k)?

A:

Let the results speak.

Q:

Bonus question 😊 I noticed your Tox nickname is "the jellyfish who jumped up the mountain" — a reference to the Shpongle track (right?). According to Simon Posford, the title refers to a Darwinian evolution metaphor: even a jellyfish can climb a mountain one tiny step at a time over millions of years. What's the story behind choosing this name? Does this gradual-evolution metaphor connect in any way to TeamPCP's philosophy or operations?

A:

Well, my circumstances weren't too great and I just kept going and learning as much as possible, trying to exploit software, writing malware and fucking up, sometimes without money for food or rent 24/7/365. I am the jellyfish who jumped up the mountain.

base44
Edit with Base44