Hackers hack victims hacked by other hackers

This post was originally published on this site.

image

Regular internet users and corporations are not the only victims of malicious hackers. Sometimes, the hackers themselves get hacked.

That is what happened in an unusual hacking campaign, where an unknown group of hackers targeted systems already compromised by a prolific cybercrime group known as TeamPCP. Once the hackers broke into those systems, they immediately kicked out TeamPCP hackers and removed their tools, according to a new report by cybersecurity firm SentinelOne. 

From there, the hackers use their access to deploy code designed to replicate across different cloud infrastructure like a self-spreading worm, steal various types of credentials, and finally send the stolen data back to their infrastructure.

TeamPCP is a cybercriminal group that has gathered headlines in the last few weeks, thanks to a series of high-profile hacks attributed to the group. Those hacks have included a breach of the European Commission’s cloud infrastructure, and a broadscale cyberattack against widely used vulnerability scanner tool Trivvy, which affected any company that relied on it, including LiteLLM and AI recruiting startup Mercor, among others.

Alex Delamotte, the SentinelOne senior researcher who found the new hacking campaign and dubbed it “PCPJack,” told TechCrunch that it’s not clear who is behind it. At this point, Delamotte said her three theories are that the hackers are either disgruntled ex-TeamPCP members, are part of a rival group, or are a third party “who chose to directly model their attack tools on TeamPCP’s earlier campaigns,” many of which targeted cloud infrastructure. 

“The services targeted by PCPJack strongly resemble the December-January TeamPCP campaigns, before the alleged change in group membership that happened in February-March,” said Delamotte. 

Delamotte also noted that the hackers don’t just target systems compromised by TeamPCP, but they also scan the internet for exposed services such as the virtual machine cloud platform Docker, databases running MongoDB, and others. But SentinelOne said the group appeared largely focused on targeting TeamPCP.  

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

According to the report, the hackers’ own tools keep a tally of the number of hacked targets where they successfully evicted TeamPCP by sending this information back to its infrastructure.

The goals of the PCPJack hackers appear to be purely financial, as they steal credentials with a focus on monetizing them. The hackers do this by reselling them, selling access to the hacked systems as so-called initial access brokers — hackers who break into systems and then let paying customers into the hacked machines, or by extorting the victims directly.

The hackers, however, do not try to install software to mine crypto on the hacked systems, likely because that strategy requires more time to reap rewards, according to Delamotte.

As part of some of their attacks, the hackers are using domains that suggest they are phishing for password manager credentials and using fake help desk websites, according to Delamotte.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Hot this week

OpenAI introduces new ‘Trusted Contact’ safeguard for cases of possible self-harm

On Thursday OpenAI announced a new feature called Trusted...

Tesla Model Y is first car to meet new U.S. driver assistance safety benchmark

The National Highway Traffic Safety Administration said Tuesday that...

Valverde taken to hospital after alleged incident with Tchouameni

An incident involving team-mates Federico Valverde and Aurelien Tchouameni threatens to overshadow one of Real Madrid's biggest matches of the season.

Bonnie Tyler in induced coma after emergency surgery

The Total Eclipse of the Heart singer was rushed to hospital for emergency surgery in Portugal on Wednesday.

Perplexity’s Personal Computer is now available to everyone on Mac

Perplexity’s Personal Computer, its answer to OpenClaw and other...

Topics

Tesla Model Y is first car to meet new U.S. driver assistance safety benchmark

The National Highway Traffic Safety Administration said Tuesday that...

Valverde taken to hospital after alleged incident with Tchouameni

An incident involving team-mates Federico Valverde and Aurelien Tchouameni threatens to overshadow one of Real Madrid's biggest matches of the season.

Bonnie Tyler in induced coma after emergency surgery

The Total Eclipse of the Heart singer was rushed to hospital for emergency surgery in Portugal on Wednesday.

Perplexity’s Personal Computer is now available to everyone on Mac

Perplexity’s Personal Computer, its answer to OpenClaw and other...

Shakira unveils official World Cup 2026 song

Colombian pop star Shakira unveils her official song for the 2026 World Cup.

Shakira unveils official World Cup 2026 song

Getty ImagesMatt DavisBBC Sport Senior Journalist18 minutes agoColombian pop...

William, Catherine and children name baby kangaroo at Australia Zoo

Conservationist Robert Irwin, son of Steve Irwin, says Cwtch - Welsh for cuddle - is the perfect name.
spot_img

Related Articles

Popular Categories

spot_imgspot_img