Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure

2026-04-01T08:51:35Zcefd038ee24b1f48aebf40cddd8f3ced656a94a654ffca95383fc9ceff393523
AI-agentsAI-in-malwareAI-judge-bypassBoggy-SerpensGCPHandala-HackIranian-threat-actorsTeamPCPUSBFectVectVertex-AIcloud-securityespionageoverprivileged-agentspasswordless-authphishingprompt-fuzzingprompt-injectionransomwarerecruitment-phishingretail-fraudsupply-chainwiper

What happened

Unit 42 RSS roundup (Mar 2026): Key findings include a multi-stage supply-chain campaign by TeamPCP that now partners with the Vect ransomware group to weaponize security infrastructure; a critical “double agent” class vulnerability in Google Cloud Vertex AI where overprivileged AI agents can compromise cloud environments; and an escalation of Iran-linked activity (wipers, Handala Hack/Void Manticore, Boggy Serpens) including phishing, social engineering, and misuse of admin tools. Additional briefs cover espionage campaigns (USBFect, RATs, custom backdoors), recruitment phishing impersonating

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
cefd038ee24b1f48aebf40cddd8f3ced656a94a654ffca95383fc9ceff393523
Enrichment time
2026-04-01T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.