Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
2026-04-01T08:51:35Z•cefd038ee24b1f48aebf40cddd8f3ced656a94a654ffca95383fc9ceff393523
AI-agentsAI-in-malwareAI-judge-bypassBoggy-SerpensGCPHandala-HackIranian-threat-actorsTeamPCPUSBFectVectVertex-AIcloud-securityespionageoverprivileged-agentspasswordless-authphishingprompt-fuzzingprompt-injectionransomwarerecruitment-phishingretail-fraudsupply-chainwiper
What happened
Unit 42 RSS roundup (Mar 2026): Key findings include a multi-stage supply-chain campaign by TeamPCP that now partners with the Vect ransomware group to weaponize security infrastructure; a critical “double agent” class vulnerability in Google Cloud Vertex AI where overprivileged AI agents can compromise cloud environments; and an escalation of Iran-linked activity (wipers, Handala Hack/Void Manticore, Boggy Serpens) including phishing, social engineering, and misuse of admin tools. Additional briefs cover espionage campaigns (USBFect, RATs, custom backdoors), recruitment phishing impersonating
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- cefd038ee24b1f48aebf40cddd8f3ced656a94a654ffca95383fc9ceff393523
- Enrichment time
- 2026-04-01T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.