Campaign comparison

One Operator, Every LLM Key They Could Reach vs TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

2026-10-02  ·  2026-06-29

Link signals

Analytic Same stage(s) reached by different techniques: credential-access, privilege-escalation — same objective, different method
Commodity Shared ATT&CK technique(s): T1496, T1552.001 — commodity, many actors share these

Actor & objective

Actor unattributed vs unattributed different
Objective LLM/cloud credential theft for free AI compute access vs Credential harvesting + Monero cryptojacking via Docker API container escape, with Kubernetes cluster-wide propagation different

Kill chain

= same stage & technique   ≠ same stage, different technique   • unique to one campaign

One Operator, Every LLM Key They Could Reach

  1. divergent step: 1. credential-access · T1552.001
    Jenkins Script Console Groovy enumerates AWS/ANTHROPIC/SECRET env vars, reads credentials.xml
  2. divergent step: 2. credential-access · T1552.001
    Docker API container inspection finds a planted AWS key in a container environment block
  3. divergent step: 3. privilege-escalation · T1078.004
    PutUserPolicy self-grant attempt against the stolen key after Bedrock InvokeModel is denied
  4. shared step: 4. impact · T1496
    RunInstances and repeated InvokeModel attempts against the stolen key, all denied (zero-permission decoy)
  5. divergent step: 5. credential-access · T1552.001
    Multi-provider API key sweep (Anthropic/OpenAI/OpenRouter prefixes) via Docker exec and Langflow code execution, a week later

TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

  1. unique step: 1. reconnaissance · T1190
    Docker /version probe + /images/json enumeration on exposed daemon API
  2. unique step: 2. execution · T1610
    Four privileged containers created (Privileged:true, Binds /:/host:rw)
  3. divergent step: 3. privilege-escalation · T1611
    Escape to host via bind-mounted root; CVE-2026-31431 kernel LPE if not root
  4. unique step: 4. persistence · T1543.002
    cgroup-fs.service systemd unit disguised as 'Control Group FS'; cron net-check; profile.d hijack; 41832@CAI SSH key
  5. divergent step: 5. credential-access · T1552.005
    Cloud metadata tokens (AWS/GCP/Azure/Alibaba/Tencent), SSH keys, K8s SA tokens, wallets, CI/CD tokens, AI tool configs -> POST :667
  6. unique step: 6. lateral-movement · T1021.004
    SSH worm via harvested keys + masscan; K8s kubectl apply DaemonSet attempt
  7. shared step: 7. impact · T1496
    XMRig 6.22.2 Monero mining behind self-hosted stratum proxies -> MoneroOcean
  8. unique step: 8. defense-evasion · T1562.001
    Cloud monitoring-agent removal; Perfctl-style process hiding; iptables DROP 2375-2377

Side by side

green = shared by both campaigns.

Attribute-by-attribute comparison of One Operator, Every LLM Key They Could Reach and TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking. Values labelled "shared" appear in both campaigns.
One Operator, Every LLM Key They Could Reach TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking
Procedures
docker-api-exec:container-env-inspect+key-exfiljenkins-groovy-console:env-enum+credential-file-readprovider-key-sweep:multi-prefix-grep-env-and-filesystemstolen-key-decision-tree:identity-check-then-model-invoke-then-self-grant-then-retryFive-method fetch fallback (bash /dev/tcp, busybox wget, curl, wget, python3 urllib; each x2)Live C2 rotation via sed patch of /opt/.cgroup-fs/miner.c on pre-compromised hosts
Toolmarks
—Monero wallet 85BVSXMzxy74NTecwdiNbZZ83gxibFSszZhwCHBwcCCfW2xdrTWzMT14EgGihhQWC9fi3m5ZNfFAcaR4u5QYFP19ArnSAsKSSH key comment 41832@CAISource comment '# Pattern: 0cl/boatnet(ELLIO)+TeamTNT+PCPJack+RedTail+Perfctl+Kiss-a-dog'Source comment '# TeamPCP v21'XMRig CI/CD build path /home/buildbot/xmrig/ dated 2024-11-03
C2 protocol
—HTTP dropper delivery (port 666); HTTP POST credential exfil (port 667); Monero stratum via self-hosted relay proxies (80/443/3333/8080)
Tooling
—TeamPCP v21 toolkitXMRig 6.22.2masscan
Capabilities
cloud-api-abusecredential-harvestingllm-credential-theft18-category credential harvest incl. cloud metadata + AI tool configsCloud security-agent removal; rival-miner termination; Docker port lockoutDocker API container escape (privileged + host bind mount)Four-layer host persistence (systemd + cron + profile.d + SSH key)Kubernetes config dump + DaemonSet propagation attemptSSH worm spreading via harvested keys + masscanSelf-hosted stratum proxy aggregation
C2
—31.56.48.17995.182.96.193
ASNs
AS41745AS20473AS37963AS56971
Domains
—gulf.moneroocean.stream
CVEs
—CVE-2026-31431
Products
Docker APIJenkinsLangflow—
Geographies
global—

← Compare a different pair