Skip to content
Weekly Threat Bulletin February 11th 2026

Weekly Threat Bulletin February 11th 2026

www.f5.com July 2, 2026

A massive, worm-driven campaign, attributed to the TeamPCP threat cluster (also known as DeadCatx3, PCPcat, PersyPCP, and ShellForce), has been systematically targeting cloud-native environments since at least November 2025, with significant activity observed around December 25, 2025. This operation aims to establish a distributed proxy and scanning infrastructure to compromise servers for data exfiltration, ransomware deployment, extortion, and cryptocurrency mining. TeamPCP leverages misconfigured Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers, alongside vulnerabilities such as React2Shell (CVE-2025-55182) and React flaw (CVE-2025-29927). The group employs various payloads, including `proxy.sh` for installing proxy and tunneling utilities with Kubernetes-specific logic, `scanner.py` to identify misconfigured Docker APIs and Ray dashboards and deploy cryptocurrency miners, `kube.py` for Kubernetes credential harvesting and persistent backdoor deployment, `react.py` for remote code execution via the React flaw, and `pcpcat.py` for automated deployment of malicious containers. The C2 server 67.217.57[.]240 has been linked to the Sliver framework. Primarily targeting Amazon Web Services (AWS) and Microsoft Azure, the attacks are opportunistic, focusing on infrastructure that facilitates their criminal ecosystem rather than specific industries, making affected organizations collateral victims. The danger of TeamPCP lies in its operational integration and scale, combining infrastructure exploitation with data theft and extortion for multiple revenue streams.

A critical pre-authentication remote code execution (RCE) vulnerability, identified as CVE-2026-1731 with a CVSS score of 9.9, has been addressed in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products. This operating system command injection flaw allows an unauthenticated remote attacker to execute arbitrary commands in the context of the site user by sending specially crafted requests, potentially leading to unauthorized access, data exfiltration, and service disruption. The vulnerability affects Remote Support versions 25.3.1 and prior, and Privileged Remote Access versions 24.3.4 and prior. Patches are available in Remote Support - Patch BT26-02-RS, version 25.3.2 and later, and Privileged Remote Access - Patch BT26-02-PRA, version 25.1.1 and later. Self-hosted customers are advised to manually apply these patches if not on automatic updates, and those on older versions (RS older than 21.3 or PRA older than 22.1) must upgrade to a newer base version before applying the patch. Discovered by security researcher Harsh Jaiswal on January 31, 2026, via AI-enabled variant analysis, approximately 11,000 instances were found exposed to the internet, with 8,500 being on-prem deployments that remain vulnerable if not patched. Given past active exploitation of similar flaws, immediate updates are crucial for protection.

A critical vulnerability, identified as CVE-2026-1868 with a CVSS score of 9.9, affects self-hosted versions of the GitLab AI Gateway. This flaw, an "Insecure Template expansion issue" within the Duo Workflow Service, allows an authenticated attacker to achieve remote code execution or cause a denial of service by submitting crafted Duo Agent Platform Flow definitions. The vulnerability was discovered internally by a GitLab team member. Affected versions include GitLab AI Gateway versions starting from 18.1.6, 18.2.6, and 18.3.1 that are older than the fixed releases. Immediate upgrade to patched versions 18.6.2, 18.7.1, or 18.8.1 is strongly recommended for all Self Managed customers with GitLab Duo Self-Hosted installations.

Cybercriminals are exploiting legitimate Google Firebase developer accounts to launch phishing campaigns, leveraging the platform's free tier to host malicious content and send fraudulent emails. These emails originate from subdomains like `firebaseapp.com`, which possess a high domain reputation due to their association with Google's infrastructure, allowing them to bypass traditional spam filters and land directly in victims' inboxes. The attacks employ psychological tactics, including scare tactics (e.g., urgent alerts "fraudulent account use") and high-value lures (e.g., promises of free items) to trick users into clicking malicious links and divulging sensitive information. Indicators of compromise include sender addresses with random alphanumeric strings preceding `firebaseapp.com` (e.g., `[email protected][.]com`) and redirect chains involving URLs such as `hxxps[:]//rebrand[.]ly/auj0ngh`. This "living off the land" technique necessitates that security teams monitor traffic from `firebaseapp.com` subdomains that do not align with known business applications, and users must remain vigilant against unsolicited emails demanding urgent action, even if the sender appears legitimate.

China-nexus threat actors have operated the DKnife gateway-monitoring and adversary-in-the-middle (AitM) framework since at least 2019, utilizing seven Linux-based implants to perform deep packet inspection, traffic manipulation, and malware delivery via routers and edge devices. This framework, discovered during monitoring of the Earth Minotaur threat cluster, primarily targets Chinese-speaking users, evidenced by credential harvesting phishing pages for Chinese email services, exfiltration modules for WeChat, and code references to Chinese media domains, though infrastructural links to TheWizards group suggest broader targeting across Asia and the Middle East. DKnife's modular architecture includes `dknife.bin` for deep packet inspection and hijacking, `postapi.bin` for data reporting, `sslmm.bin` for TLS termination and credential harvesting from POP3/IMAP connections, `mmdown.bin` for APK downloads, `yitiji.bin` for packet forwarding, `remote.bin` for P2P VPN communication, and `dkupdate.bin` for component updates and watchdog functions. The framework delivers ShadowPad and DarkNimbus backdoors by hijacking binary downloads and Android application updates, conducts DNS-based hijacking for domains like JD.com, and interferes with antivirus and PC-management products while monitoring user activity in real-time.