← Back to BrewedIntel
malwarehighRansomwareSupply Chain AttackTeamPCPVect

Mar 31, 2026 • Unit 42

Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure

TeamPCP has announced a partnership with the Vect ransomware group and is continuing its campaign of multi-stage supply chain attacks targeting security...

Source
Unit 42 (Palo Alto Networks)
Category
malware
Severity
high

Executive Summary

TeamPCP has announced a partnership with the Vect ransomware group and is continuing its campaign of multi-stage supply chain attacks targeting security infrastructure. This development represents a concerning escalation as threat actors increasingly compromise trusted security tools and providers to reach downstream customers. The targeting of security infrastructure is particularly dangerous as it weaponizes the very tools organizations rely on for protection. Organizations should immediately review their supply chain dependencies, implement verification mechanisms for security software updates, enforce strict vendor risk management protocols, and maintain robust incident response plans to mitigate the risk of compromise through trusted security channels.

Summary

TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group. The post Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure appeared first on Unit 42 .

Published Analysis

TeamPCP has announced a partnership with the Vect ransomware group and is continuing its campaign of multi-stage supply chain attacks targeting security infrastructure. This development represents a concerning escalation as threat actors increasingly compromise trusted security tools and providers to reach downstream customers. The targeting of security infrastructure is particularly dangerous as it weaponizes the very tools organizations rely on for protection. Organizations should immediately review their supply chain dependencies, implement verification mechanisms for security software updates, enforce strict vendor risk management protocols, and maintain robust incident response plans to mitigate the risk of compromise through trusted security channels. TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group. The post Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure appeared first on Unit 42 . TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group. The post Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure appeared first on Unit 42 .

Linked Entities

  • TeamPCP
  • Vect