How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account
hunt.io | research | #supply-chain | #threat-intelligence | #malware | #credential-theft | #github | #python | #c2 | #dead-drop
Summary
Hunt.io analyzes the 13-file Python toolkit TeamPCP deploys post-compromise, documenting the FIRESCALE GitHub dead-drop, three-tier exfiltration and infrastructure pivots prior reporting missed.
- Published
- Collected
Skip to content