Security1 distinct publisher2 min readPublished
The Ray, Docker and Redis endpoints hijacked in ShadowRay 2.0 were worked by operators Oligo now ties to TA-NATALSTATUS activity from 2020, which makes the AI-cluster worm a tooling upgrade on an old farm.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The weight in this attribution sits on the two indicators an operator cannot retroactively clean. GitLab authentication records are server-side, and Oligo correlated them against ShadowRay 2.0 command-and-control traffic, reverse-shell activity and malware staging to build what it calls a direct operational bridge between the campaign and the actor later branded TeamPCP [8]. The hinge identity is IronErn, seen on both GitHub and GitLab during ShadowRay 2.0 and again in TeamPCP's later infrastructure [7]. Oligo had those identities in hand during the original ShadowRay 2.0 work but could not yet place them [17].
The rest of the case is the softer material: shared domains, malware deployment paths, staging techniques, backend infrastructure, operational tradecraft [4]. All of that is cheap for a competent crew to rotate. Oligo's argument is that it did not rotate. The same infrastructure families, staging patterns, malware path conventions and command-and-control held steady straight through the point where the operators started publishing under a name [5].
The span matters more than the name. Oligo places the IOC and infrastructure overlap with TA-NATALSTATUS between 2020 and August 2025 [3], which works out to somewhere between 56 and 68 months of continuous operation depending on where in 2020 it began [18]. Oligo also found TeamPCP activity months before the group branded itself [9]. The public identity therefore accounts for the tail end of a lineage running five years or more [19].
The exploitation cadence is the part worth internal circulation. Oligo describes repeated exploitation of 1-day vulnerabilities in React, Docker, Redis and Ray, frequently automated and wormable [11]. That is a crew whose business model is the gap between a disclosure and your patch window, applied to services somebody stood up and stopped owning. ShadowRay 2.0 added AI-assisted malware development and wormable payloads against exposed Ray clusters on top of the same habits [16]. The supply chain phase, GitHub Actions abuse, token theft and open-source project abuse, came later, and surfaced publicly through attacks on Trivy, Checkmarx and BerriAI/LiteLLM [10][12].
Oligo credits Mandiant and GitLab with independent review and investigative context, and GitLab banned the accounts named in the report [14][15]. TeamPCP has presented itself publicly as financially motivated [13]. On Oligo's timeline it was collecting for years before it wanted the credit.
Ranked by verification strength, evidence, and original report placement.
The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft.
Across multiple years Oligo observed recurring infrastructure families, staging patterns, malware path conventions and command-and-control infrastructure that remained consistent through the emergence of the TeamPCP identity.
Oligo's findings link the group to activity previously attributed to TA-NATALSTATUS dating back to 2020.
Oligo identified direct IOC and infrastructure overlap linking TeamPCP to activity previously attributed to TA-NATALSTATUS between 2020 and August 2025.
Oligo states the overlap suggests operational continuity consistent with the same operators, closely affiliated groups, or shared operational infrastructure, rather than completely unrelated threat activity.
Oligo calls the overlap between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0 and TeamPCP's later infrastructure one of the strongest operational links.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A misconfigured GitHub Actions workflow handed TeamPCP the token that poisoned five ecosystems1 distinct publisher
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
leadership
VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless1 distinct publisher
build
An exposed LiteLLM gateway hands over every key in PID 1's environment1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific, but only one pair of eyes has published
The technical spine is unusually concrete for an attribution piece: masscan[.]cloud recurring across TA-NATALSTATUS, IronErn and TeamPCP activity, GitLab authentication logs correlated against C2 and reverse shells, four named accounts, and a stated 2020-to-August-2025 overlap window. What holds it back is that all of it arrives in Oligo's own write-up, the promised indicators are not in the text we have, and the load of the argument sits on a sentence that says 'we assess' rather than one that counts anything. Mandiant and GitLab are credited with reviewing, which is corroboration by reputation, not a second published analysis.
Real compromises, unmeasured blast radius
Concrete things happened here: exposed Ray clusters were worked at scale, Trivy, Checkmarx and BerriAI/LiteLLM were reached through CI workflows and stolen credentials, and GitLab pulled the accounts. That is more real-world footprint than most attribution research carries. What nobody supplies is a denominator — how many clusters, how many tokens, how many downstream users pulled a poisoned artifact — so the campaign's reach remains a shape rather than a number.
Superlative outruns the hedge
Two claims are being made at once and they are not equally solid. The five-year lineage is documented indicator work; 'first known attack in which AI infrastructure was hijacked into a self-propagating botnet' is a superlative nobody else has tested, and it sits three paragraphs above Oligo's own concession that the overlap may reflect the same operators, close affiliates, or simply shared infrastructure. Naming the campaign, branding the actor and adjudicating the attribution all fall to the same house. The gap is real but modest — the underlying tradecraft detail largely earns its keep.
Discoverer, namer and vendor are one party
Oligo sells runtime security for exactly the workloads in this story — Ray clusters, containers, exposed internal services — and it authored ShadowRay 2.0 as a brand before authoring the attribution that deepens it. A lineage stretching back to 2020 makes the vendor's earlier research look prescient and the threat look permanent; both are commercially useful. None of that makes the domain overlaps untrue, and inviting Mandiant and GitLab to review cuts against pure self-dealing. But readers should notice that the only party with the telemetry is also the party selling the remedy.
Coherent single account, nothing to triangulate against
We are reading one publisher, self-interested, in a text that breaks off mid-section before the indicator detail lands. The internal logic is consistent and the hedging is honest, which is why this is not lower. It would move quickly on two things: a Mandiant or GitLab statement in its own words, and any figure attaching scale to the ShadowRay 2.0 intrusions.