Threat Brief — 2026-08-07 — DDoS at scale, TeamPCP's deeper roots
Executive summary
Today's fresh intelligence is thin but notable on two fronts. TeamPCP's operational history has been pushed back to at least 2020, revealing years of internet-facing Redis compromises before the group pivoted to supply-chain extortion — a meaningful expansion of the threat-actor profile. Separately, DDoS attacks sourced from over 3.1 million IP addresses are now described as routine against the gaming sector, signalling a shift in baseline attack capacity. Most other ingested findings are re-reportings of stories already covered this week with no new developments.
Top items
- TeamPCP's tracked history extended to 2020 with Redis-focused intrusions. New analysis shows TeamPCP was compromising internet-facing Redis instances and other infrastructure for years before pivoting to supply-chain extortion campaigns, meaning the group's capability and victim base are broader than previously understood. This develops the story first reported 2026-08-04 by RSS:securitylab-ru. (src: The Hacker News)
- DDoS attacks from 3.1M+ source IPs normalised against gaming industry. Record-breaking volumetric attacks are now routine, with botnets leveraging millions of IP addresses — a capacity level that raises the bar for downstream mitigation and suggests broadly compromised consumer-device pools. (src: SecurityLab)
- Russian corporate certificate migration cost estimated at 10–50M rubles per organisation. While the domestic TLS certificates themselves are free, adapting enterprise PKI, application stacks, and CI/CD pipelines to replace foreign CAs will require significant engineering spend — relevant for any organisation operating under Russian regulatory mandates. (src: SecurityLab)
Themes
Attack-surface maturation. Both TeamPCP's multi-year Redis campaign and the 3.1M-IP DDoS baseline illustrate threat actors operating at sustained scale well before public attribution catches up — reinforcing that "newly discovered" often means "long-active."
