TA-NATALSTATUS is a cybercrime-linked infrastructure exploitation cluster associated with long-running attacks against exposed internet-facing services and later linked to the broader operational ecosystem publicly tracked as TeamPCP. Activity attributed to TA-NATALSTATUS has been observed since at least 2020 and continued through August 2025. It is linked by shared infrastructure, deployment paths, staging techniques, backend systems, and overlapping operational tradecraft to later campaigns including ShadowRay 2.0, also known as IronErn, and TeamPCP’s subsequent software supply-chain operations. TA-NATALSTATUS is known for targeting exposed Redis servers to deploy cryptocurrency miners. The broader linked ecosystem repeatedly exploited vulnerable or misconfigured cloud-native and internet-accessible technologies including Redis, Docker, Ray, and React-based environments. Operations relied heavily on automated and wormable exploitation, enabling self-propagation across compromised infrastructure. Across related activity, the operators used compromised systems to build distributed scanning and proxy infrastructure, conduct data theft, mine cryptocurrency, and support follow-on intrusion activity. The actor’s tradecraft evolved over time from opportunistic exploitation of exposed infrastructure into more complex post-compromise operations. Linked campaigns have included credential theft, abuse of GitHub Actions, theft of access tokens, poisoning of open-source libraries, and large-scale compromises of developer environments. Malware and staging components associated with the same ecosystem show continued development, including tooling for propagation, persistence, backdoor deployment, and destructive actions. In 2026, linked Kubernetes-focused payloads added wiper-like behavior, including destructive routines selectively triggered on systems configured for the Iran timezone, while non-Iranian Kubernetes victims could receive backdoor payloads instead. TA-NATALSTATUS should be understood as part of an established and evolving operational ecosystem rather than an isolated short-lived campaign. High-confidence reporting links it to TeamPCP and to ShadowRay 2.0 / IronErn, but available information does not conclusively establish whether these names represent a direct rebrand, the same operators throughout, or closely collaborating actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign assessed as part of the same operational ecosystem, targeting exposed Redis servers to deploy cryptocurrency miners and described as an evolution of an earlier Redis-focused malware campaign.
Earlier tracked activity cluster linked by shared domains, deployment paths, and backend infrastructure to TeamPCP operations dating back to 2020.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.