Hackers hack victims hacked by other hackers
A sophisticated hacking campaign dubbed 'PCPJack' is actively targeting systems already compromised by the cybercriminal group TeamPCP, forcibly removing their tools and repurposing the access for credential theft and resale—representing a new threat vector where attackers exploit existing breaches rather than conducting independent intrusions. This secondary-exploitation attack pattern expands the attack surface for organizations already dealing with initial compromise and suggests evolving threat actor strategies focused on monetizing stolen credentials through resale and initial access broker operations. For IT organizations, this means that breach response must now account for not just the initial threat actor, but the heightened risk of follow-on attacks from opportunistic groups seeking to capitalize on already-weakened security postures.
