Product
GCP
- First Reported
- May 14, 2026
- Latest Reported
- Jul 11, 2026
Reported Context (3)
- GCP โ metadata.google.internal, the compute-metadata service-account token endpoint, GOOGLE_APPLICATION_CREDENTIALS, .config/gcloud, credentials.db, access_tokens.db, application_default_credentials.json, and Secret Compromised Jscrambler npm Releases Deliver Cross-Platform Infostealer
- proxy, consistent with web application exploitation for initial access. Representative entries include a GCP managed instance group node (ddx-instance-group-1-4xfx, 35.223.238.76), an AWS Graviton instance in PCPJack Used 230 Cloud Linux Servers in a Hidden SMTP Relay Network
- The GCP collection module covers three authentication scenarios without using any Google-provided libraries. For service account key files, the module constructs and signs a cryptographic assertion using only standard TeamPCP Python Toolkit Uses FIRESCALE and Victim GitHub Accounts to Survive C2 Disruption
CVE (1)
Malware (1)
People (1)
Threat Actors (2)
MITRE ATT&CK (42)
Vendors (6)
Products (59)
Tools (6)
Industries (2)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.