Technology 2 min read source: Ars Technica Türkçe

Google Analyst Infiltrated Notorious Supply-Chain Hacking Gang TeamPCP

Google's threat intelligence group revealed it had an undercover analyst embedded within TeamPCP, a hacking group responsible for compromising hundreds of companies.

Google Analyst Infiltrated Notorious Supply-Chain Hacking Gang TeamPCP
Image: Ars Technica

Google's threat intelligence group has announced that one of its undercover analysts successfully infiltrated TeamPCP, a notorious hacking group that compromised hundreds of companies. This infiltration allowed Google to monitor the group's activities from within, warn potential victims, and help disrupt their exploitation attempts. Two alleged members of TeamPCP were arrested and charged in Australia last month.

Highlights

  • Google's security subsidiary, Mandiant, had an undercover analyst embedded within TeamPCP's inner circle almost from the beginning of the group's operations.
  • The analyst gained access to a server where TeamPCP stored stolen credentials, enabling Google to warn victims and prevent further exploitation.
  • Instead of directly alerting individual victims, Google contacted providers like Amazon Web Services and Microsoft to revoke the compromised credentials.
  • Internal chats revealed TeamPCP was developing an AI-powered zero-day exploit to bypass two-factor authentication, which Google helped patch.
  • TeamPCP partnered with other cybercriminal groups like ShinyHunters to monetize its stolen data, but ShinyHunters later betrayed them.

Details

TeamPCP emerged in late 2025 and conducted an unprecedented spree of supply-chain attacks. They infected hundreds of open-source programs with malware, hijacked developer accounts, and even released a Dune-themed self-spreading worm to automate their process, ultimately breaching over a thousand companies.

According to Google Threat Intelligence Group researcher Austin Larsen, Google's undercover analyst was invited to join the group's core chat, dubbed "CanisterWorm," in March. This insider access allowed Google to monitor the group's activities and access their trove of stolen credentials, which included over half a million user credentials. Google then sent hundreds of notification emails to providers and victims to revoke these credentials and prevent their misuse.

Operational security mistakes made by TeamPCP members, combined with intelligence from the cybercriminal group ShinyHunters, led to the arrests of Ruben Ian Thomson and Louis Michael Gaebler in Australia. These two individuals, both in their early 20s, were charged with hacking crimes and described as "principal participants" in TeamPCP by the Australian Federal Police (AFP) in a joint investigation with the FBI.

Why it matters

This incident is a rare example of how cybersecurity firms can proactively combat cybercrime by infiltrating threat groups. Google's undercover operation not only allowed them to monitor the attacks but also to take decisive action to protect victims and help patch previously unknown vulnerabilities. This highlights the critical importance of intelligence gathering and collaboration in the fight against sophisticated cyber threats.

Technology

← All news