Google's threat intelligence team revealed that an undercover analyst infiltrated the notorious hacking group TeamPCP during its widespread supply-chain attacks, allowing the company to monitor activities, warn victims, and disrupt the hackers' operations from the inside.
TeamPCP, known for its sophisticated attacks on software supply chains, compromised hundreds of open-source programs, stole developer accounts, and even launched a Dune-themed worm to automate breaches, impacting over a thousand companies. The group's alleged masterminds, two Australians in their early twenties, were arrested last month. Google's research presented at the LABScon security conference detailed how their undercover operation provided invaluable intelligence.
According to Austin Larsen of Google Threat Intelligence Group, the infiltration began after identifying operational security mistakes made by one of the accused leaders. The undercover analyst, part of Google's subsidiary Mandiant, joined TeamPCP's inner circle early on, gaining access to their core chat, dubbed "CanisterWorm." This allowed Mandiant to observe the group's activities in real-time.
During the investigation, Google's analyst accessed a server containing a vast trove of stolen credentials. To thwart TeamPCP's extortion attempts, Google proactively contacted providers like Amazon Web Services and Microsoft to revoke compromised credentials and then notified the affected victim companies. This swift action prevented further exploitation and disrupted the hackers' monetization plans.
Adding another layer to the saga, Larsen revealed that another hacker group, ShinyHunters, with whom TeamPCP partnered, later betrayed them. ShinyHunters used TeamPCP's stolen data for their own extortion schemes without sharing profits, even providing Google with chat logs, unaware of Google's existing inside access. This betrayal led TeamPCP to tighten its circle, inadvertently pushing out Google's undercover analyst.
Despite the internal betrayal, Larsen's team continued traditional investigative work, tracing stolen credentials back to a Gmail address. This led to the identification of one of the alleged TeamPCP leaders, providing crucial evidence that was passed to the FBI. Google's involvement highlights a new, more aggressive approach by the company to combat cybercrime through its Cyber Disruption Unit, shifting from just reporting to actively intervening.