AI News Feed
Market watch
Cybersecurity

Google Analyst Infiltrated TeamPCP Supply-Chain Hacking Group, Researcher Says

Google says an undercover analyst infiltrated TeamPCP, helping warn breach targets as two alleged members face charges.

TeamPCP carried out a hacking spree unlike any other in history before two of its alleged members were arrested and charged in Australia last month, Ars Technica reported. It tainted hundreds of open-source programs with malware, stole developer accounts to perpetuate its software supply-chain hacking and released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.

Larsen said Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of TeamPCP and passed key identifying details to law enforcement. Google also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with but which later turned on the supply-chain hackers, according to Larsen.

Larsen said Google's security subsidiary Mandiant had an undercover analyst—not himself—within TeamPCP's inner circle from almost the beginning of the group's time in the spotlight. The infiltration gave Google visibility into what Larsen described as an unprecedented and chaotic supply-chain hacking campaign.

The campaign's tactics combined contaminated open-source software, stolen developer accounts and a self-spreading worm, according to Ars Technica. Google's position inside the group allowed it to warn breach targets and help disrupt the group's attempts to exploit victims, Larsen said.

The disclosure comes as the two alleged TeamPCP members face charges in Australia. Larsen's talk at LABScon is expected to provide further details on how Google investigated and infiltrated the group, and on the intelligence it received from ShinyHunters after that group broke with TeamPCP.