Before authorities in Australia arrested two alleged members last month, the hacker collective known as TeamPCP executed a supply-chain cyberattack campaign unlike any previously recorded. The group infected hundreds of open-source programs with malicious code, stole developer credentials to sustain their operations, and deployed a self-replicating worm inspired by the ‘Dune’ franchise to automate their attacks. These efforts ultimately resulted in breaches at more than a thousand organizations.
Google’s Threat Intelligence Group has now disclosed that its own undercover researcher was embedded within the group during the peak of its activity. This infiltration allowed Google to monitor the attacks from the inside, issue warnings to targeted entities, and assist in thwarting exploitation attempts against those victims.
Austin Larsen, a researcher with Google’s Threat Intelligence Group, will present findings on the investigation and infiltration during a talk at SentinelOne’s LABScon research conference. According to Larsen, Google traced operational security errors allegedly committed by one of two Australians accused of leading TeamPCP, passing critical identifying information to law enforcement.
The company also utilized intelligence from ShinyHunters, another well-known cybercriminal group that had partnered with TeamPCP before turning against the supply-chain hackers. In a significant revelation, Larsen noted that Mandiant, Google’s security subsidiary, maintained an undercover analyst within TeamPCP’s inner circle from nearly the beginning of the group’s public emergence—though that analyst was not Larsen himself.
Does infiltrating a hacker group actually prevent future attacks, or does it just help catch them later? I wonder how much this slows down their next move.
I can’t believe Mandiant had someone inside from the start. That’s a serious long con and pretty impressive operational security work by Google.