Google’s threat intelligence division has disclosed that an undercover analyst successfully infiltrated TeamPCP, a notorious hacker collective responsible for one of the most extensive supply-chain cyberattack campaigns in history. The infiltration occurred just before two alleged members, identified as Australians Ruben Ian Thomson and Louis Michael Gaebler, were arrested and charged last month. Through this inside access, Google was able to monitor the group’s activities in real-time, alert compromised organizations, and actively disrupt exploitation attempts.
Austin Larsen, a researcher with the Google Threat Intelligence Group, detailed the operation during a presentation at SentinelOne’s LABScon conference. According to Larsen, Google traced a trail of operational security errors allegedly committed by one of the accused Australians to identify key figures, subsequently passing these details to law enforcement. Additionally, the company received critical intelligence from ShinyHunters, another criminal group that had partnered with TeamPCP before turning against them.
Perhaps most significantly, Larsen revealed that an undercover analyst from Mandiant, Google’s security subsidiary, had been embedded within TeamPCP’s inner circle from the group’s earliest public emergence. “One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen told WIRED. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”
I wonder if the Aussie suspects know their operational security failed so completely right from the start.
This is wild. Mandiant being there from day one really shows the depth of their resources.