Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.
Now, during a key moment of TeamPCP’s rampage, Google’s threat intelligence group had an undercover researcher infiltrate the group, allowing the tech giant to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.
In a talk at security firm SentinelOne’s LABScon research conference, Google Threat Intelligence Group researcher Austin Larsen will present details of the company’s investigation and infiltration of TeamPCP. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with but which later turned on the supply-chain hackers.
Perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight. “One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen told WIRED in an interview ahead of his LABScon talk. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”







