A Google undercover analyst infiltrated TeamPCP, the supply-chain hacking gang, watching its spree from inside and helping warn victims.
TeamPCP hacking gang was operating under a microscope far earlier than anyone outside a small circle at Google realized. Before Australian police arrested two alleged members last month, before the headlines about poisoned open-source tools and a worm named after Dune sandworms, an undercover analyst working for Google's security subsidiary Mandiant had already slipped inside the group's core chat. Almost day one, the company was watching the supply-chain rampage unfold from behind the scenes. That detail emerged during a talk at security firm SentinelOne's LABScon research conference, where Austin Larsen of Google Threat Intelligence Group laid out how his team investigated and infiltrated the TeamPCP hacking gang. The analyst, whose name Larsen declined to reveal, had spent months building trust with someone who would eventually be invited into the group. That patience paid off in March, just as the hacking spree was accelerating. ## Inside CanisterWorm By the time the mole settled in, the group had roughly twelve members with access to a core chat it called CanisterWorm. One participant bragged in the leaked conversations about pulling off "the biggest supplychain maybe ever recorded in modern history." The confidence was not entirely misplaced. The TeamPCP hacking gang had turned cascading supply-chain attacks into a routine. It compromised open-source software to hide malware, then used that foothold to hijack developer credentials and plant code in yet another widely used tool. The cycle repeated. Starting this spring, the group hit the open-source security scanner Trivy, the AI application programming interface tool LiteLLM, infrastructure belonging to the web application security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. Those attacks ultimately opened doors into GitHub, data contracting firm Mercor, and employee devices at OpenAI and the European Commission. The worm the group deployed, Mini Shai-Hulud, automated the process and scaled it further. More than a thousand companies were breached. ## A Credential Vault and a Race to Warn From inside the chat, Google's analyst gained access to a server where the group stored its loot: usernames, passwords, and access tokens stolen from victims, seemingly stockpiled for extortion. Larsen's instinct was not to study the haul but to sabotage the scheme. "My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?" he said. "Let's go mess up what they're doing. That was my goal." Alerting every victim company directly would have taken too long given the sheer number of breached organizations. So Google went upstream, contacting providers like Amazon Web Services and Microsoft to get the credentials revoked before the hackers could exploit them. Hundreds of notification emails went out to providers and victims. Many drew immediate responses. ### The Zero-Day Built With AI While monitoring the chat, Larsen's team noticed something separate from the supply-chain campaign. Someone in the group's core circle was using an AI tool to develop a zero-day exploit against widely used login software, one that would bypass two-factor authentication. Google obtained the code, tested it, and found that with a few tweaks it worked. It was a rare instance of an AI-created hacking technique exploiting a previously unknown vulnerability. The software's developer was warned and patched the flaw. ## Betrayal From Within and Without Google's mole was not the only source of trouble for the TeamPCP hacking gang. Even before the disruption effort, the group was struggling to convert its enormous trove of stolen data into money. Australian Federal Police said the haul included more than half a million users' credentials. Larsen estimates the extortion payments amounted to only tens of thousands of dollars, not the millions similar groups have collected. Hoping to monetize the stash, the group invited other cybercriminal outfits to partner, handing over credentials in exchange for a cut of extortion payments. One partner was ShinyHunters, a prolific group that has extracted millions through data theft and ransomware, including a breach of the educational software platform Canvas that paralyzed thousands of schools across the United States. Around April, weeks after the partnership began, ShinyHunters went rogue. It ran its own extortions using TeamPCP's credentials without paying its cut. ## The Gmail Address That Ended the Hunt Losing the inside source did not stop Larsen. Traditional detective work filled the gap. Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, were arrested late last month by Australian police in a joint investigation with FBI assistance. The Australian Federal Police described them, without naming them due to privacy laws, as "principal participants" in the TeamPCP hacking gang. Larsen says Google's tip was one thread among a broader investigative effort. The FBI declined to comment on an active investigation. ## A Fly on the Wall, and a New Mission For the TeamPCP hacking gang, the lesson is blunter. It bragged about the biggest supply-chain campaign in modern history while a Google analyst read every word.
Frequently Asked Questions
What was the name of the core chat used by the TeamPCP hacking gang, and how many members had access to it?
The group's core chat was called CanisterWorm. By the time Google's mole settled in, the group had roughly twelve members with access to it.
How did Google respond after its analyst gained access to the server where the group stored stolen credentials?
Google went upstream by contacting providers like Amazon Web Services and Microsoft to get the credentials revoked before the hackers could exploit them. Hundreds of notification emails were also sent to providers and victims, and many drew immediate responses.
What did Larsen's team discover about an AI-developed zero-day exploit while monitoring the group's chat?
Someone in the group's core circle was using an AI tool to develop a zero-day exploit against widely used login software that would bypass two-factor authentication. Google obtained and tested the code, found it worked with a few tweaks, warned the software's developer, and the flaw was patched.
Why did the TeamPCP hacking gang's partnership with ShinyHunters fall apart?
Hoping to monetize its stolen data, the group invited other cybercriminal outfits to partner, handing over credentials in exchange for a cut of extortion payments. Around April, weeks after the partnership began, ShinyHunters went rogue and ran its own extortions using TeamPCP's credentials without paying its cut.
Who was arrested in connection with the TeamPCP hacking gang, and how did Larsen continue his investigation after losing the inside source?
Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, were arrested late last month by Australian police in a joint investigation with FBI assistance. Losing the inside source did not stop Larsen, who filled the gap with traditional detective work, and Google's tip was one thread among a broader investigative effort.
Marcus Thorne covers the fast-moving field of artificial intelligence, with a particular interest in large language models, automation and the companies driving the technology forward. He aims to cut through the hype and explain what these systems can and cannot do.