Google mole in TeamPCP hacking gang watched from day one
Google's undercover analyst infiltrated TeamPCP, the supply-chain hacking gang, warning victims and passing key details to the FBI before arrests in Australia.
Google Mole in TeamPCP Hacking Gang
Google mole in TeamPCP hacking gang watched the operation from inside its inner circle almost from the start. That is the headline from a LABScon talk by Google Threat Intelligence Group researcher Austin Larsen, who laid out how an undercover Mandiant analyst sat in the group's core chat while it tore through open-source software at a pace the security world had never seen.
TeamPCP first appeared online in late 2025. Before two alleged members were arrested in Australia last month, the group had tainted hundreds of open-source programs with malware, stolen developer accounts to keep the cycle going, and released a Dune-themed self-spreading worm called Mini Shai-Hulud. More than a thousand companies were breached.
How the Mole Got In
Larsen said one of Google's personas spent months building trust with an actor. That actor was later invited to join TeamPCP. And that relationship carried the analyst into the group. So essentially, almost day one, Mandiant was watching everything behind the scenes, Larsen told WIRED ahead of his SentinelOne LABScon presentation, explaining how the persona's patient work and the invitation that followed pulled the analyst straight into TeamPCP's orbit.
The mole was not Larsen himself. He declined to name the analyst. The account was one of roughly 12 members granted access to TeamPCP's core chat, a channel the group called CanisterWorm.
Michael Fletcher is a former Australian Federal Police analyst. He's now in the threat research division of an Australian telecom firm. He says he approached Larsen around that time about monitoring the group, and Larsen asked him to move cautiously because one of the hackers was a "friendly," Fletcher remembers. "I thought, damn, you all have been inside this early," he said.
What Google Saw and Did
From inside CanisterWorm, the analyst reached a server where TeamPCP stored credentials stolen from victims: usernames, passwords, and access tokens the group appeared to be holding for extortion. Larsen's instinct was disruption. "Let's go mess up what they're doing," he said. "That was my goal."
Alerting every victim directly would have taken too long given the sheer number of breached companies.
The chat also revealed something else. Someone in the core circle was using an AI tool, separate from the supply-chain campaign, to develop a zero-day exploit in a widely used piece of login software that would bypass two-factor authentication. Google obtained the exploit code, tested it, and found it worked with a few tweaks. It was a rare in-the-wild case of an AI-created hacking technique exploiting an unknown vulnerability. Google warned the software's developer, who patched the flaw. A case study in May described the incident without naming TeamPCP.
Betrayal From a Partner
Money was a problem. The Australian Federal Police said its stolen data included more than half a million users' credentials, a staggering haul that made the group's financial troubles look even stranger given how much sensitive information they'd supposedly grabbed. Larsen estimates TeamPCP pulled in only tens of thousands of dollars in extortion payments. And they're not the millions similar crews have amassed. It's a gap you can't ignore.

TeamPCP wanted cash. So they invited other cybercriminal groups to partner, handing over stolen credentials in exchange for a cut of any extortion payments, because that's how you turn a haul into money. One partner was ShinyHunters. They're a prolific crew that has extorted millions through data theft and ransomware, including the breach of educational software platform Canvas that later paralyzed thousands of US schools, and they don't stop there.
Around April, weeks after the partnership began, ShinyHunters went rogue. It ran its own extortions with TeamPCP's credentials and skipped the cut, then shared a full log of TeamPCP's chat with Larsen without knowing Google already had a mole inside. It also taunted TeamPCP on X. The louder betrayal got attention. TeamPCP narrowed its inner circle, moved its data to a new server, and exiled ShinyHunters and several members from CanisterWorm, including Google's analyst.
The Trail to an Arrest
Losing the chat did not end the investigation. Larsen turned to older-fashioned detective work. In a leak of user data from the BreachForums hacker forum, he found that one of the most active handles in CanisterWorm had been registered with the Gmail address [email protected]. Digging through forum archives, he found a 2019 dispute between a user calling themselves sheepstealing and a seller of pirated Microsoft Office keys. The sheepstealing user demanded a refund to a PayPal account tied to [email protected].
After TeamPCP moved its stolen credentials to a server run by a different provider, Google learned through what Larsen calls a "trusted partner" about some contents of the new server, and that it was being backed up to a Google Drive on that same [email protected] account.
"When we saw that, I just thought: There's no way. Why would he be sending all of this illicit, stolen material to a Google Drive that's tied to himself?" Larsen said. "That's when we gave the tip to the FBI."
An agent responded with interest within minutes. About a month later, US law enforcement had completed the legal process of requesting the account's data with a warrant. Late last month, Australian police arrested Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, in a joint investigation with FBI assistance. The AFP described them as "principal participants" in TeamPCP. Privacy laws kept their names out of the official announcement. Video showed Thomson being walked out of a suburban home in a Northface hoodie and sweatpants.
They were a fly on the wall, only saying enough to not be suspicious. There are guardrails around what we do. - Austin Larsen, Google Threat Intelligence Group
The FBI declined to comment on an active investigation but said it confirms it strives to increase impact on adversaries through partnerships. The AFP declined to comment. Neither Thomson nor Gaebler could be reached.
A Shift Inside Google
Larsen stressed one thing. Google's undercover analyst never took part in illegal hacking. They didn't encourage any breaches either. But the work fits a broader change at the company, a shift that's been building as Google moves toward a more aggressive posture on cybercrime, and the investigation began around the same time as Google's new Cyber Disruption Unit, which is tasked with a more aggressive approach to cybercrime and state-sponsored hacking.
- TeamPCP compromised open-source tools including Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI.
- Those attacks let it breach GitHub, data contracting firm Mercor, and employee devices at OpenAI and the European Commission.
- Google says it sent hundreds of notification emails to credential providers and victims.
"Writing reports can only be so useful," Larsen said. "Taking action to protect users and customers, that is the next step."
The lesson is blunt. If you're running open-source dependencies, you can't ignore it. A single stolen token can cascade into a supply-chain breach touching a thousand companies, and that's not a hypothetical, it's the shape of the threat they're already facing. Google's mole in TeamPCP gave defenders a rare look at how fast that cascade moves. And how sloppy the people behind it can be.
Frequently Asked Questions
How did Google's analyst gain access to TeamPCP's core chat, CanisterWorm?
One of Google's personas spent months building trust with an actor who was later invited to join TeamPCP. That relationship carried the analyst into the group, and the account was one of roughly 12 members granted access to TeamPCP's core chat called CanisterWorm.
What did the undercover analyst discover on the server reached from inside CanisterWorm?
From inside CanisterWorm, the analyst reached a server where TeamPCP stored credentials stolen from victims, including usernames, passwords, and access tokens the group appeared to be holding for extortion. The chat also revealed that someone in the core circle was using an AI tool to develop a zero-day exploit in widely used login software that would bypass two-factor authentication.
Why did Google contact providers like Amazon Web Services and Microsoft instead of alerting every victim directly?
Alerting every victim directly would have taken too long given the sheer number of breached companies. Google instead contacted providers where the credentials could be used, including Amazon Web Services and Microsoft, to get them revoked, and Larsen's team sent hundreds of notification emails to those providers and to victims.
How did ShinyHunters' betrayal affect TeamPCP and Google's analyst?
Around April, weeks after the partnership began, ShinyHunters went rogue, ran its own extortions with TeamPCP's credentials, skipped the cut, and shared a full log of TeamPCP's chat with Larsen without knowing Google already had a mole inside. TeamPCP then narrowed its inner circle, moved its data to a new server, and exiled ShinyHunters and several members from CanisterWorm, including Google's analyst.
What evidence led Google to give the FBI a tip that resulted in arrests?
Larsen found that one of the most active handles in CanisterWorm had been registered with the Gmail address [email protected], and through a trusted partner Google learned that TeamPCP's new server was being backed up to a Google Drive on that same account. Google gave the tip to the FBI, and late last month Australian police arrested Ruben Ian Thomson and Louis Michael Gaebler in a joint investigation with FBI assistance.
๐ฌ Comments (0)
No comments yet. Be the first!













