Advertisement
Advertisement
Advertisement
20 September 2026·11 min read·By Markus Heill

Google Analyst Infiltrated TeamPCP Hacking Gang

A Google undercover analyst infiltrated TeamPCP, the supply-chain hacking gang behind Mini Shai-Hulud, helping disrupt its extortion campaign from the inside.

Google Analyst Infiltrated TeamPCP Hacking Gang

Google watched. A Google analyst infiltrated TeamPCP, the hacker group behind one of the most aggressive software supply-chain campaigns on record, and watched the operation from inside its inner circle almost from the beginning. That's the headline. It comes from a talk Google Threat Intelligence Group researcher Austin Larsen is giving at security firm SentinelOne's LABScon research conference, where he is laying out how his team monitored the group, warned victims, and eventually helped put two alleged members behind bars, a story that reads less like a standard threat report and more like a spy thriller, except every detail here is documented in Larsen's account. And they're all documented.

A Mole Inside CanisterWorm

The most striking disclosure? Google's security subsidiary Mandiant had a person inside TeamPCP roughly from day one. Larsen says one of the company's undercover personas spent many months building trust with an actor who was eventually invited to join the group, and that relationship got the persona added to the crew, which is how it's done. That undercover analyst, whose name Larsen declined to reveal, was one of about twelve members given access to a core chat TeamPCP called CanisterWorm. Twelve members. They're in.

"One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group," Larsen told WIRED. "So essentially, almost day one, Mandiant was watching everything behind the scenes."

The mole was not Larsen himself. He is clear on that point. The infiltrator was a separate Mandiant analyst operating under a false identity, and Larsen says that person never engaged in illegal hacking or even encouraged the group's breaches.

"They were a fly on the wall, only saying enough to not be suspicious," Larsen says. "There are guardrails around what we do."

That distinction matters. Intelligence work has a line, and Larsen is drawing it in public: observation and disruption, not participation. Now for the awkward part. The timing of that infiltration lines up with a moment when TeamPCP was just starting its supply-chain spree, which means Google had visibility into the group's plans while the damage was still unfolding.

The Supply-Chain Spree That Broke Records

TeamPCP seems to have first appeared online in late 2025, and it made headlines with a brazen string of cascading supply-chain attacks. The method was a repeating cycle: compromise open-source software to hide malware, use that position to hijack developer credentials, then plant malicious code in yet another widely used tool. Each successful pass widened the net.

Starting this spring, the group hit Trivy. It's an open-source security scanner. They also compromised LiteLLM, the AI application programming interface tool, along with infrastructure belonging to the web application security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI, a list that shows just how wide their targeting spread across the software supply chain. Those repeated attacks ultimately allowed the hackers to breach open-source code repository GitHub, data contracting firm Mercor, and employee devices at OpenAI, the European Commission, and many others who've remained unnamed in public reporting. And at times, the group deployed a worm known as Mini Shai-Hulud, named after the sandworms in Dune, to automate its hacking and scale up to even more victims.

That name pointed back, too. It seemed to refer to an earlier Shai-Hulud worm, one built to try a similar approach in September 2025. And it's still not clear whether TeamPCP or any of its alleged members were involved in that earlier intrusion campaign, which is the question everyone keeps asking.

  • Compromised tools named in the campaign: Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI.
  • Breached targets include GitHub, Mercor, OpenAI employee devices, and the European Commission.
  • The group ran an automated worm called Mini Shai-Hulud, a reference to the sandworms in Dune.
  • According to the Australian Federal Police, the stolen haul included more than half a million users' credentials.

How Google Turned the Tables

Once inside, Google's analyst gained access to a server where TeamPCP was storing its trove of credentials stolen from victims: usernames, passwords, and access tokens the group had obtained through hacking and seemingly planned to use to extort target companies. Larsen's team decided to act rather than simply document.

a blue and black machine
"My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?" Larsen says. "Let's go mess up what they're doing. That was my goal."

Instead of alerting the owners of stolen credentials at victim companies one by one, which Larsen says would have taken too long given the sheer number of breached companies, Google first reached out to providers where those credentials could be used, like Amazon Web Services and Microsoft, to have them revoked. The team sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses.

The AI-Built Zero-Day

Around the same time, Google's visibility into the internal chat revealed something unusual. Someone in the group's core circle was, distinct from the supply-chain hacking, using an AI tool to develop a zero-day exploit in a widely used piece of login software that would allow the hackers to bypass its two-factor authentication. Google's team got a copy of the exploit code, tested it, and found that with a few tweaks it worked. That is a rare instance of an in-the-wild AI-created hacking technique exploiting a previously unknown software vulnerability. Google warned the software's developer, who patched the flaw. The incident was described in a case study Google released in May, but without naming TeamPCP or detailing how Google learned about the exploit.

Betrayal, Bad Opsec, and a Gmail Address

Important. Google's analyst was not the only traitor inside TeamPCP. Even before the disruption effort, Larsen says the group struggled to profit from its enormous collection of stolen data. Larsen estimates that despite the haul, it was pulling in only tens of thousands of dollars in extortion payments, not the millions similar groups have amassed.

So TeamPCP invited other cybercriminal groups to partner with it. The pitch? Stolen credentials for a cut. One partner was ShinyHunters, a years-old, highly prolific hacker group that has extorted millions through data theft and ransomware, including in the breach of educational software platform Canvas that would later paralyze thousands of schools across the US. Then things changed. Around April, a few weeks after partnering with TeamPCP, ShinyHunters went rogue, Larsen says, carrying out its own extortions with TeamPCP's credentials but without giving the supply-chain hackers their cut. And ShinyHunters even shared with Larsen, unsolicited, a full log of the group's chat on TeamPCP's server, not knowing he already had access through Google's mole.

ShinyHunters also taunted TeamPCP in messages on X, and the louder betrayal got attention. TeamPCP narrowed its inner circle, moved its data to a new server, and exiled ShinyHunters and several other members from the CanisterWorm chat, including Google's undercover analyst.

"Just delete that and stop sharing shit with shinyhunters," one of the TeamPCP leaders wrote.

Even without the inside source, Larsen says more traditional detective work let him piece together the trail of breadcrumbs that would ultimately identify Thomson, one of the two men charged. Larsen found in a leak of user data from the BreachForums hacker forum that one of the most active handles in the CanisterWorm chat had been registered with the Gmail address [email protected]. Combing through other forum archives, he found a 2019 dispute between someone using the pseudonym sheepstealing and a seller of pirated Microsoft Office keys, in which the sheepstealing user demanded a refund at a PayPal account tied to the email [email protected].

After TeamPCP moved its stolen credentials to a server hosted by a different provider, Larsen says Google learned about some contents of the new server through what he describes as a trusted partner, and also that it was being backed up to a Google Drive on that same [email protected] account.

"When we saw that, I just thought: There's no way. Why would he be sending all of this illicit, stolen material to a Google Drive that's tied to himself?" Larsen says. "That's when we gave the tip to the FBI."

Larsen says he got an interested response from an agent in a matter of minutes. About a month after his tip, US law enforcement had finished the legal process of requesting Thomson's data from Google with a warrant. Late last month, Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, were arrested by Australian police in a joint investigation with assistance from the FBI, charged with hacking crimes, and described by the Australian Federal Police in a press release as principal participants in TeamPCP. Australian privacy laws meant the release did not name them. Police released a video of Thomson being walked out of a suburban home in a Northface hoodie and sweatpants. Neither Thomson nor Gaebler could be reached for comment.

A Shift Inside Google

Michael Fletcher, a former AFP analyst who now works in the threat research division of an Australian telecom firm, says he approached Larsen around that time about methods for monitoring the group. He says Larsen responded by asking Fletcher to approach the hackers with caution because one of them was a friendly. Fletcher remembers thinking the team had been inside this early.

Larsen says his team is actively foiling TeamPCP's hacking. That work is part of a new shift within Google. But it's not happening in isolation, because the investigation kicked off around the same time as Google's newly launched Cyber Disruption Unit, which has been officially tasked with taking a more aggressive approach to combating cybercrime and state-sponsored hacking.

"Google Threat Intelligence Group has put an emphasis on disruption. That's one of our missions now," Larsen says. "Writing reports can only be so useful. Taking action to protect users and customers, that is the next step."

So what does this actually mean for the reader? For one thing, the case shows that supply-chain attacks are only as strong as the operational security of the people running them. A single reused Gmail address, a refund dispute from 2019, and a backup drive tied to a real identity undid months of careful hacking. For another, it signals a change in how at least one major tech company approaches cybercrime: not just publishing threat reports, but sending notifications, revoking credentials, and handing tips to law enforcement. The FBI declined to comment on any active investigation but noted it strives to increase impact on adversaries through partnerships. The AFP declined to comment. Whether that more aggressive posture becomes standard across the industry is an open question, but the TeamPCP case suggests the playbook is already being rewritten.

Frequently Asked Questions

Who infiltrated TeamPCP, and how did the undercover analyst gain access to the group's inner circle?

A separate Mandiant analyst operating under a false identity infiltrated TeamPCP, not Larsen himself. According to Larsen, the persona spent many months building trust with an actor who was eventually invited to join the group, which got the persona added to the crew. That undercover analyst was one of about twelve members given access to TeamPCP's core chat called CanisterWorm.

What supply-chain attacks and tools did TeamPCP compromise, and which organizations were breached as a result?

Starting this spring, TeamPCP hit Trivy, an open-source security scanner, and also compromised LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI. Those repeated attacks ultimately allowed the hackers to breach GitHub, Mercor, employee devices at OpenAI, the European Commission, and many others unnamed in public reporting. The group also deployed a worm known as Mini Shai-Hulud to automate its hacking and scale up to even more victims.

How did Google's team disrupt TeamPCP's campaign after the analyst gained access to the group's stolen credentials server?

Instead of alerting credential owners one by one, which Larsen said would take too long, Google first reached out to providers like Amazon Web Services and Microsoft to have the credentials revoked. The team sent hundreds of notification emails to those providers and then to victims, many of which got immediate responses. Larsen said his goal was to disrupt the campaign as quickly as possible before more compromises could happen.

What unusual AI-related activity did Google discover inside TeamPCP's internal chat, and what did Google do about it?

Someone in the group's core circle was using an AI tool to develop a zero-day exploit in widely used login software to bypass two-factor authentication. Google's team got a copy of the exploit code, tested it, and found that with a few tweaks it worked, which the article describes as a rare instance of an in-the-wild AI-created hacking technique exploiting a previously unknown vulnerability. Google warned the software's developer, who patched the flaw.

What role did ShinyHunters play in TeamPCP's operations, and how did that partnership end?

TeamPCP invited other cybercriminal groups to partner with it, offering stolen credentials for a cut, and one partner was ShinyHunters. Around April, a few weeks after partnering with TeamPCP, ShinyHunters went rogue, carrying out its own extortions with TeamPCP's credentials without giving the supply-chain hackers their cut. TeamPCP then narrowed its inner circle, moved its data to a new server, and exiled ShinyHunters and several other members from the CanisterWorm chat, including Google's undercover analyst.

Markus Heill
Written by
Gadgets and Software Writer

Markus Heill writes about technology and the tools we use every day, from smartphones to the services that run in the background. He is interested in how good design makes technology easier to live with.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement