By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Google Analyst Infiltrated Supply-Chain Hacking Gang

Google's Threat Intelligence Group successfully infiltrated the notorious supply-chain hacking gang known as TeamPCP, an operation that provided critical inside intelligence during the group's extensive malware campaign. This infiltration allowed Google to monitor the hackers' activities, warn potential targets of impending breaches, and actively assist in disrupting the group's exploitation attempts. The revelations come from Austin Larsen, a researcher with Google Threat Intelligence, who is set to present these findings at SentinelOne's LABScon research conference. TeamPCP is known for a historically significant hacking spree that involved tainting hundreds of open-source programs with malware, stealing developer accounts to maintain control over compromised software, and deploying a self-spreading worm themed around the movie "Dune" to automate their attacks. This campaign ultimately resulted in breaches affecting over a thousand companies. Larsen detailed how Google's investigation traced operational security errors allegedly made by two Australian individuals, who are now facing charges in Australia as leading members of TeamPCP. Google passed these identifying details to law enforcement, contributing to their apprehension. The company also leveraged intelligence from ShinyHunters, another cybercriminal group that had initially partnered with TeamPCP but later turned against them. Perhaps the most significant aspect of Google's involvement was the presence of an undercover analyst from Google's security subsidiary, Mandiant. This analyst was embedded within TeamPCP's inner circle from the early stages of the group's prominent activity, offering unparalleled insight into their operations. The infiltration provided Google with a unique vantage point to understand the scale and methods of TeamPCP's sophisticated software supply-chain attacks, which represent a significant threat to the digital ecosystem by compromising widely used software components. The group's modus operandi involved injecting malicious code into open-source projects, which would then be distributed to a vast number of downstream users when the compromised software was updated or downloaded. This tactic allows attackers to gain access to a large number of organizations simultaneously through a single point of compromise. The success of Google's undercover operation highlights the evolving strategies employed by cybersecurity firms to combat sophisticated threat actors and underscores the persistent dangers posed by supply-chain attacks in the current digital landscape.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.