conv.

All stories
SecurityActive today · day 6

Google reveals undercover analyst infiltrated TeamPCP hacking group

Security researcher embedded in notorious supply-chain attackers helped warn victims and disrupt exploits before two alleged leaders were arrested.

What to know

  • Google had embedded an undercover analyst in TeamPCP's inner circle from nearly the group's inception, monitoring the unprecedented supply chain hacking spree in real time.
  • TeamPCP's cascade of attacks compromised hundreds of open-source programs and breached over 1,000 companies including GitHub, OpenAI, and the European Commission.
  • Google used its undercover access to warn victims, disrupt extortions, and provide law enforcement with identifying details that led to the August arrest of two alleged ringleaders in Australia.
  • The group deployed a self-spreading worm called Mini Shai-Hulud (named after Dune's sandworms) to automate its malware distribution across developer tools and infrastructure.

Austin Larsen Google Threat Intelligence Group researcherRuben Ian Thomson Alleged TeamPCP leaderLouis Michael Gaebler Alleged TeamPCP leaderGoogle Threat Intelligence Group / Mandiant Security researchers and threat intelligence divisionTeamPCP Cybercriminal hacking group

Google reveals undercover analyst infiltrated TeamPCP hacking group
wired.com

How it unfolded 1 development · click the chart to see its coverage articlesposts

Peak 7 pieces in two hours at Sep 18, 11 AM; 25 pieces over 6 days (5 articles · 20 posts) Sep 18, 11 AM — 7 pieces · 3 articles · 4 posts — Mastodon 3, Newswires 2, Bluesky 2Sep 18, 1 PM — 1 piece · 1 post — Hacker News 1Sep 18, 3 PM — quietSep 18, 5 PM — 1 piece · 1 post — Mastodon 1Sep 18, 7 PM — quietSep 18, 9 PM — quietSep 18, 11 PM — quietSep 19, 1 AM — quietSep 19, 3 AM — quietSep 19, 5 AM — quietSep 19, 7 AM — quietSep 19, 9 AM — quietSep 19, 11 AM — quietSep 19, 1 PM — quietSep 19, 3 PM — quietSep 19, 5 PM — quietSep 19, 7 PM — quietSep 19, 9 PM — quietSep 19, 11 PM — quietSep 20, 1 AM — quietSep 20, 3 AM — quietSep 20, 5 AM — 6 pieces · 2 articles · 4 posts — Mastodon 5, Newswires 1Sep 20, 7 AM — quietSep 20, 9 AM — 1 piece · 1 post — Bluesky 1Sep 20, 11 AM — 1 piece · 1 post — Hacker News 1Sep 20, 1 PM — quietSep 20, 3 PM — quietSep 20, 5 PM — quietSep 20, 7 PM — quietSep 20, 9 PM — quietSep 20, 11 PM — quietSep 21, 1 AM — 1 piece · 1 post — Bluesky 1Sep 21, 3 AM — quietSep 21, 5 AM — 1 piece · 1 post — Bluesky 1Sep 21, 7 AM — quietSep 21, 9 AM — 2 pieces · 2 posts — Hacker News 1, Bluesky 1Sep 21, 11 AM — quietSep 21, 1 PM — quietSep 21, 3 PM — quietSep 21, 5 PM — quietSep 21, 7 PM — quietSep 21, 9 PM — 1 piece · 1 post — Mastodon 1Sep 21, 11 PM — quietSep 22, 1 AM — quietSep 22, 3 AM — quietSep 22, 5 AM — quietSep 22, 7 AM — quietSep 22, 9 AM — quietSep 22, 11 AM — quietSep 22, 1 PM — quietSep 22, 3 PM — quietSep 22, 5 PM — quietSep 22, 7 PM — quietSep 22, 9 PM — quietSep 22, 11 PM — quietYesterday, 1 AM — quietYesterday, 3 AM — quietYesterday, 5 AM — quietYesterday, 7 AM — 2 pieces · 2 posts — Bluesky 1, Mastodon 1Yesterday, 9 AM — quietYesterday, 11 AM — quietYesterday, 1 PM — quietYesterday, 3 PM — quietYesterday, 5 PM — quietYesterday, 7 PM — quietYesterday, 9 PM — quietYesterday, 11 PM — 1 piece · 1 post — Hacker News 1Today, 1 AM — quietToday, 3 AM — quiet 1
Sep 19Sep 20Sep 21Sep 22yesterdaynow · 4:44 AM ET
  1. 1

    Google details how it disrupted TeamPCP operations from inside

    Larsen reveals Google used its undercover access to monitor the hacking spree, warn breach targets including GitHub, Mercor, OpenAI, and the European Commission, and help disrupt the group's extortion attempts. Google also traced operational security mistakes by one suspect and shared identifying details with law enforcement, while receiving intelligence from ShinyHunters, a rival criminal group that turned against TeamPCP.

    “One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group. So essentially, almost day one, Mandiant was watching everything behind the scenes.”
    — Austin Larsen, Google Threat Intelligence Group researcher · source
    1. first by Wired, 5d ago · also Ars Technica

      1 more headline
    • agreenberg@infosec.exchange

      As the TeamPCP cybercrime group carried out an unprecedented spree of software supply chain hacking this year, it had been infiltrated by an undercover analyst from Google's threat intel division. Google watched from inside, warned victims, even disrupted extortions. https://www. wired.com/story/an-undercover-…

      agreenberg@infosec.exchangeMastodon5d agoview on Mastodon ↗
    1 more of the top 2 · 5 posts in this stretch
    • NEW: A Google researcher snuck into the group chat of TeamPCP, the hacker gang responsible for the worst-ever supply chain hacking spree, allowing the company to disrupt the group's attacks. @agreenberg.bsky.social has the scoop:

      @coutsBluesky5d agoview on Bluesky ↗
    all of them →
  2. background

    Google reveals it had mole inside TeamPCP inner circle — Google Threat Intelligence Group researcher Austin Larsen presents findings at SentinelOne's LABScon conference detailing how Mandiant, Google's security subsidiary, embedded an undercover analyst in TeamPCP from nearly the beginning of the group's operations. The embedded persona had built months of trust with one of the hackers and was added to the group's inner circle.

  3. background

    Two alleged TeamPCP leaders arrested in Australia — Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early twenties, are arrested by Australian Federal Police in a joint investigation with FBI assistance and charged with hacking crimes as principal participants in TeamPCP.

  4. background

    TeamPCP escalates attacks on major software projects — Starting in spring 2026, TeamPCP compromises security scanner Trivy, AI tool LiteLLM, Checkmarx infrastructure, web library TanStack, and Mistral AI platform, using each breach to access more developer credentials and infect additional software.

  5. background

    TeamPCP emerges online and begins supply chain attacks — The hacker group first appears online in late 2025 and begins its unprecedented spree of cascading supply-chain attacks, compromising open-source software and stealing developer credentials to perpetuate malware distribution across hundreds of programs.

What people are saying 0 voices from 0 sites · best of 5 · verbatim