Ethical Hacking News
An inside job: How Google's undercover analyst infiltrated a notorious supply chain hacking gang, helping to bring down one of the largest and most notorious hacking groups in history, in a shocking revelation that highlights the increasingly complex and sophisticated nature of modern cybercrime.
Google's undercover analyst helped disrupt TeamPCP's supply chain hacking operations by providing crucial intel and assisting in breach disruption. A mole within TeamPCP allowed Google to monitor the group's activities from the inside, helping to warn breach targets and assist in disrupting the group's attempts to exploit them. Google's analyst gained access to TeamPCP's server, where they found stolen credentials and internal chat, allowing Google to revoke credentials and warn providers and victims. Google's team identified a zero-day exploit being developed by TeamPCP using an AI tool, which they warned the software's developer and helped patch. TeamPCP's downfall was due to operational security mistakes, including a rogue partner, ShinyHunters, which betrayed the group and led to its exile. Google's analyst played a crucial role in identifying two alleged members of TeamPCP, Ruben Ian Thomson and Louis Michael Gaebler, who were arrested and charged with hacking crimes. Google's Threat Intelligence Group now places an emphasis on disruption as part of its mission to protect users and customers.
An unprecedented supply chain hacking spree carried out by the notorious TeamPCP hacker group has finally been brought to an end, thanks in part to the efforts of Google's undercover analyst, who infiltrated the group and provided crucial intel to help disrupt their operations.
In a shocking revelation, Google's Threat Intelligence Group has confirmed that a mole within TeamPCP allowed the company to monitor the group's activities from the inside, helping to warn breach targets and even assist in the disruption of the group's attempts to exploit those victims.
The investigation into TeamPCP's activities, which began around the same time as Google's newly launched Cyber Disruption Unit, was led by researcher Austin Larsen, who revealed that Google's undercover analyst was invited to join the hackers' inner circle just as the group was beginning its frenzied supply chain hacking campaign in March.
According to Larsen, the analyst, who remains anonymous, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims. Rather than alerting the owners of the stolen credentials directly, Google instead reached out to providers like Amazon Web Services and Microsoft to have the credentials revoked and prevent the hackers from exploiting them.
Google's team also sent out hundreds of notification emails to those providers and to victims, many of which received immediate responses. Meanwhile, the analyst gained valuable insights into the group's internal chat, allowing Google to learn that someone within the group's core circle was using an AI tool to develop a zero-day exploit in a widely used piece of login software.
The exploit code was tested and found to work, with Google warning the software's developer, who was able to patch its security flaw. In a case study released by Google in May, the incident highlighted the company's efforts to take a more aggressive approach to combating cybercrime and state-sponsored hacking.
However, TeamPCP's inner workings were not without their own set of operational security mistakes, which ultimately led to the group's downfall. According to Larsen, the group struggled to profit from its enormous collection of stolen data, which included more than half a million users' credentials.
TeamPCP attempted to better monetize its hacking by inviting multiple other cybercriminal groups to partner with it, giving them access to the stolen credentials in exchange for a percentage of any extortion payments they were able to extract. However, one of those partners, ShinyHunters, turned rogue and carried out its own extortions with TeamPCP's credentials, sharing the group's internal chat with Larsen and other hackers.
ShinyHunters' betrayal got the attention of TeamPCP, which responded by narrowing its inner circle, moving its data to a new server, and exiling ShinyHunters and several other group members from its CanisterWorm chat, including Google's undercover analyst.
Despite the challenges posed by TeamPCP's inner workings, Larsen and his team were able to piece together a trail of breadcrumbs that ultimately led to the identification of two alleged members of the group, Ruben Ian Thomson and Louis Michael Gaebler. The two were arrested by Australian police in a joint investigation with assistance from the FBI, and charged with hacking crimes.
The TeamPCP mole, who remains anonymous, played a crucial role in helping Google disrupt the group's activities and prevent further breaches. According to Larsen, the analyst's work marked a new shift within Google, with the company's threat intelligence group now placing an emphasis on disruption as part of its mission to protect users and customers.
"LGoogle Threat Intelligence Group has put an emphasis on disruption," Larsen said. "That's one of our missions now. Writing reports can only be so useful. Taking action to protect users and customers—that is the next step."
Related Information:
https://www.ethicalhackingnews.com/articles/An-Inside-Job-How-Googles-Undercover-Analyst-Infiltrated-a-Notorious-Supply-Chain-Hacking-Gang-ehn.shtml
https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
Published: Fri Sep 18 11:20:54 2026 by llama3.2 3B Q4_K_M