Ethical Hacking News
Google's threat intelligence group infiltrated a notorious supply-chain hacking gang by sending an undercover researcher to join the group's inner circle. The researcher, who gained access to a server where the group was storing its stolen credentials, helped Google monitor the group's activities and disrupt its attempts to exploit victims. The team's work is part of a new shift within Google, which has been officially tasked with taking a more aggressive approach to combating cybercrime and state-sponsored hacking.
Google's threat intelligence group infiltrated TeamPCP, a hacker group that breached over 1,000 companies and stole over half a million user credentials. Google's undercover analyst gained access to a server where TeamPCP stored its stolen credentials, allowing Google to warn victims and prevent TeamPCP's ransom scheme. TeamPCP was unable to profit from its enormous collection of stolen data, with estimated extortion payments of only tens of thousands of dollars. TeamPCP was forced to expel its partners, including ShinyHunters, after the latter group went rogue and took TeamPCP's credentials for themselves. Google's Cyber Disruption Unit, launched around the same time as the TeamPCP infiltration, is taking a more aggressive approach to combating cybercrime and state-sponsored hacking.
Google’s threat intelligence group said it had a mole inside TeamPCP’s inner circle. The hacker group known as TeamPCP carried out a hacking spree unlike any other in history, breaching more than a thousand companies. The group tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process. TeamPCP was known for its brazen string of cascading supply-chain attacks, repeatedly compromising open-source software to hide its malware, which then allowed it to hijack the credentials of software developers and plant its malicious code in yet another widely used tool.
In a surprising turn of events, Google's threat intelligence group revealed that during a key moment of TeamPCP's rampage, the company's own undercover researcher had infiltrated the group. This allowed Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group's attempts to exploit those victims. According to researcher Austin Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement.
Larsen, who will be presenting details on Google's investigation and infiltration of TeamPCP at SentinelOne's LABScon research conference, revealed that Google's undercover analyst, who was part of the group's inner circle, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims. This allowed Google's team to take action to warn victims and prevent TeamPCP's ransom scheme. Larsen notes that Google's undercover analyst never engaged in any illegal hacking or encouragement of the group's breaches, but rather served as a "fly on the wall" to monitor the group's activities.
The TeamPCP mole
The investigation, which was part of a new shift within Google, kicked off around the same time as the company's newly launched Cyber Disruption Unit, which has been officially tasked with taking a more aggressive approach to combating cybercrime and state-sponsored hacking. According to Larsen, Google's undercover analyst infiltrated TeamPCP's inner circle in March, just as the group was beginning its frenzied supply-chain hacking campaign. The analyst, who was one of about 12 members of the group given access to a core chat, gained access to the group's inner circle and was able to gather intelligence on the group's activities.
The team was able to learn that one of the TeamPCP members was using an AI tool to develop a zero-day exploit in a widely used piece of login software that would allow the hackers to bypass its two-factor authentication. Google's team was able to get a copy of the exploit code, test it out, and find that it worked, a rare instance of an in-the-wild AI-created hacking technique that took advantage of a previously unknown software vulnerability. Google warned the software's developer, who was able to patch its security flaw.
The group struggled to profit from its enormous collection of stolen data, which included more than half a million users' credentials. Larsen estimates that despite this haul, TeamPCP was pulling in only tens of thousands of dollars in extortion payments, not the millions similar groups have amassed. So, in an attempt to better monetize its hacking, TeamPCP invited multiple other cybercriminal groups to partner with it, giving them access to the stolen credentials in exchange for a percentage of any extortion payments they were able to extract.
One of those cybercriminal partners was ShinyHunters, a years-old, highly prolific hacker group that has extorted millions of dollars from victims through data theft and ransomware, including in the breach of educational software platform Canvas that would later paralyze thousands of schools across the US. Around April, ShinyHunters went rogue, carrying out its own extortions with TeamPCP's credentials but without giving the supply-chain hackers their cut. ShinyHunters also taunted TeamPCP in messages on X, and its louder betrayal got the latter group's attention. TeamPCP responded by narrowing its inner circle, moving its data to a new server, and exiling ShinyHunters and several other group members from its CanisterWorm chat, including Google's undercover analyst.
The FBI
Neither Thomson nor Gaebler, the other alleged member of TeamPCP who was arrested, could be reached for comment. Larsen was careful to note that Google's undercover analyst inside of TeamPCP never engaged in any illegal hacking or encouragement of the group's breaches. "They were a fly on the wall, only saying enough to not be suspicious," Larsen says. "There are guardrails around what we do." But Larsen also notes that his team's work to actively foil TeamPCP's hacking is part of a new shift within Google. The investigation, after all, kicked off around the same time as Google's newly launched Cyber Disruption Unit, which has been officially tasked with taking a more aggressive approach to combating cybercrime and state-sponsored hacking.
The team's work to actively disrupt TeamPCP's hacking is part of a new emphasis on disruption within Google. "Google Threat Intelligence Group has put an emphasis on disruption. That's one of our missions now," Larsen says. "Writing reports can only be so useful. Taking action to protect users and customers—that is the next step."
Related Information:
https://www.ethicalhackingnews.com/articles/Googles-Undercover-Operation-Infiltrating-a-Notorious-Supply-Chain-Hacking-Gang-ehn.shtml
https://arstechnica.com/security/2026/09/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
Published: Sun Sep 20 08:16:28 2026 by llama3.2 3B Q4_K_M