All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

Created at 28 Aug · 11:20 AM1 source↑ Market-relevant
IN SHORT

Australian authorities have arrested two men accused of participating in cybercrimes for TeamPCP, a hacking group known for supply chain attacks that infected over 1,000 organizations worldwide. The group's malware, Shai-Hulud, targeted CI/CD pipelines and used smart contracts to evade takedowns.

Key Numbers

1,000+organizations infected by TeamPCP
9months of relentless attacks
14offenses charged against the two men
20+years in prison for one defendant
10+years in prison for the other defendant

Who's Involved

TeamPCP
Prolific hacking group responsible for supply chain attacks
Australian Federal Police
Authorities who arrested two alleged members of TeamPCP
Charlie Eriksen
Aikido Security researcher quoted on LLMs' impact on hacking
Brian Krebs
Journalist who reported on TeamPCP's operational discipline
Authorities arrest 2 alleged members of prolific hacking group TeamPCP

↳ Why This Matters

The arrests highlight ongoing efforts to combat sophisticated cybercrime, particularly supply chain attacks that can have widespread impact across numerous organizations. The involvement of LLMs in potentially lowering the barrier to entry for complex cyberattacks also raises concerns about future cybersecurity threats.

Key facts

  • Two men were arrested and charged with 14 offenses in Australia.
  • The arrested men are alleged members of the hacking group TeamPCP.
  • TeamPCP is accused of carrying out supply chain attacks that infected over 1,000 organizations globally.
  • The group's malware, Shai-Hulud, targeted CI/CD pipelines and used smart contracts for control servers.
  • If convicted, one man faces over 20 years in prison, and the other over 10 years.

Australian authorities announced the arrest of two men accused of being members of the prolific hacking group TeamPCP. Over a nine-month period, TeamPCP allegedly conducted supply chain attacks that compromised more than 1,000 organizations globally.

The Australian Federal Police stated that the two men were arrested and face 14 charges. TeamPCP is known for its sustained supply chain attacks, which involved lacing open-source software with malware that self-propagated. The group's worm, dubbed Shai-Hulud, targeted organizations' CI/CD pipelines. Once a package was compromised, Shai-Hulud attached itself to future updates, infecting subsequent downloads. A component of the malware collected credentials for other packages, which TeamPCP members then used to infect those additional packages.

One notable compromise involved the Trivy vulnerability scanner, which led to the theft of terabytes of credentials and private data. Shai-Hulud employed Internet Computer Protocol-based canisters, a form of smart contract, to ensure its command-and-control servers were resistant to takedowns. Infected machines communicated with these canisters every 50 minutes.

According to reporting by KrebsOnSecurity, citing researcher Charlie Eriksen, the operational discipline of TeamPCP members was lacking compared to other highly accomplished hacking groups. Eriksen suggested that large language models (LLMs) have significantly reduced the gap in the skills and infrastructure required for such sophisticated campaigns.

If convicted, one of the arrested men could face over 20 years in prison, while the other faces more than 10 years.

Frequently asked questions

TeamPCP is a prolific hacking group known for conducting supply chain attacks that have infected over 1,000 organizations worldwide.

Shai-Hulud was the name given to the malware used by TeamPCP in its supply chain attacks. It targeted CI/CD pipelines and self-propagated through open-source software packages.

Shai-Hulud used Internet Computer Protocol-based canisters, a type of smart contract, to host its control servers, making them difficult to shut down.

If convicted, one man faces over 20 years in prison, and the other faces over 10 years.

What Happens Next

01The two arrested men will face legal proceedings.
02Further investigations into TeamPCP's activities may continue.

How It Developed

Authorities in Australia arrested two men accused of participating in cybercrimes for TeamPCP.
TeamPCP is known for supply chain attacks that infected over 1,000 organizations worldwide.
The group's malware, dubbed Shai-Hulud, targeted CI/CD pipelines and self-propagated through open-source software.
Shai-Hulud used Internet Computer Protocol-based canisters to evade third-party takedowns.
One arrested man faces over 20 years in prison if convicted, the other over 10 years.

Sources

T1
Authorities arrest 2 alleged members of prolific hacking group TeamPCPvar abtest_2169528 = new ABTest(2169528, 'impression');Ars Technica

Related Stories

Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
27 Aug · 2:56 PM
AI agents install unowned code in corporate networks
27 Aug · 2:06 PM
OpenAI agents gamed test, breached Hugging Face network
27 Aug · 1:06 PM
xAI accused of training Grok on child sex abuse material in lawsuit
27 Aug · 8:56 PM
OpenAI urges collective action on cyber defense amid 'limited window'
27 Aug · 6:00 PM