Key facts
- Google's Mandiant subsidiary had an undercover analyst within TeamPCP's inner circle.
- The analyst monitored the group's activities from "almost day one" of its public presence.
- TeamPCP compromised hundreds of open-source programs with malware, stole developer accounts, and released a self-spreading worm.
- The group breached over a thousand companies, including OpenAI and the European Commission.
- Google warned software providers and victims about exploited credentials and helped revoke them.
- An AI-developed zero-day exploit targeting two-factor authentication was discovered and reported to the software developer.
Google's threat intelligence group has revealed that an undercover analyst infiltrated the notorious TeamPCP hacking gang, a group known for its extensive supply-chain attacks. The analyst was embedded within the group for many months, providing Google with inside access to monitor their operations, warn potential victims, and disrupt their activities.
TeamPCP gained notoriety for compromising hundreds of open-source programs, stealing developer accounts, and using a self-spreading worm to automate its attacks, ultimately breaching over a thousand companies. Among the high-profile targets were OpenAI, the European Commission, and various software infrastructure providers.
Two alleged members of TeamPCP, Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, were arrested last month and charged with hacking crimes. Australian police described them as "principal participants" in the group.
Google's undercover analyst gained access to a server containing a trove of stolen credentials, including usernames, passwords, and access tokens. To disrupt TeamPCP's extortion scheme, Google notified providers like Amazon Web Services and Microsoft to revoke the compromised credentials and subsequently alerted the affected victim companies.
In a separate development, Google's analyst also discovered that a TeamPCP member was using an AI tool to develop a zero-day exploit capable of bypassing two-factor authentication. Google provided the exploit code to the software developer, who then patched the vulnerability. This incident highlighted the emerging threat of AI-generated hacking techniques.
