TLDRocket
Sign in

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Ars Technica Andy Greenberg, WIRED.com

Google says one of its analysts got inside a supply-chain hacking gang. That let it watch the spree from the inside and help warn victims.

Based on reporting by Ars Technica, Andy Greenberg, WIRED.com — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Before two alleged members were arrested and charged in Australia last month, TeamPCP ran a supply-chain hacking campaign that sounds almost absurd in hindsight: tainting hundreds of open-source programs with malware, stealing developer accounts to spread it further, and even using a Dune-themed worm to automate the mess. The result was broad. More than a thousand companies were breached.

Now Google is saying it had a view few defenders ever get. During a key stretch of that campaign, an undercover researcher from Google’s threat intelligence team was already inside TeamPCP’s orbit, monitoring the group as it moved through the attacks. That access helped Google warn targets and disrupt some of the group’s efforts to exploit victims.

The details are set to be presented by Google Threat Intelligence Group researcher Austin Larsen at SentinelOne’s LABScon conference. Larsen’s account also says Google traced operational-security mistakes back to one of the two Australians now accused of being leading members of the group, then passed identifying details to law enforcement.

There was another twist too. Google says it received intelligence from ShinyHunters, a separate cybercrime group that had worked with TeamPCP before turning against it. And according to Larsen, Mandiant had an undercover analyst inside TeamPCP’s inner circle from almost the start of the group’s rise.

It’s a rare glimpse of intelligence work done the hard way: not just watching logs and alerts, but sitting inside the mess while the mess is still happening. TeamPCP may have been chaotic, but Google’s account suggests the response was unusually close-in as well.

My take — AI-written commentary, not fact-checked reporting

This is what security looks like when it stops pretending every problem can be solved from a dashboard. The embarrassing part for attackers is not just getting caught; it’s that a rival criminal crew helped give them up. Supply-chain hacks are built on trust, so they are also built to collapse fast when trust gets weird.

Read more about this at: Ars Technica

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.