Google's Mandiant infiltrated hacking gang TeamPCP

Google's Mandiant infiltrated hacking gang TeamPCP

Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP ran a supply-chain hacking spree the article calls unlike any other in history. It tainted hundreds of open-source programs with malware, stole developer accounts to spread that compromise further, and released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.

Google Threat Intelligence Group researcher Austin Larsen disclosed at security firm SentinelOne's LABScon research conference that during a key stretch of that campaign, Google was watching from the inside. Google's security subsidiary Mandiant had an undercover analyst, not Larsen himself, embedded within TeamPCP's inner circle from almost the beginning of the group's time in the spotlight. Larsen told WIRED ahead of his talk: "One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group."

That vantage point let Google monitor the hacking spree, warn breach targets, and help disrupt TeamPCP's attempts to exploit those victims. According to Larsen, Google separately followed a trail of operational security mistakes allegedly made by one of the two now-accused Australians and passed key identifying details to law enforcement. Google also received intelligence from ShinyHunters, another well-known cybercriminal group that had partnered with TeamPCP before turning on it.

Key facts

  • TeamPCP tainted hundreds of open-source programs with malware, stole developer accounts to spread the compromise, and released a Dune-themed self-spreading worm, ultimately breaching more than a thousand companies.
  • Two alleged TeamPCP members were arrested and charged in Australia last month.
  • Google's security subsidiary Mandiant had an undercover analyst inside TeamPCP's inner circle almost from the start, distinct from Google researcher Austin Larsen who disclosed the operation at LABScon.
  • The inside view let Google monitor the hacking spree, warn breach targets, and help disrupt attempts to exploit those targets.
  • Google traced operational security mistakes to one of the accused Australians and passed identifying details to law enforcement, and separately got intelligence from ShinyHunters, a former TeamPCP partner that turned on the group.

Why it matters

This is not routine incident response after a breach: Mandiant put an undercover persona inside an active hacking group and watched a supply-chain campaign unfold from the inside, in real time, rather than only reconstructing it afterward. Treating a criminal group as an infiltration target, and doing so almost from the moment the group became prominent, is a notably aggressive posture for a company's threat intelligence arm.

Who it affects

The more than a thousand companies the article says TeamPCP ultimately breached, largely through tainted open-source packages and stolen developer accounts, sit downstream of this story. Open-source maintainers whose accounts were compromised to spread the malware are also directly affected, as are the two individuals now facing charges in Australia over their alleged roles in the group.

How to use it

There is no product or service here to adopt. The practical takeaway for security teams is the pattern Google describes: combining an undercover human source with intelligence volunteered by a rival criminal group (ShinyHunters) and operational-security mistakes traced back to suspects, then handing identifying details to law enforcement rather than only publishing an incident report.

How solid is it

The account rests on Austin Larsen's own presentation at LABScon and a WIRED interview cited by the article; the central claims, including that the undercover analyst was in place almost from day one, come directly from Larsen rather than from independent verification. The article does not describe how the infiltration was run day to day or whether TeamPCP ever detected it.

Risks and caveats

The two arrested Australians are not named, and no exact arrest date is given beyond "last month." The size of TeamPCP's inner circle and the group's total membership are not stated, nor is how the undercover operation ended or whether it was ever compromised. Technical detail on what the Dune-themed worm actually did, beyond automating the hacking process, is also absent from the source.

“So essentially, almost day one, Mandiant was watching everything behind the scenes.”

— Austin Larsen, Google Threat Intelligence Group researcher