Trending: On-device modelsSearch
iHeartGeek
iTECH

Google spent months inside the TeamPCP hacking gang

A Mandiant analyst spent months inside the supply-chain gang's core chat, letting Google warn victims and helping build the case against two men charged in Australia.

A lone analyst silhouetted against a wall of glowing monitors showing cascading code in a dark operations room

Google had somebody inside one of the most damaging hacking crews of the year, and it was in there almost from the start. Speaking at the LABScon security conference on 18 September, Google Threat Intelligence Group researcher Austin Larsen revealed that a Mandiant undercover analyst spent months building trust with an operator who was about to join TeamPCP, and was added to the group alongside him.

What the mole could see

According to Larsen, the analyst was one of roughly a dozen people with access to TeamPCP's core chat, a room the crew called CanisterWorm. "One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group," he said. "So essentially, almost day one, Mandiant was watching everything behind the scenes."

Inside that room sat a server holding credentials stolen from victim companies, which the group appeared to be stockpiling for an extortion drive. Instead of contacting every breached business one at a time, Google went to the platforms where stolen keys and tokens get spent, sending hundreds of notifications so that providers including Amazon Web Services and Microsoft could revoke the credentials before the hackers cashed them in.

The supply-chain spree

TeamPCP appeared online in late 2025 and turned open-source software into a repeating weapon. The crew compromised the security scanner Trivy, the AI API tool LiteLLM, infrastructure at the web application security firm Checkmarx, the web app library TanStack and the enterprise AI platform Mistral AI, then used the developer credentials it harvested to plant code in whatever came next. The chain reached GitHub, the data contractor Mercor, employee devices at OpenAI and the European Commission, and at one point the group ran a self-spreading worm called Mini Shai-Hulud, named after the sandworms in Frank Herbert's Dune.

In late August the Australian Federal Police charged two West Australian men, Ruben Ian Thomson and Louis Michael Gaebler, both in their early twenties, with a combined 14 offences after searches in Perth carried out with the FBI and Western Australia Police Force. The AFP described them as principal participants in a syndicate that allegedly slipped malicious code into open-source software later used by government, academia and private industry.

An exploit written with an AI tool

The chatter also revealed something the industry has been waiting for. Larsen says a member of the group's inner circle was using an AI tool to develop an exploit for widely used login software, aimed at bypassing two-factor authentication. Google obtained the code, tested it and found it worked with a few tweaks, then warned the software's maker, which patched the hole. The company published a case study about the technique in May without naming the group behind it.

Larsen says Google also traced operational security mistakes made by one of the men now charged and passed identifying details to law enforcement, while taking intelligence from ShinyHunters, a rival crew that partnered with TeamPCP and later turned on it. Australian police say the syndicate's haul ran to more than half a million sets of user credentials.

Our opinion

The most effective security operation described this year was not a machine reading a trillion log lines. It was a person sitting quietly in a criminal group chat for months, and that is an awkward fact for an industry that keeps buying dashboards. Google's disclosure also confirms that the AI-written exploit has quietly arrived: not a doomsday scenario, just an operator who shortened a tedious job and produced code that a patch eventually closed. The money tells the other half of the story. Half a million stolen credentials and only tens of thousands of dollars in extortion payments is a failure of criminal business planning, not a reason to relax, because those credentials stay dangerous in the hands of whoever buys them next. Two arrests in Perth do not fix that. Only rotating and retiring what was stolen will, and almost nobody does it fast enough.