In a talk at SentinelOne's LABScon research conference, Google Threat Intelligence Group researcher Austin Larsen disclosed details of the company's investigation and infiltration of TeamPCP, a hacking group that tainted hundreds of open-source programs with malware, stole developer accounts, and released a self-spreading worm ultimately breaching more than a thousand companies.
According to Larsen, Google followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the group, passing key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another cybercriminal group that initially partnered with TeamPCP but later turned on the supply-chain hackers.
Most notably, Larsen said that Google's security subsidiary Mandiant had an undercover analyst within TeamPCP's inner circle from almost the beginning of the group's time in the spotlight, providing a unique vantage point on the rampage that security researchers have described as unlike any other in history.