Google’s undercover operation against TeamPCP exposed stolen credentials, a potential zero-day exploit and identifying clues that ultimately helped law enforcement arrest an alleged hacker.
Google’s Threat Intelligence team has revealed that, during a key moment in the hacking campaign carried out by TeamPCP, an undercover researcher infiltrated the group, allowing Google to monitor its activities. The researcher also tried to track its actions, warn potential victims, and disrupt the group’s attempts to exploit them.
According to Austin Larsen, the researcher who went undercover, Google followed a trail of operational security lapses allegedly made by one of the two Australians now accused of being part of the hacker group and passed key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that had partnered with TeamPCP but later turned on the supply-chain hackers.
Larsen said he was able to gain access to a server where TeamPCP was storing a trove of credentials stolen from its victims, including usernames, passwords, and access tokens obtained through hacking. Google then used the information to warn victims and disrupt TeamPCP’s attempts to exploit the stolen credentials.
A bigger threat
Google’s visibility into the group’s activities also revealed that someone within TeamPCP’s core circle had a separate identity and was using an AI tool to develop a zero-day exploit targeting widely used login software. The exploit could have allowed the hackers to bypass two-factor authentication.
Google acted quickly, recovering the code and developing a hacking technique that took advantage of the previously unknown software vulnerability.
ShinyHunters had initially worked with TeamPCP but later began carrying out its own extortion operations, allegedly using TeamPCP’s stolen credentials without giving the group a cut.
Further cyber detective work helped Larsen identify Thomson, one of the alleged hackers playing a key role in TeamPCP. Investigators were eventually able to link a key hacker to a Gmail account and discovered that the group’s stolen credentials were being backed up to a Google Drive associated with the account. The findings were passed to the FBI, and about a month later, Australian police arrested the alleged hacker.
Click Here For The Original Source.
