An undercover Google analyst infiltrated a notorious supply-chain hacking gang



“You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in the leaked chats.

Michael Fletcher, a former AFP analyst who now works in the threat research division of an Australian telecom firm, says he approached Larsen around that time about methods for monitoring the group’s members and activities. He says that Larsen responded by asking Fletcher to approach the hackers with caution because one of them was a “friendly,” Fletcher remembers. “I thought, damn, you all have been inside this early,” he says.

Google’s undercover analyst, Larsen says, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims: the usernames, passwords, and access tokens it had obtained through its hacking and seemingly planned to use to extort target companies. So Google’s team decided to take action to warn victims and prevent TeamPCP’s ransom scheme. “My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?” Larsen says. “Let’s go mess up what they’re doing. That was my goal.”

Rather than focus on alerting the owners of the stolen credentials at victim companies directly, which Larsen says would have taken too long given the sheer number of breached companies, Google first reached out to providers where those credentials could be used, like Amazon Web Services and Microsoft, to have the credentials revoked and prevent the hackers from exploiting them. Larsen and his team sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses.

Around the same time, Larsen says, Google’s visibility into the TeamPCP internal chat also allowed it to learn that someone within the group’s core circle was, distinct from the group’s supply-chain hacking, using an AI tool to develop a zero-day exploit in a widely used piece of login software that would allow the hackers to bypass its two-factor authentication. Google’s team got a copy of the exploit code, tested it out, and found that, with a few tweaks, it worked—a rare instance of an in-the-wild AI-created hacking technique that took advantage of a previously unknown software vulnerability. Google warned the software’s developer, who was able to patch its security flaw. (The incident was described in a case study Google released in May, but without naming TeamPCP or detailing how Google learned about the exploit.)



Source link

  • Related Posts

    All roads lead to cable

    This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on streaming platforms, FAST channels, and the future of entertainment, follow Charles…

    Continue reading
    Don’t call it an SUV: The Ferrari Purosangue review

    Ferrari’s two-seat sports cars might be the brand’s identity, but the Italian automaker has always catered to customers who want to bring more than one passenger along for the ride.…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    ‘They didn’t want me, I didn’t want them:’ Florida’s Jon Sumrall says he had no interest in Auburn job after Gators’ win over Tigers

    ‘They didn’t want me, I didn’t want them:’ Florida’s Jon Sumrall says he had no interest in Auburn job after Gators’ win over Tigers

    She cheered a teen protest against ICE. Police charged her with a crime.

    She cheered a teen protest against ICE. Police charged her with a crime.

    Mailbox: Wordcrafting, Backtracking, One-Handed Titles – Nintendo Life Letters

    Mailbox: Wordcrafting, Backtracking, One-Handed Titles – Nintendo Life Letters

    All roads lead to cable

    All roads lead to cable

    Delta Honors "Ridiculously Low" $17.34 Upgrade To Delta One On 15-Hour Seoul Flight

    Delta Honors "Ridiculously Low" $17.34 Upgrade To Delta One On 15-Hour Seoul Flight

    Paolo Carzana Spring 2027 Ready-to-Wear Runway, Fashion Show & Collection Review

    Paolo Carzana Spring 2027 Ready-to-Wear Runway, Fashion Show & Collection Review