Inside the Infiltration: How a Google Mole Took Down the Notorious TeamPCP Cyber Gang
In one of the most audacious cyber-espionage operations of recent years, an undercover Google analyst penetrated the inner circle of TeamPCP, the hacking group responsible for an unprecedented global supply-chain attack spree. The infiltration allowed Google’s threat intelligence division to monitor the chaos in real-time, proactively warn hundreds of victims, and ultimately assist law enforcement in arresting two of the group's alleged leaders in Australia. This marks a significant escalation in how private cybersecurity firms are moving from passive reporting to active disruption of criminal hacking operations.
Before the dust settled and two young Australians were charged by federal police, the hacker collective known as TeamPCP had carved its name into the history books of cybersecurity. Their campaign was not merely a single data breach; it was a cascading, self-perpetuating nightmare that tainted hundreds of open-source programs, hijacked developer accounts, and unleashed a self-spreading worm inspired by the *Dune* universe. At the peak of this hacker group’s rampage, however, Google was watching every move from the inside, turning the tables on a gang that thought it was untouchable.
The Rise of TeamPCP and the Supply Chain Pandemic
TeamPCP, which seemingly materialized online in late 2025, quickly distinguished itself by the sheer scale and brazenness of its attacks. Unlike traditional hacking groups that breach a single network and extort the owner, TeamPCP executed a sophisticated "cascading" supply-chain attack strategy. The modus operandi was simple yet devastatingly effective: they would compromise an open-source software tool, embed malware within it, and then use that tainted tool to hijack the credentials of software developers. With those stolen identities, they would poison the next popular application in the chain, repeating the cycle to cast an ever-widening net.
This hacking spree included compromises of high-profile targets such as the security scanner Trivy, the AI tool LiteLLM, the web application security firm Checkmarx, the library TanStack, and the enterprise AI platform Mistral AI. This relentless wave of supply-chain attacks ultimately allowed the group to breach the open-source code repository GitHub, data contracting firm Mercor, and even employee devices at OpenAI and the European Commission. The scale of the data breach was staggering, affecting more than a thousand companies globally and exposing over half a million user credentials.
To automate their mayhem, the group deployed a worm dubbed "Mini Shai-Hulud," a nod to the sandworms from Frank Herbert’s sci-fi classic *Dune*. This malware allowed TeamPCP to scale its operations exponentially, spreading laterally across networks without requiring constant human intervention. It was a period of unprecedented vulnerability for the software ecosystem, leaving security researchers scrambling to understand the scope of the breach.
Google’s Mole: A Fly on the Wall in CanisterWorm
As detailed by Austin Larsen of Google’s Threat Intelligence Group at the LABScon security conference, the turning point came in March. Just as TeamPCP was igniting its supply-chain fuse, Google’s security subsidiary, Mandiant, had an undercover analyst embedded within the group. Speaking with WIRED, Larsen revealed that the mole had spent months building trust with a key actor, eventually gaining access to "CanisterWorm," the group’s core inner-circle chat that contained approximately twelve members.
“One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen explained. “So essentially, almost day one, Mandiant was watching everything behind the scenes.” This unprecedented access meant that Google had a front-row seat to the hackers’ operational security, their stolen credential troves, and their strategic decisions. The undercover analyst acted as a passive observer, never engaging in illegal hacking or encouraging breaches, adhering to strict "guardrails" regarding what constitutes acceptable surveillance.
This insider position provided crucial intelligence, including the location of a server where TeamPCP stored the vast haul of passwords, usernames, and access tokens—the hackers’ leverage for extortion plots. Rather than simply logging the information, Larsen’s team pivoted to an offensive disruption strategy. They bypassed the arduous process of contacting each of the over 1,000 breached companies by instead sending hundreds of notifications to credential providers like Amazon Web Services and Microsoft, effectively forcing the revocation of stolen tokens and locking the hackers out of their own spoils before they could cash in.
AI Zero-Days and Cybercriminal Betrayals
Google’s view inside the chat also exposed a more experimental threat: a member of TeamPCP was using an AI tool to develop a zero-day exploit targeting a widely used login software framework. The exploit was designed to bypass two-factor authentication. Google’s team obtained a copy of the code, tested it, and discovered that with minor tweaks, it was functional—a rare instance of an AI-created hacking technique exploiting a previously unknown vulnerability in the wild. Google alerted the software developer, who patched the flaw before it could be weaponized against the broader public.
The operation took another bizarre twist when TeamPCP, struggling to monetize their enormous trove of stolen data (earning only tens of thousands of dollars compared to the millions typical of such groups), partnered with external criminal entities. They invited the infamous ShinyHunters group to collaborate, offering a cut of extortion profits in exchange for monetization expertise. However, the partnership soured quickly. ShinyHunters turned rogue, using the credentials for their own extortion schemes and withholding TeamPCP’s share. In a stunning breach of cybercriminal etiquette, ShinyHunters even shared a full log of TeamPCP’s internal chat with Google’s Larsen, unaware that he already possessed similar access via the mole.
This betrayal led TeamPCP to purge their inner circle, exiling ShinyHunters and inadvertently kicking Google’s undercover analyst out of the chat. Despite losing the insider source, Larsen turned to "old school" digital detective work. By combing through leaks and forum archives, he traced a Gmail address to a PayPal account linked to a user named "sheepstealing," ultimately identifying Ruben Ian Thomson. The trail ended when TeamPCP moved their server and backed up illicit material to a Google Drive tied to Thomson’s personal email—a fatal operational security blunder that triggered the tip-off to the FBI.
Conclusion
The arrest of Ruben Ian Thomson and Louis Michael Gaebler, both in their early twenties, represents a significant victory for the cybersecurity community. It demonstrates a new, aggressive frontier in cyber defense, where private entities like Google are no longer just writing threat reports but are actively engaging in disruption operations. The infiltration of TeamPCP highlights the fragile ecosystem of cybercrime, where trust is fleeting and even the most sophisticated hacking groups are vulnerable to the very espionage tactics they employ. As Google’s Cyber Disruption Unit takes a more active role, the narrative has shifted from passive defense to proactive offense, signaling a new era in the war against hacking gangs. For security researchers and tech enthusiasts, the story of TeamPCP serves as a masterclass in how modern cybersecurity resilience requires not just better code, but intelligence, infiltration, and international cooperation.