Authorities arrest 2 alleged members of prolific hacking group TeamPCP

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

当局逮捕两名涉嫌隶属于高产黑客组织 TeamPCP 的成员

Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply-chain attacks that infected more than 1,000 organizations worldwide.

澳大利亚当局周三表示,他们逮捕了两名男子,指控其参与了黑客组织 TeamPCP 的网络犯罪活动。TeamPCP 是一个高产的黑客组织,在过去九个月中,该组织发动了一系列持续不断的供应链攻击,导致全球超过 1,000 家机构受到感染。

In a statement, the Australian Federal Police said the two men were arrested and charged with 14 offenses. The statement said the men were members of TeamPCP, which by the authorities’ count, compromised more than 1,000 organizations worldwide. The statement didn’t identify the men, except to say they lived in the Western Australian towns of Cottesloe and Mandurah.

澳大利亚联邦警察在一份声明中表示,这两名男子已被逮捕并被控 14 项罪名。声明称,这两人是 TeamPCP 的成员,据当局统计,该组织在全球范围内入侵了超过 1,000 家机构。声明未透露这两人的身份,仅表示他们居住在西澳大利亚州的科特斯洛(Cottesloe)和曼杜拉(Mandurah)。

KrebsOnSecurity, citing a lengthy investigation, provided what it reports to be both defendants’ names, along with an extensive background of their lives and the mistakes that led to their downfall.

KrebsOnSecurity 援引一项长期调查,公布了据称是两名被告的姓名,并详细介绍了他们的生活背景以及导致他们落网的失误。

The hacks that keep on hacking

持续不断的黑客攻击

TeamPCP has vexed law enforcement officials and security personnel around the world since it emerged in December. The group is best known for a sustained series of supply-chain attacks that laced open source software with malware that self-propagated from one package to another.

自去年 12 月出现以来,TeamPCP 一直令全球执法官员和安全人员感到头疼。该组织最出名的是其持续发动的一系列供应链攻击,通过在开源软件中植入恶意软件,使其能够在不同的软件包之间自我传播。

The viral infections worked by targeting organizations’ CI/CD pipelines, which are used to rapidly develop, update, and deploy software. Once a package or tool was compromised, Shai-Hulud, as the worm was dubbed, attached itself to future package updates. When developers downloaded the compromised packages and ran them through their own CI/CD platforms, their software was also compromised.

这种病毒式感染通过针对机构的 CI/CD 流水线(用于快速开发、更新和部署软件)进行运作。一旦某个软件包或工具被入侵,这种被称为“Shai-Hulud”的蠕虫病毒就会附着在未来的软件包更新中。当开发人员下载这些受感染的软件包并通过其 CI/CD 平台运行时,他们的软件也会随之被入侵。

Key to Shai-Hulud’s viral ability was a separate component that collected credentials for other packages in the memory of infected hardware. Once TeamPCP had the credentials, members used them to infect those packages. In one case, the group infected the Trivy vulnerability scanner. As reported earlier this month, the compromise went on to infect downstream packages, including KICS, the Telnyx Python SDK, and LiteLLM. Those packages were infected after their developers ran either the compromised versions of Trivy or another package that had.

Shai-Hulud 病毒传播能力的关键在于一个独立组件,它能在受感染硬件的内存中收集其他软件包的凭据。一旦 TeamPCP 获取了这些凭据,成员们就会利用它们去感染其他软件包。在一个案例中,该组织感染了 Trivy 漏洞扫描器。据本月初报道,此次入侵进一步感染了下游软件包,包括 KICS、Telnyx Python SDK 和 LiteLLM。这些软件包是在其开发人员运行了受感染的 Trivy 版本或其他受感染软件包后被感染的。

The initial Trivy compromise resulted in the theft of terabytes of credentials and other private data. Shai-Hulud employed an unconventional means for ensuring its channel for collecting credentials was immune to third-party takedowns. It used a form of smart contract known as an Internet Computer Protocol-based canister. The mechanism lets the worm find control servers using URLs that could be rapidly changed at any time. Infected machines reported to the canister once every 50 minutes.

最初的 Trivy 入侵导致了数 TB 的凭据和其他私密数据被窃取。Shai-Hulud 采用了一种非传统手段,确保其收集凭据的渠道免受第三方封杀。它使用了一种被称为“基于互联网计算机协议(ICP)的容器(canister)”的智能合约。该机制使蠕虫病毒能够使用可随时快速更改的 URL 来寻找控制服务器。受感染的机器每 50 分钟向该容器报告一次。

KrebsOnSecurity’s Brian Krebs said TeamPCP members lacked the operational discipline that usually accompanies a hacking group with its level of accomplishment. Citing Aikido Security researcher Charlie Eriksen, Krebs reported that traditionally, hackers at that level have had to spend considerable time researching various techniques, tailoring and troubleshooting code, and building the infrastructure to successfully carry out such campaigns.

KrebsOnSecurity 的布莱恩·克雷布斯(Brian Krebs)表示,TeamPCP 成员缺乏通常与该成就水平的黑客组织相匹配的操作纪律。克雷布斯援引 Aikido Security 研究员查理·埃里克森(Charlie Eriksen)的话报道称,传统上,达到这一水平的黑客必须花费大量时间研究各种技术、定制和调试代码,并构建基础设施才能成功实施此类攻击。

“LLMs have compressed that gap significantly,” Eriksen told Krebs.

“大语言模型(LLM)显著缩小了这一差距,”埃里克森告诉克雷布斯。

Australian authorities say that if convicted, one of the men faces more than 20 years in prison and that the other faces more than 10.

澳大利亚当局表示,如果罪名成立,其中一名男子将面临超过 20 年的监禁,另一名男子将面临超过 10 年的监禁。