An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
一名谷歌卧底分析师渗透了一个臭名昭著的供应链黑客组织
Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.
在上个月该组织的两名涉嫌成员在澳大利亚被捕并受到指控之前,这个名为 TeamPCP 的黑客组织进行了一场史上罕见的黑客攻击狂潮。他们用恶意软件污染了数百个开源程序,窃取开发者账户以持续进行软件供应链攻击,甚至发布了一种以《沙丘》(Dune)为主题的自我传播蠕虫病毒来自动化这一过程,最终入侵了超过一千家公司。
Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.
现在,谷歌威胁情报小组透露,在 TeamPCP 疯狂作案的关键时刻,该公司的一名卧底研究员已经渗透进了该组织——这使得谷歌能够从内部监控其黑客行为,向被入侵的目标发出警告,甚至帮助挫败该组织利用这些受害者的企图。
In a talk at security firm SentinelOne’s LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply-chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement.
在今天安全公司 SentinelOne 举办的 LABScon 研究会议上,谷歌威胁情报小组的研究员奥斯汀·拉森(Austin Larsen)将详细介绍该公司在 TeamPCP 前所未有的混乱供应链黑客攻击活动中,对其进行的调查和渗透过程。据拉森称,谷歌最终追踪了该黑客组织两名主要嫌疑人之一所犯下的操作安全错误,并将关键的身份识别细节移交给了执法部门。
The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight.
该公司还从另一个臭名昭著的网络犯罪组织 ShinyHunters 那里获得了情报。TeamPCP 曾与该组织合作,但后来 ShinyHunters 反戈一击,转而对付这些供应链黑客。最令人惊讶的是,拉森表示,谷歌旗下的安全子公司 Mandiant 在 TeamPCP 受到关注的初期,就已经有一名卧底分析师(并非他本人)潜伏在该组织的核心圈子中。
“One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen told WIRED in an interview ahead of his LABScon talk. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”
“我们的一个虚拟身份花了几个月的时间与一名受邀加入 TeamPCP 的成员建立信任,并因此被拉入了该组织,”拉森在 LABScon 会议前的采访中告诉《连线》(WIRED)杂志。“所以从本质上讲,几乎从第一天起,Mandiant 就在幕后注视着一切。”
The TeamPCP Mole / TeamPCP 的内鬼
Last month, Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early twenties, were arrested by Australian police in a joint investigation with assistance from the FBI, charged with hacking crimes, and described by the Australian Federal Police (AFP)—in a press release that, due to Australian privacy laws, did not name them—as “principal participants” in TeamPCP.
上个月,两名二十出头的澳大利亚人鲁本·伊恩·汤姆森(Ruben Ian Thomson)和路易斯·迈克尔·盖布勒(Louis Michael Gaebler)在澳大利亚警方与联邦调查局(FBI)的联合调查中被捕,并被控犯有黑客罪。澳大利亚联邦警察(AFP)在一份新闻稿中将他们描述为 TeamPCP 的“主要参与者”(由于澳大利亚隐私法,新闻稿中未提及他们的姓名)。
The hacker group, which seems to have first appeared online in late 2025, had made headlines with a brazen string of cascading supply-chain attacks: It repeatedly compromised open-source software to hide its malware, which then allowed it to hijack the credentials of software developers and plant its malicious code in yet another widely used tool, in a repeating cycle.
该黑客组织似乎于 2025 年底首次出现在网络上,并因一系列厚颜无耻的级联供应链攻击而登上头条:他们反复入侵开源软件以隐藏其恶意软件,随后利用这些软件劫持软件开发者的凭据,并将恶意代码植入到另一个广泛使用的工具中,形成了一个循环。
Starting this spring, for instance, TeamPCP compromised the open-source security scanner Trivy, the AI application programming interface tool LiteLLM, infrastructure of the web application security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. Those repeated supply-chain attacks, with each enabling the group to cast its net again for more victims, ultimately allowed the hackers to breach open-source code repository Github, data contracting firm Mercor, and employee devices at OpenAI, the European Commission, and many others who have remained unnamed in public reporting.
例如,从今年春天开始,TeamPCP 入侵了开源安全扫描器 Trivy、AI 应用程序接口工具 LiteLLM、Web 应用安全公司 Checkmarx 的基础设施、Web 应用库 TanStack 以及企业级 AI 平台 Mistral AI。这些反复的供应链攻击使该组织能够不断扩大受害者范围,最终让黑客入侵了开源代码库 Github、数据承包公司 Mercor,以及 OpenAI、欧盟委员会等机构的员工设备,还有许多未在公开报道中提及的受害者。
At times, the group deployed a worm known as Mini Shai-Hulud, named after the sandworms in Dune, to automate its hacking and scale up to even more victims. (The name also seemed to refer to an earlier Shai-Hulud worm that hackers designed to try a similar approach in September 2025, though it’s still not clear if TeamPCP or any of its alleged members were involved in that earlier intrusion campaign.)
有时,该组织会部署一种名为“Mini Shai-Hulud”的蠕虫病毒(以《沙丘》中的沙虫命名),以自动化其黑客攻击并扩大受害者规模。(这个名字似乎也指代 2025 年 9 月黑客为尝试类似方法而设计的早期 Shai-Hulud 蠕虫,尽管目前尚不清楚 TeamPCP 或其任何涉嫌成员是否参与了那次早期的入侵活动。)
Larsen now says that in March, just as TeamPCP was beginning its frenzied supply-chain hacking, Google’s own undercover analyst was invited to join the hackers’ inner circle. That inside source, whose name Larsen declined to reveal, was one of about 12 members of the group given access to a core chat that TeamPCP called CanisterWorm.
拉森现在表示,今年 3 月,就在 TeamPCP 开始其疯狂的供应链黑客攻击时,谷歌的卧底分析师受邀加入了黑客的核心圈子。这位拉森拒绝透露姓名的内部人士,是该组织约 12 名能够访问名为“CanisterWorm”核心聊天室的成员之一。
“You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in the leaked chats.
“你们应该明白,我们完成了现代史上可能是有史以来最大规模的供应链攻击,”一名 TeamPCP 成员在泄露的聊天记录中写道。
Michael Fletcher, a former AFP analyst who now works in the threat research division of an Australian telecom firm, says he approached Larsen around that time about methods for monitoring the group’s members and activities. He says that Larsen responded by asking Fletcher to approach the hackers with caution because one of them was a “friendly,” Fletcher remembers. “I thought, damn, you all have been inside this early,” he says.
曾任澳大利亚联邦警察分析师、现就职于一家澳大利亚电信公司威胁研究部门的迈克尔·弗莱彻(Michael Fletcher)表示,他当时曾就监控该组织成员和活动的各种方法与拉森进行过接触。他回忆说,拉森当时回应称,请弗莱彻在接触这些黑客时要谨慎,因为其中一人是“友军”。“我当时心想,天哪,你们竟然这么早就渗透进去了,”他说。
Google’s undercover analyst, Larsen says, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims: the usernames, passwords, and access tokens it had obtained through its hacking and seemingly planned to use to extort target companies. So Google’s team decided to take action to warn victims and prevent TeamPCP’s ransom scheme. “My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?” Larsen says. “Let’s go mess up what they’re doing. That was my goal.”
拉森说,谷歌的卧底分析师获得了一台服务器的访问权限,TeamPCP 将从众多受害者那里窃取的凭据存储在那里:包括通过黑客攻击获得的用户名、密码和访问令牌,他们似乎计划利用这些信息勒索目标公司。因此,谷歌团队决定采取行动,警告受害者并阻止 TeamPCP 的勒索计划。“我的想法是:我们如何能在更多损害发生之前,尽快破坏他们的行动?”拉森说。“我们要去搞砸他们的计划。这就是我的目标。”
Rather than focus on alerting the owners of the stolen credentials at victim companies directly, which Larsen says would have taken too long given the sheer number of breached公司的数量,谷歌首先联系了可以使用这些凭据的服务提供商,如亚马逊云科技(AWS)和微软,要求撤销这些凭据,防止黑客利用它们。拉森和他的团队向这些服务提供商发送了数百封通知邮件,随后又通知了受害者,其中许多都得到了即时的回应。
Rather than focus on alerting the owners of the stolen credentials at victim companies directly, which Larsen says would have taken too long given the sheer number of breached companies, Google first reached out to providers where those credentials could be used, like Amazon Web Services and Microsoft, to have the credentials revoked and prevent the hackers from exploiting them. Larsen and his team sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses.
拉森表示,与其直接提醒受害公司的凭据所有者(考虑到被入侵公司的数量之多,这样做太耗时),谷歌首先联系了可以使用这些凭据的服务提供商,如亚马逊云科技(AWS)和微软,要求撤销这些凭据,防止黑客利用它们。拉森和他的团队向这些服务提供商发送了数百封通知邮件,随后又通知了受害者,其中许多都得到了即时的回应。
Around the same time, Larsen says, Google’s visibility into the TeamPCP internal chat also allowed it to learn that someone within the group’s core circle was, distinc…
拉森说,大约在同一时间,谷歌通过对 TeamPCP 内部聊天记录的监控,还了解到该组织核心圈子里的某个人正在……(注:原文此处中断)