HeadlinesBriefing favicon HeadlinesBriefing.com

Google Infiltrated Team PCP Hacking Group

Ars Technica •
×

Google's Threat Intelligence Group revealed it had an undercover analyst inside the hacker group Team PCP during its unprecedented software supply-chain attack campaign. At Sentinel One's LABScon conference, researcher Austin Larsen detailed how Mandiant, Google's security subsidiary, infiltrated the group's inner circle "almost day one" via a persona that built trust with an actor invited to join. This access allowed Google to monitor attacks, warn victims, and disrupt exploitation attempts.

Team PCP, which emerged in late 2025, compromised hundreds of open-source programs—including Trivy, Lite LLM, Checkmarx, Tan Stack, and Mistral AI—to steal developer credentials and plant malware in a repeating cycle. The group breached over a thousand companies, including GitHub, Mercor, OpenAI, and the European Commission, often using a self-spreading worm dubbed Mini Shai-Hulud.

In late March, Australians Ruben Ian Thomson and Louis Michael Gaebler, both in their early 20s, were arrested by Australian Federal Police with FBI assistance and charged as "principal participants." Google identified them by tracking operational security mistakes and received intelligence from rival cybercriminal group Shiny Hunters, which had partnered with then turned on Team PCP.