Google Disrupted TeamPCP’s Ransom Campaign and Uncovered an AI-Assisted Zero-Day Exploit
Leaked chats reveal that the hacking group TeamPCP lost access to a major supply chain while Google worked to disrupt its campaign and protect targeted companies.
Google Found TeamPCP’s Stolen Credentials
Michael Fletcher, a former Australian Federal Police analyst who now works in the threat research division of an Australian telecommunications company, said he approached undercover Google analyst Larsen about monitoring TeamPCP’s members and activities.
Fletcher recalled that Larsen urged him to approach the hackers carefully because one member was considered “friendly.” A TeamPCP member later wrote in a leaked chat: “You have to understand that we’ve taken away our biggest supply chain.”
Larsen said he accessed a server where TeamPCP stored a large collection of stolen credentials from numerous victims. The usernames, passwords, and access tokens appeared to have been obtained through hacking and were intended to support blackmail attempts against targeted companies.
Google decided to act quickly to warn victims and disrupt TeamPCP’s ransom plan. “My thinking was, how can we disrupt their campaign as quickly as possible before further compromise occurs,” Larsen said. “Let’s screw up what they’re doing. That was my goal.”
Google Asked AWS and Microsoft to Revoke Compromised Credentials
Rather than contacting every affected company first, Google reached out to providers that could use the stolen credentials, including Amazon Web Services and Microsoft. Those providers could revoke the credentials and prevent the hackers from using them.
Larsen and his team sent hundreds of notification emails to the providers and then to the victims. Many of the companies responded immediately.
TeamPCP Used AI to Develop a Zero-Day Exploit
Google’s visibility into TeamPCP’s internal chats also revealed that someone in the group’s core circle was using AI tools to develop a zero-day exploit for widely used login software.
The exploit could bypass the software’s two-factor authentication and was separate from TeamPCP’s supply chain attacks. Google obtained a copy of the exploit code, tested it, and found that it worked with a few modifications.
The incident represents a rare example of an AI-assisted hacking technique exploiting a previously unknown software vulnerability. Google warned the software developers, who were able to fix the security flaw.
Google has released additional examples and threat-intelligence details about the incident, although the report does not explain how Google learned about the exploit or provide further details about TeamPCP’s involvement.
Source: arstechnica.com


