An undercover Google analyst infiltrated a notorious supply-chain hacking gang
摘要
谷歌威胁情报团队披露,其一名卧底研究员曾潜入黑客组织TeamPCP内部。该组织此前通过污染开源软件、窃取开发者账号等方式发动供应链攻击,并传播自复制蠕虫,波及逾千家企业。谷歌借此从内部监控攻击活动,向受害目标发出预警,并协助干扰其攻击行为。谷歌还根据该组织成员的操作安全失误线索,向执法部门提供了关键身份信息。两名疑似核心成员已于上月被澳大利亚逮捕并起诉。
Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.
Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.
In a talk at security firm SentinelOne's LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply-chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight.
转载信息
评论 (0)
暂无评论,来留下第一条评论吧