谷歌威胁情报小组披露,其旗下安全子公司Mandiant的一名卧底分析师自TeamPCP活动初期就已渗透该黑客组织内部1。这个供应链攻击团伙通过感染数百个开源程序、盗取开发者账户,并发布了Dune主题的自传播蠕虫,最终突破超过1000家公司1。
谷歌通过追踪操作安全漏洞向执法部门提供了关键信息1。两名涉嫌领导TeamPCP的澳大利亚人上月在当地被逮捕并被控相关罪名1。此外,谷歌还从另一个网络犯罪集团ShinyHunters获得了情报,该组织曾与TeamPCP合作但随后背离了他们1。
Google's threat intelligence division has revealed that an undercover researcher successfully embedded within TeamPCP, a notorious hacking organization responsible for large-scale malware poisoning attacks across software supply chains.1 The analyst maintained an internal presence within the group from the early stages of TeamPCP's operations, providing critical visibility into the organization's activities.1
TeamPCP orchestrated a sophisticated campaign that infected hundreds of open-source programs and compromised developer accounts, ultimately breaching more than 1,000 companies.1 The group distributed a self-propagating Dune-themed worm as part of its attack infrastructure.1 Google leveraged its undercover intelligence to track operational security lapses by suspected leaders based in Australia, enabling the company to share crucial details with law enforcement.1 Two suspected members of TeamPCP were arrested in Australia last month and face charges related to the conspiracy.1
In addition to its direct infiltration, Google obtained intelligence from ShinyHunters, another prominent cybercriminal organization that had collaborated with TeamPCP before eventually severing ties with the group.1 This multi-faceted intelligence gathering approach allowed Google to disrupt the organization's attack attempts.
评论
还没有评论,欢迎留下第一条。