Abstract:
The Google Threat Intelligence Team recently revealed at a security conference that security researchers from Mandiant, a Google subsidiary, had secretly lurked into the core chat group of the hacker team TeamPCP and continued to monitor the hacker team's large-scale supply chain attacks against the open source software ecosystem. Since it is undercover, of course it also has the advantage of being undercover. Before the hacker launched the attack, Google had already assisted the affected enterprises and cloud service providers in handling the stolen credentials in advance.

Create a virtual character to gain the trust of hackers:
This security researcher was assigned by Google to lurk in a hacker group. For this purpose, the team spent time building a virtual character and interacting with a hacker to build trust. The hacker was invited to join the TeamPCP team. Based on this layer of trust, the undercover analyst of the Google team was also successfully accepted and entered the core chat group.
There are 12 people in this core chat group, which mainly discuss the progress of the attack, successfully stolen data, and the development of subsequent extortion plans. The worm developed by TeamPCP can infect a large number of applications in a short period of time and steal sensitive enterprise data, and then extort the sensitive data from the enterprise. If the enterprise does not pay the ransom, the sensitive data may be disclosed.
Become an insider and steal hacker data and notify AWS to revoke the leaked credentials:
In this offensive and defensive battle, an analyst from the Google security team played the role of an insider. The analyst discovered that hackers stored a large number of usernames, passwords and access credentials centrally in the server. Relevant clues were reported to the Google security team. The Google security team did not notify the affected companies one by one (because it was too inefficient), but directly contacted Amazon AWS to revoke all compromised credentials in batches.
After completing the certificate revocation, Google then began to send emails to the victim company to help the victim company quickly complete the credential rotation and tighten access rights, so that hackers can no longer access the victim company's internal facilities and steal data through the leaked credentials. Undercover analysts were never involved in launching the attack, and the undercover operation helped Google gather more internal information about TeamPCP.
The arrest of two core members is also related to the undercover:
It is worth noting that Google revealed that undercover analysts provided clues related to suspected members to law enforcement agencies based on hackers' operational mistakes in internal chat groups. It should be noted that TeamPCP members also communicate through the Internet. These members are scattered in various countries and the members do not know each other's true identity.
The FBI and the Australian police earlier cooperated to arrest two core members of TeamPCP in Australia. Although Google did not elaborate, there is a high probability that the arrest of these two core members should be related to undercover analysts.
Comments