Victims and investigators gained an inside view of TeamPCP after an undercover researcher embedded in the group's inner circle enabled Google to monitor the crew's supply-chain campaign, warn breached organisations, and hand identifying leads to law enforcement.

TeamPCP carried out a sprawling operation that altered many open-source projects to deliver malware, took over developer accounts to spread that malicious code, and deployed a Dune-themed self-propagating worm to automate infections, ultimately compromising more than a thousand companies. Two people alleged to be members of the gang were arrested in Australia last month.

Google's Threat Intelligence Group says its investigation traced operational security errors to one of the two Australians now accused of leadership, and the company passed those identifying details to police. The firm also received intelligence from ShinyHunters, a separate cybercrime group that had cooperated with TeamPCP before turning against it and sharing information.

Google's account of its role adds another layer: the company says its security subsidiary, Mandiant, had an undercover analyst inside TeamPCP's inner circle almost from the group's first public activity. That presence, together with the Threat Intelligence Group's monitoring, let Google intervene by notifying targets and attempting to hamper the group's exploitation efforts.

Google Threat Intelligence researcher Austin Larsen is set to lay out the investigation and the infiltration in a talk at SentinelOne's LABScon conference. The presentation promises further detail on how private-sector undercover work and intelligence from rival cybercriminals combined to expose tradecraft and produce leads for law enforcement.