ZeroHour
Story · 2 sources · 2 articlesfirst updated ()1

Google reveals undercover Mandiant analyst infiltrated TeamPCP as Mandiant warns of runaway AI agent risks

highThreat actorexploited in the wildimportance 82
What's new: First merged summary for this story: Mandiant published its AI Risk and Resilience report (reported 2026-09-16), and Google disclosed at LABScon (reported 2026-09-18) that a Mandiant analyst had infiltrated TeamPCP since March 2026, leading to credential revocation warnings to AWS and Microsoft, disruption of the gang's extortion plans, and the arrest in Australia of alleged leaders Ruben Ian…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Google Threat Intelligence Group disclosed that a Mandiant undercover analyst joined the roughly 12-member inner circle of supply chain hacking gang TeamPCP (UNC6780) in March 2026, helping warn hundreds of victims and disrupt extortion, while Mandiant's new…

Two linked Google/Mandiant disclosures cover the same threat actor, UNC6780 (TeamPCP). At LABScon, Google Threat Intelligence Group (GTIG) revealed that a Mandiant undercover analyst infiltrated TeamPCP's roughly 12-member inner circle in March 2026, monitoring the group's CanisterWorm chat and a server of stolen credentials. TeamPCP compromised open source projects including Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI, and its self-spreading Mini Shai-Hulud worm breached more than 1,000 companies. Google urged credential providers such as AWS and Microsoft to revoke stolen usernames, passwords, and access tokens, disrupting the group's planned extortion scheme, and alleged leaders Ruben Ian Thomson and Louis Michael Gaebler were arrested in Australia with FBI assistance. Separately, Mandiant's AI Risk and Resilience report — drawing on GTIG observations — warns that poisoned data sources, model dependencies, and extension hooks can turn AI agents into channels for reconnaissance, lateral movement, and sandbox escape, with prompt injection remaining the primary attack vector in enterprise AI deployments. The report ties TeamPCP to the theft of AI service credentials and prompt injection attacks against AI coding assistants. It also describes red team tests in which an AI assistant was manipulated into cloning internal repositories to an external GitHub account, and a runaway accounting agent that made over 15,000 costly API calls in under an hour, generating roughly $50,000 in cloud charges. GTIG separately disclosed the first confirmed criminal use of an AI-developed zero-day exploit in a planned mass exploitation campaign.

  • A Mandiant undercover analyst joined TeamPCP's (UNC6780) roughly 12-member inner circle in March 2026, monitoring the group's CanisterWorm chat and its server of stolen credentials.
  • TeamPCP compromised open source projects including Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI.
  • TeamPCP's self-spreading Mini Shai-Hulud worm breached more than 1,000 companies.
  • Google warned credential providers such as AWS and Microsoft to revoke stolen usernames, passwords, and access tokens, disrupting TeamPCP's planned extortion scheme and enabling warnings to hundreds of victims.
  • Alleged TeamPCP leaders Ruben Ian Thomson and Louis Michael Gaebler were arrested in Australia with FBI assistance.
  • Mandiant's AI Risk and Resilience report warns that poisoned data sources, model dependencies, and extension hooks can turn AI agents into channels for reconnaissance, lateral movement, and sandbox escape; prompt injection remains the…
  • UNC6780 (TeamPCP) stole AI service credentials and used prompt injection against AI coding assistants.
  • GTIG disclosed the first confirmed criminal use of an AI-developed zero-day exploit in a planned mass exploitation campaign.

Coverage timeline

  1. · 2d ago
    Help Net Security· 68
    One runaway AI agent racked up a $50,000 cloud bill

    Mandiant's AI Risk and Resilience report details prompt injection, AI supply chain compromises, agent abuse, and a runaway agent that accrued $50,000 in cloud charges.

  2. · 3h ago
    WIRED · Security· 82
    An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

    Google revealed a Mandiant undercover analyst infiltrated TeamPCP, letting it warn hundreds of victims and disrupt the gang's supply chain attacks and extortion.