• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Safety

Admin by Admin
August 28, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Authorities in Australia have arrested two males believed to be members of TeamPCP, a prolific cybercrime and information extortion group blamed for perpetrating the longest operating spree of software program provide chain assaults ever.

In an announcement launched in the present day, the Australian Federal Police (AFP) stated two males from Western Australia, aged 21 and 23, had been arrested in reference to a “refined cybercrime syndicate that allegedly created malicious open-source software program to rob 1000’s of worldwide companies.”

The AFP didn’t identify the defendants, however KrebsOnSecurity realized the 21-year-old suspect’s actual identification in June, and has been speaking with him ever since. This story consists of interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP chief that possible led to his undoing.

TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in tons of of open supply software program instruments and extorting victims for revenue. Members of the group made headlines by compromising company cloud environments utilizing a self-propagating worm dubbed Shai-Hulud, which added malicious code to open supply packages maintained by builders whose credentials at public code repositories like GitHub or NPM had been phished or stolen.

Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a sort of cyclical exploitation of software program builders.

“The hackers achieve entry to a community the place an open supply instrument generally utilized by coders is being developed,” Greenberg wrote in Could. “The hackers plant malware within the instrument that finally ends up on different software program builders’ machines, together with some who’re writing different instruments meant for use by coders. The malware permits TeamPCP’s hackers to steal credentials that allow them publish malicious variations of these software program growth instruments, too. The cycle repeats, and TeamPCP’s assortment of breached networks grows.”

TeamPCP additionally has practiced one thing akin to cyclical recruitment. In Could, the supply code for the third iteration of Shai-Hulud was printed on-line, and TeamPCP quickly after launched a contest providing $1,000 in digital foreign money to whichever participant might conduct the most important provide chain operation utilizing the worm’s code. In response to the competition guidelines, contributors had been scored based mostly on the variety of weekly and month-to-month downloads of packages they compromised — instantly incentivizing them to focus on the most well-liked code libraries.

A screenshot of a message from TeamPCP’s Telegram account, asserting the provision chain hacking contest. Picture: dataminr.com.

“TeamPCP has acknowledged the competitors is a recruiting alternative and so they intend to buy all significant entry harvested from contributors’ campaigns,” the safety agency Dataminr wrote. “The $1,000 XMR (Monero) prize is a recruitment ground and has been dismissed by the actor as ‘similar to participation trophy,’ including ‘if you happen to discover one thing good you may be paid far more,’ confirming the competition’s true operate as expertise identification and malicious entry acquisition at scale.”

In March, TeamPCP executed a provide chain assault focusing on AI infrastructure by compromising the code for LiteLLM, an open supply AI gateway that connects customers to greater than 100 completely different massive language fashions. A latest evaluation by the safety agency CloudSEK discovered TeamPCPs assault on LiteLLM harvested cloud service keys and different secrets and techniques from greater than 2,500 organizations, together with lots of the world’s prime expertise firms.

In Could, TeamPCP claimed credit score for compromising not less than 3,800 code repositories on the Microsoft-owned GitHub, after a GitHub developer put in a code extension that was compromised by TeamPCP’s malware.

MEET THE CYBERCATS

Safety consultants say TeamPCP is much less of a hacker group than an amalgamation of risk actors from a number of cybercriminal gangs who generally work collectively towards related targets.

“It’s not a structured legal crew with a single operator,” stated Austin Larsen, a principal risk analyst with the Google Risk Intelligence Group. “It’s a peer group of individually-skilled actors, with one clear heart of gravity.”

That heart of gravity is George Prepakis, an achieved safety researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this yr, @kernelstub tweeted a public invite hyperlink to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other different cybercrime entities have been utilizing this server to speak day by day for the previous a number of months.

A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles related to a number of distinct cybercrime teams which have often collaborated on a sequence of provide chain and information ransom assaults over the previous 9 months.

Kernelstub, like different directors within the Cybercats chat, has been utilizing his Twitter/X profile identify as his deal with in these Matrix communications, ceaselessly tweeting references to different members and to conversations going down within the Cybercats chat. In various circumstances, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly earlier than the incidents had been reported within the information media.

The Cybercats administrator listed on the prime of the screenshot above — “Boxturtle” — is a detailed affiliate of TeamPCP who has been tweeting concerning the group’s conquests below the identify @xpl0itrsturtle. This deal with corresponds to an information breach dealer lively on Breachforums and Darkforums who has been promoting information stolen in a wave of latest breaches at vehicle producers, together with BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, in addition to information allegedly taken from Snapchat and SportRadar.

The info leak web site for the extortion group or deal with “xpl0itrs.”

The Cybercats administrator “SeesawSec” within the screenshot above is the alias of whoever is behind the cybercrime group referred to as Fulcrumsec, which just lately claimed credit score for information extortion assaults in opposition to the pharmaceutical big Novo Nordisk, the information dealer LexisNexis, and Avnet, a Fortune 500 distributor of digital parts.

The info leak web site of Fulcrum Safety, a.ok.a. Fulcrumsec.

The Cybercats administrator “@pcpcasper” additionally has been utilizing an analogous identify on X to debate TeamPCP’s assaults and victims. This particular person has an in depth message historical past on Telegram, the place their messages and shared movies present @pcpcasper is an lively and vocal member of the Nationwide Socialist Community, a neo-Nazi political group based mostly in Australia.

At one level in these chats, @pcpcasper shared movies and pictures of what they claimed was their cat, and several other of these movies place this person in Western Australia. One supply near the investigation instructed KrebsOnSecurity that @pcpcasper was one of many two arrested, a declare supported by messages that @kernelstub posted on-line this morning.

The Cybercats member roster pictured above additionally options an administrator with the username “T,” which is brief for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested in the present day. As we’ll see in a second, @pcpcats is also from Western Australia.

By the point @kernelstub tweeted a public invite hyperlink to the Cybercats Matrix server, T/@pcpcats was posting solely occasionally to the group chat, with different members typically inquiring as to his whereabouts and well-being. The group’s collective concern associated to @pcpcats’s tendency responsible his more and more prolonged absences on using hallucinogens and different narcotics that stored him awake for days on finish, but in addition induced him to crash in mattress for a number of days after the highs wore off.

WHO IS THE TEAMPCP LEADER?

The Cybercats member @pcpcats has used a number of nicknames on the cybercrime boards, together with EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Categorical on Breachforums. These accounts are linked as a result of all of them marketed the identical Tox ID and/or Session ID as immediate message contact handles of their cybercrime discussion board posts. BulkDMT was additionally recognized on the boards as DMT Host, which was a digital non-public server (VPS) internet hosting service that was peddled on Darkforums and Breachstars.

DMT Host/EllisD25, posting on the English-language cybercrime group DarkForums in September 2025. Picture: ke-la.com.

In response to the cyber intelligence agency Intel 471, Categorical registered on Breachforums utilizing the e-mail tackle shitstickpp@gmail.com. Intel 471 finds Categorical posted on Breachforums throughout a two-month interval in 2025 utilizing 4 completely different Web addresses positioned in South Africa. On July 30, 2025, Categorical introduced on Breachforums they had been promoting entry to 14 gigabytes of information stolen from South Africa’s State Info Know-how Company.

The risk intelligence platform Flashpoint recorded greater than a yr’s price of messages from the TeamPCP chief’s alter ego on Telegram — Persy_PCP —  who claimed they break up their life dwelling between two nations [full disclosure: Flashpoint is an advertiser on this blog]. “I’ve these [files] as effectively, drawback is these are abroad,” Persy_PCP defined to a different person inquiring a few stolen information set in November 2025.

Later that month, Persy_PCP complained, “My entire nation is racist and so they need folks like me useless.” Flashpoint information present BulkDMT shared in September 2025 that “this nation goes to fucking starve after they take the farmers land,” a possible reference to white landowners in South Africa who declare to be focused by an ongoing genocide marketing campaign.

This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and cellular Web tackle connections to South Africa, “indicating the first operator was positioned there throughout not less than a few of its assaults.”

BulkDMT additionally shared on the group chat at Breachforums that they had been recovering from an dependancy to methamphetamine. “My life is kinda fucked rn [right now], however that’s advantageous and there isn’t actually some extent in pouring a lot emotional power into that truth, my dad and mom had cash however I sadly bought actually hooked on some issues so I don’t get to learn from that. So long as I proceed to outlive, keep sober, and transfer nearer in the direction of my targets that’s sufficient drive and which means.”

The identification risk safety firm SpyCloud finds shitstickpp@gmail.com reveals up within the registration of an account referred to as ChristmasSnow on the cybercrime group Raidforums in 2022. Practically all the Web addresses used to entry that account got here from ISPs in Perth, Australia, SpyCloud discovered.

KrebsOnSecurity seemed up all of these Perth IP addresses in passive DNS information maintained by DomainTools.com, and located one in every of them — 211.27.196.111 — for a number of years was used as a non-public file server by a household in Perth with the final identify of Thomson. These information present not less than three hosts — ithomson.direct.quickconnect.to (a distant Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP community storage machine) — persevered at that tackle between 2022 and 2025.

Looking out on “joshuathomson39” within the breach monitoring service Constella Intelligence reveals an account on the freight forwarding firm kwe.com created within the identify of Joshua Thomson from Perth, Australia. The open supply intelligence platform Epieos finds the telephone quantity connected to that kwe.com account was used to register a Fb profile for Josh Thomson, which says his household features a brother named Ruben, his father Ian, and his mother Cindy.

That Fb profile additionally says Josh and his household are initially from Pietermaritzburg, in KwaZulu-Natal, South Africa, however presently dwelling in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed 5 domains by the identical registrant, together with securecomputing.au, thomson.org.au, and thomsonfamily.internet.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The College of the Witwatersrand in Johannesburg, South Africa.

Constella finds a joshua@thomson.org.au registered various accounts on-line, however Josh doesn’t appear to have a lot of a connection to dodgy cybercrime boards. His brother Ruben, then again, has fairly the presence on these communities, courting again to not less than 2018. Constella reviews ruben@thomson.org.au ceaselessly reused the password “joshuathomson1,” and Constella additional finds that password was utilized by only a handful of accounts, together with yolosolo17@gmail.com and surfinup8@gmail.com.

In response to Intel 471, surfinup8@gmail.com was used to register the person Yolosolo17 on the crime discussion board Altenen in 2018, and that person account was registered from the Perth tackle 110.141.230.15. On Altenen, Yolosolo17 marketed free internet proxies, in addition to the area rubenthomson.com, which was at one level used to promote steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.

A cached copy of the area rubenthomson.com from 2017 reveals a login web page beneath a banded stack of cash. Picture: archive.org.

SpyCloud reviews 10.141.230.15 was utilized by the e-mail tackle sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the identical IP was utilized by the e-mail addresses ian@thomsonfamily.internet.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud additionally reveals that sheepstealing Gmail tackle is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as effectively Sheepx on Altenen.

Epieos reviews that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Net developer who went to highschool on the College of Western Australia and was dwelling exterior the nation. “Hey, I’m Ruben, my pals name me Ellis. I’m a Perth artistic who often books rooms when visiting household and for pictures.”

Epieos additionally finds sheepstealing@gmail.com registered an upwork.com profile below the identify Ruben, who stated his primary expertise are establishing safe server internet hosting options and PHP full-stack Net growth.

“I’m conversant in Linux, working with relational databases (SQL),” the Upwork profile reads. “I additionally script in Python primarily for writing social media bots.”

The Upwork profile for Ruben Thomson in Cottesloe, Australia.

Epieos additional found sheepstealing@gmail.com is related to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account referred to as XmasSnow/XmasSnowisBack that scammed folks on the boards in 2022 by claiming to promote unique exploits for recently-released software program patches (recall that shitstickpp@gmail.com was used to register a discussion board account named ChristmasSnow).

This identical sheepstealing e mail tackle registered a Twitter/X account in 2026 referred to as “Gone Fishing” that lists its location as South Africa. That Gmail account additionally left a number of critiques for companies listed on Google Maps over the previous seven years, however all of these institutions are positioned on the west coast of Australia.

Enterprise critiques in Western Australia left by the Google account sheepstealing at gmail.com.

The folks search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a telephone quantity ending in 979. A lookup on that quantity at Epieos reveals it’s related to a TikTok account below the identify Ellis, and to a PayPal account within the identify of Ruben Thomson.

Lastly, a search on the identify Ruben Thomson from Cottesloe on the Australian authorities’s document of registered companies finds he has included or served as an official in a number of firms created since 2024, together with Safe Computing Options, Tensor Industries, and one other entity satirically named OPSEC Categorical. Recall that Categorical was BulkDMT’s nickname on Breachforums.

Australian firms related to Ruben Thomson. Picture: abr.enterprise.gov.au.

It’s ironic as a result of OPSEC is brief for the time period “operational safety,” which refers to methods and behaviors used to obfuscate and compartmentalize one’s real-life identification on-line, and utilizing your cybercrime deal with as a part of your individual firm identify may be very a lot the antithesis of that apply.

There’s not less than one different main opsec failure by Ruben that uncovered a hyperlink to TeamPCP. In June 2025, somebody utilizing the identify Ruben Thomson registered on HackerOne, a preferred “bug bounty” program that seeks to reward and acknowledge researchers who conform to work with affected software program distributors to assist repair the failings earlier than publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by a number of safety companies as an alias utilized by TeamPCP.

The HackerOne profile for “Ruben Thomson” makes use of the nickname Deadcatx3, which a number of safety companies have concluded is an alias utilized by TeamPCP. Picture credit score: flare.io.

INTERVIEW WITH ELLIS

In early July 2026, not lengthy after having found clues about Ellis’s actual life identification, KrebsOnSecurity interviewed the TeamPCP chief through Sign, the place he was remarkably open about his actions and private struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].

Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — simply earlier than the assaults that compromised LiteLLM — and that not less than one different particular person has taken over the group’s management since then. Ellis shared {that a} yr earlier he had simply accomplished the newest in a sequence of detox and sobriety packages, and was two months sober when he reconnected with some outdated pals from the malware growth scene.

“One yr in the past I wanted assist monetizing some [GitHub credentials], I used to be two months sober and wanted a distraction and one thing to maintain busy in addition to folks to talk to,” Ellis stated. “I had largely disconnected from my outdated circle, they’d grow to be very poisonous and I wanted to get away from the substances. Beforehand I had accomplished some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There have been some pals who had been additionally merchandising however had stopped some time, and one in every of them launched me to some chats the place I posted entry on the market.”

Previous to that, Ellis stated, he was homeless and hopping between “some very unstable locations.”

“Blackhatting is enjoyable,” he stated. “There are precise rewards and incentives to be taught and also you develop together with your group. With out {qualifications}, no employer will even take the time to listen to you out.”

Ellis claims he’s earned a grand complete of about $20,000 for his actions with TeamPCP, and that it was by no means concerning the cash or fame for him. Requested whether or not his experiences with TeamPCP would possibly put together him for gainful employment in a official IT job, Ellis stated he doubted it.

“I’m nowhere near a talent stage the place I’m snug, and this could take perhaps half a decade of additional expertise,” he stated. “I not have to decide on between hire and meals for that I’m grateful and so are the group members.”

Ellis expressed no regret over his cybercrime actions, and stated he was grateful for the friendships and relationships constructed all through his engagement with TeamPCP. The younger hacker additionally appeared resigned to his destiny, and instructed KrebsOnSecurity that he’ll settle for the results if he’s ever arrested.

“If I’ve already been came upon then its out of my management, I’ll make peace with that,” he stated. “Truthfully, I believe somebody like me wants a number of assist that jail simply can’t present. If I had the funds to review completely different components of the sector and nearer steerage, this could have turned out in a different way. However that’s a pipe dream and we each know this.”

It’s clear from studying Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis instructed @kernelstub he was about to “journey” together with his “homie.”

“What form,” @kernelstub inquired.

“Ketty and a few DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a robust psychedelic compound that’s discovered naturally in some crops however can be synthetically produced in underground lab environments. “There’s somewhat 2cb so we’d throw that within the combine,” he continued, referring to one other psychedelic compound by its chemical shorthand.

Roughly two weeks earlier than his arrest, Ellis instructed KrebsOnSecurity he was prepared to go away his lifetime of crime behind and was ready to show himself in, however that within the meantime he was planning to tie up free ends.

Lower than 24 hours later, the TeamPCP chief posted a picture on Telegram exhibiting a yellowish powdered substance in a baggie and on a scale, probably artificial DMT. The picture reveals the powder being weighed subsequent to a sequence of small vape cartridges, two of that are open on the desk in entrance of the photographer.

A picture posted by the TeamPCP chief to Telegram, promoting his acquisition of some kind of psychoactive substance, almost certainly an artificial model of the highly effective hallucinogen referred to as DMT.

The 2 defendants had been arrested Wednesday morning. The AFP stated the boys face a mixed 14 cybercrime offenses and are scheduled to look in Perth Magistrates Court docket in the present day.

Charlie Eriksen is a safety researcher at Aikido Safety who has carefully adopted TeamPCP’s cybercrime campaigns. Eriksen stated TeamPCP are a great instance of a brand new sort of risk actor that doesn’t match neatly into the same old classes.

“They don’t seem to be a state actor, not fairly organized cybercrime, and never purely ideological,” he stated. “Their motivations appear to combine cash, disruption, consideration, and beliefs.”

Eriksen stated that traditionally there has all the time been a significant hole between studying about an assault method and with the ability to reliably flip it into an operational marketing campaign, however that giant language fashions (LLMs) and synthetic intelligence more and more are serving to risk actors to bypass that data hole.

“You needed to perceive the analysis, adapt the code, troubleshoot it, construct infrastructure round it, after which repeat that course of throughout completely different targets,” he stated. “LLMs have compressed that hole considerably.”

In response to Eriksen, this creates an surroundings the place risk actors instantly have the flexibility to function at important scale with out having developed the operational self-discipline that historically accompanies that stage of functionality. Put one other approach, it units the stage for cybercriminals who’re succesful sufficient to trigger important injury, however not essentially cautious sufficient to grasp or care concerning the penalties.

“They are often noisy, they’ll make errors,” he stated. “They’ll depart proof in every single place. They’ll take dangers {that a} skilled legal group or intelligence service would take into account fully unacceptable. However that doesn’t essentially make them much less harmful. In some methods, it could actually make them extra harmful.”

In a latest weblog submit, Eriksen referred to as TeamPCP’s Shai-Hulud worm the “neatest thing to occur to provide chain safety,” as a result of it compelled GitHub and different public coding platforms to erect new safety safeguards.

In direct response to TeamPCP’s broad success at pushing poisoned variations of common software program packages, GitHub in late July launched a three-day “cooldown” mechanism for Dependabot, the platform’s instrument for auto-fetching newly shipped updates for any bundle dependencies. Cooldown intervals are designed to assist purchase time for safety instruments and bundle maintainers to establish and take away any compromised variations. Different coding ecosystems like Python and varied JavaScript platforms additionally added help for cooldown intervals this yr amid rising calls from safety consultants concerning the want for extra widespread adoption of the security function.

Eriksen stated TeamPCP’s legacy is that they achieved within the span of some months what the provision chain safety group has been unable to do for years.

“They managed to get up Microsoft to the truth that they’d grow to be negligent by way of safety,” Eriksen stated. “By compromising GitHub and stealing their supply code, they humiliated Microsoft into motion, making them lastly act on what we had been asking them to do and take critically for some time now.”

Replace, 10:08 a.m. ET: A story this morning from ABC Information in Australia confirms Ruben Ian Thomson of Cottesloe was one of many two arrested. The 23-year-old suspect regarded as @pcpcasper, Michael Gaebler, additionally was arrested in Perth. ABC Information reviews that Thomson was denied bail (Mr. Gaebler’s legal professional reportedly didn’t request bail for his consumer), and that each males can be held in custody till their subsequent court docket look on September 18.



Tags: AllegedArrestedAustraliaHackersKrebsSecurityTeamPCP
Admin

Admin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
Prime AI Legacy System Modernization Firms in 2026

Prime AI Legacy System Modernization Firms in 2026

July 10, 2026
Discover a Software program Improvement Firm in Europe

Discover a Software program Improvement Firm in Europe

August 22, 2025
These 5 Easy Methods Helped Me Construct a Smarter House

These 5 Easy Methods Helped Me Construct a Smarter House

July 19, 2025
The right way to Create a Threat Administration Plan: Template, Key Steps

The right way to Create a Threat Administration Plan: Template, Key Steps

July 20, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Safety

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Safety

August 28, 2026
AWS Safety Groups Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Assaults

AWS Safety Groups Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Assaults

August 28, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved