Skip to content
DnsLister Forum

Where domain hunters compare notes

Walkthrough: deanonymizing the operator behind the Trivy/LiteLLM supply chain compromises

Our Emerging Threats Team put together a walkthrough of the attribution process behind the individual arrested and accused of being behind TeamPCP.

The pivot chain, briefly:

  • Seed was the handle DeadCatx3, reused verbatim outside the group's operational channels
  • Username enumeration surfaced a HackerOne account under a real name, plus a Hugging Face profile listing the group's own C2 domain (masscan[.]cloud, used for Mini-Shai-Hulud)
  • Credential reuse bridged a school email to a personal Gmail
  • The Gmail resolved to a TikTok account under the same real name, which linked out to a Steam profile
  • That Steam profile's avatar was the identical image fronting the group's Telegram channel

The writeup includes screenshots of each pivot and five defender recommendations at the end.

https://flare.io/learn/resources/blog/teampcp-software-supply-chain-attacks

Source: r/threatintel · by /u/FlareSystems

Leave a Reply

Your email address will not be published. Required fields are marked *