Our Emerging Threats Team put together a walkthrough of the attribution process behind the individual arrested and accused of being behind TeamPCP.
The pivot chain, briefly:
- Seed was the handle DeadCatx3, reused verbatim outside the group's operational channels
- Username enumeration surfaced a HackerOne account under a real name, plus a Hugging Face profile listing the group's own C2 domain (masscan[.]cloud, used for Mini-Shai-Hulud)
- Credential reuse bridged a school email to a personal Gmail
- The Gmail resolved to a TikTok account under the same real name, which linked out to a Steam profile
- That Steam profile's avatar was the identical image fronting the group's Telegram channel
The writeup includes screenshots of each pivot and five defender recommendations at the end.
https://flare.io/learn/resources/blog/teampcp-software-supply-chain-attacks
Source: r/threatintel · by /u/FlareSystems