Skip to main content
Attribution of TeamPCP Member DeadCatx3

Attribution of TeamPCP Member DeadCatx3

On August 27, the Australian Federal Police announced the arrest and charging of two Western Australian men following a joint investigation involving the AFP, Western Australia Police Force and FBI into an alleged global cybercrime syndicate. With the arrests now public, some of the identities around TeamPCP are no longer particularly well kept secrets. The cat is out of the bag - or, in this case, the bag belongs to DeadCatx3.


DeadCatx3: Following an Identity Trail from a Threat Actor Alias
#

Our first coverage into TeamPCP was in May this year, when we identified the linkage between a supply chain attack targeting npm and PyPI packages, such as Mistral AI SDK, to TeamPCP. This post is a natural follow-up to that case, highlighting the need for the right tooling and access to attribute the actors and take action.

Both MITRE and Flare had linked the alias DeadCatx3 with TeamPCP operations, showing multiple links in the group’s infrastructure with the DeadCatx3 alias, including a GitHub account.

This investigation kicked off for us as usual, with a freshly unveiled threat actor username. We would task the Glazer Agent Investigator profile with an ambiguous task of:

Identify the teampcp member going by username DeadCatx3

Alt text
Initial task for the Agent

And the resulting investigation took less than two minutes.

From one username to an identity
#

Glazer’s output converged on Ruben Thomson, a Western Australian individual whose online footprint intersected with the DeadCatx3 identity in several independent places.

The strongest pivot was a HackerOne registration under the username DeadCatx3, where the account was registered using the name Ruben Thomson.

That alone is an interesting lead, but not something we would want to treat as sufficient attribution. The useful part of the investigation was what could be pivoted from that initial match.

The identity graph expanded through email addresses, historical breach records, platform registrations, IP information and other usernames. The resulting chain looked roughly like this:

DeadCatx3
   ├── HackerOne
   │      └── Ruben Thomson
   ├── [email protected]
   │      ├── Houzz
   │      │     ├── Ruben Thomson
   │      │     ├── East Fremantle, WA 6158
   │      │     └── 110.141.230.15
   │      │
   │      ├── Microsoft
   │      │     └── Ruben Thomson / AU
   │      │
   │      ├── Dropbox
   │      │     └── Ruben Thomson
   │      │
   │      ├── Etsy
   │      │     └── Ruben
   │      │
   │      └── Google Maps
   │            └── Perth metropolitan area
   ├── 110.141.230.15
   │      ├── Telstra residential connection
   │      ├── Perth, WA
   │      └── historical DNS
   │            ├── newslibar.com
   │            └── zzap.cc
   ├── nervequake
   │      ├── Internet Archive
   │      ├── GitHub
   │      ├── Discord
   │      ├── Reddit
   │      └── other platforms
   └── TeamPCP
          ├── MITRE
          ├── Unit 42
          ├── Malpedia
          ├── Mandiant / Google
          ├── Okta
          ├── Wiz
          ├── BitSight
          └── others

The HackerOne pivot
#

The first particularly useful result was HackerOne.

The DeadCatx3 username was registered with the real name Ruben Thomson. This is a very different type of signal from simply finding DeadCatx3 on another social platform. The username is the same, platform is related to the cybersecurity domain and the account exposes a real-world name. From there, the investigation can pivot on the newly discovered name and associated identifiers rather than continuing to search for DeadCatx3 directly.

That produced [email protected] as one of the more significant identifiers. The email appeared across multiple datasets, and importantly, those datasets did not simply repeat the same piece of information but added context with every finding.

From an email address to a physical location
#

One of the strongest supporting records came from the Houzz breach.

The record associated:

  • [email protected]
  • the name Ruben Thomson
  • the username steinvine_
  • an East Fremantle, Western Australia address
  • IP address 110.141.230.15

This is the ideal goal of an investigation for law enforcment, as it takes the alias to a physical space with high certainty. The same email identifier that can be reached from the DeadCatx3 identity is now associated with a named individual and a physical location, while other platform records independently reinforce the name:

  • The Microsoft account associated with [email protected] lists Ruben Thomson and Australia.
  • Dropbox similarly contains the name Ruben Thomson.
  • Etsy contains the first name Ruben.

The IP pivot
#

The Houzz record also gave us an IP address:

110.141.230.15

This address resolves to the Perth area and is associated with Telstra’s residential network, ASN 1221. Again, IP geolocation by itself is weak attribution evidence. Residential IPs change, geolocation is imperfect, and an address being in Perth doesn’t tell us who was using it at a particular moment, but within the Agent context, it adds confidence to the findings. In particular, when the raw breach record contains:

Ruben Thomson
East Fremantle, WA
[email protected]
steinvine_
110.141.230.15

The location trail
#

The same email address also provided another interesting pivot through Google Maps activity.

Reviews associated with [email protected], under the display name “Gone Fishing”, were concentrated around the Perth metropolitan area.

The locations included:

  • Jasper Green Reserve, Cottesloe
  • PLE Computers, Osborne Park
  • Golden Cloud Spur, Mandurah
  • KFC Subiaco
  • UWA Sports Park, Mount Claremont
  • Grill’d at Claremont Quarter
  • David Jones at Claremont Quarter

The activity dates to 2019 and forms a geographically coherent pattern around Perth, raising the confidence in the found identity cluster.

The right tools in the right hands
#

Alt text
Generated report

In this case, we started with a single username and, in under two minutes, were able to connect it to a real-world identity, email addresses, historical breach records, account registrations, a physical location, an IP address, additional aliases, and the wider TeamPCP ecosystem. That does not replace investigative work, and it does not turn every correlation into evidence. It does, however, shorten the distance between a lead and the next action.

The right tools, with the right data, in the hands of people who know how to investigate it, can help defenders move faster, identify the infrastructure and identities behind an operation, and potentially prevent further harm. For law enforcement, the same intelligence can help turn an online alias into something that can be investigated in the real world and, where the evidence supports it, ultimately help enforce justice.

The arrests announced today are the result of a much larger investigation involving the AFP, WAPOL, and FBI. We are here to show how quickly the same identity trail can be reconstructed once the right starting point is available.

Building on our law enforcement experience, we know that sometimes that is the difference that matters: having the information is one thing. Being able to find it, connect it, and act on it before the next victim is hit is another.

Related