Home / Crime and Justice / Screen Name Snares Alleged TeamPCP Leader in Australia
Screen Name Snares Alleged TeamPCP Leader in Australia
27 Aug
Summary
- Hacker's reuse of 'DeadCatx3' alias aided investigators.
- Suspect Ruben Thomson linked to TeamPCP via GitHub and HackerOne.
- Malware allegedly compromised over 1,000 organizations globally.

Law enforcement in Australia apprehended two men allegedly involved with TeamPCP, a hacking group known for distributing malware via open-source software. One suspect, 21-year-old Ruben Thomson, was identified due to his prominent screen name, DeadCatx3. This alias was linked to TeamPCP through their GitHub account, where they hosted their tools. Cybersecurity firm Flare discovered that the DeadCatx3 handle was also active on HackerOne, a bug bounty platform.
On HackerOne, the DeadCatx3 account listed Ruben Thomson's full name. Further investigation by Flare uncovered additional accounts tied to Thomson, including a Steam profile with a unique cat avatar. This avatar was later observed on TeamPCP's Telegram account, strongly suggesting Thomson's leadership. TeamPCP's "loud by choice" communication on Telegram and X also facilitated the investigation.
Authorities also arrested 23-year-old Louis Michael Gaebler. The malicious code spread by the group is estimated to have compromised over 1,000 organizations worldwide, leading to the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data. Thomson and Gaebler face a total of 14 charges and are scheduled to appear in an Australian court.