1
00:00:11,400 --> 00:00:15,400
Hello and welcome to the First 
Decipher podcast of 2026. 

2
00:00:15,400 --> 00:00:18,760
Hope you all had a nice holiday 
break as I did. 

3
00:00:19,280 --> 00:00:23,240
This is a solo podcast because 
as we mentioned late last year, 

4
00:00:23,240 --> 00:00:26,600
Lindsay is on maternity leave. 
Everything went well. 

5
00:00:26,600 --> 00:00:30,960
She's got a healthy baby girl at
home, so she's doing great. 

6
00:00:30,960 --> 00:00:33,520
It's going to be a few weeks 
before she's back, obviously, 

7
00:00:34,360 --> 00:00:38,640
but there's still plenty for us 
to catch up on, plenty of stuff 

8
00:00:38,640 --> 00:00:42,400
going on in the security world. 
So you get me as a solo 

9
00:00:42,400 --> 00:00:46,040
podcaster, talking into a 
microphone for a few weeks. 

10
00:00:46,360 --> 00:00:50,320
Hopefully some special guests. 
A few things before we get to 

11
00:00:50,320 --> 00:00:53,360
this week's news, I wanted to 
mention all the ways you can get

12
00:00:53,360 --> 00:00:56,360
in touch with us. 
You can follow us on Blue sky 

13
00:00:56,360 --> 00:01:01,400
Twitter at deciphersec. 
That's Decipher SEC. 

14
00:01:02,200 --> 00:01:06,440
That's also our YouTube channel.
It's youtube.com or yeah, 

15
00:01:06,440 --> 00:01:08,960
youtube.com slash at decipher 
SEC. 

16
00:01:09,520 --> 00:01:12,240
And if you want to e-mail us, 
you can get in touch with me, 

17
00:01:12,240 --> 00:01:17,080
Dennis at Decipher dot SC 
Lindsay's is the same, just 

18
00:01:17,080 --> 00:01:21,360
Lindsay, Lindsey at Decipher dot
SC. 

19
00:01:21,800 --> 00:01:23,320
Always happy to hear from our 
listeners. 

20
00:01:23,320 --> 00:01:26,520
If you have any podcast guests 
or topics you'd like us to 

21
00:01:26,520 --> 00:01:31,960
cover, please get in touch. 
Also, before we get to the news,

22
00:01:31,960 --> 00:01:34,920
I wanted to mention a few things
we have coming up on the podcast

23
00:01:34,920 --> 00:01:38,760
feed. 
I have a podcast coming next 

24
00:01:38,760 --> 00:01:43,000
week that I recorded yesterday 
with my friends Jeremiah 

25
00:01:43,000 --> 00:01:46,440
Grossman and Robert Hansen, who 
many of you probably know is our

26
00:01:46,440 --> 00:01:51,600
Snake 2 very, very smart and 
very experienced folks in the 

27
00:01:51,600 --> 00:01:55,680
cybersecurity industry. 
We talked about a whole bunch of

28
00:01:55,680 --> 00:01:59,520
things, mostly about their new 
venture, which is called Root 

29
00:01:59,520 --> 00:02:01,640
Evidence. 
It's in the vulnerability 

30
00:02:01,640 --> 00:02:05,680
management space, but it's not 
exactly the vulnerability 

31
00:02:05,680 --> 00:02:09,560
management company that you 
might be thinking of. 

32
00:02:09,560 --> 00:02:14,240
It's a different approach and 
it's backed by some data, which 

33
00:02:14,240 --> 00:02:17,520
is a interesting idea in the 
security world. 

34
00:02:17,520 --> 00:02:20,280
It's not backed by vibes or best
guesses. 

35
00:02:20,640 --> 00:02:22,640
So it's a really great 
conversation. 

36
00:02:22,640 --> 00:02:24,880
We talked for over an hour. 
We talked about a whole bunch of

37
00:02:24,880 --> 00:02:30,280
things, some of the security 
industry history, why 0 days 

38
00:02:30,280 --> 00:02:33,800
matter sometimes and usually not
all that much. 

39
00:02:34,120 --> 00:02:37,800
What organizations should be 
doing in terms of prioritizing 

40
00:02:37,800 --> 00:02:42,360
vulnerability patching, how they
make those decisions, how to 

41
00:02:42,360 --> 00:02:46,680
justify those decisions with the
board and the C-Suite and other 

42
00:02:46,680 --> 00:02:50,400
folks that are involved. 
So that should be up early next 

43
00:02:50,400 --> 00:02:52,680
week. 
That'll be on this feed as well 

44
00:02:52,680 --> 00:02:55,000
as the podcast or excuse me, the
YouTube channel. 

45
00:02:55,000 --> 00:02:59,320
So look out for that. 
And we also will have some of 

46
00:02:59,320 --> 00:03:02,400
our hacker movie episodes coming
soon as well. 

47
00:03:02,400 --> 00:03:04,840
We don't, I don't want to give 
away exactly which ones we're 

48
00:03:04,840 --> 00:03:08,640
doing in the next few weeks, but
we have plenty of good ones 

49
00:03:08,640 --> 00:03:11,440
coming. 
So keep an eye out for those. 

50
00:03:11,880 --> 00:03:13,960
All right, on to the news. 
So there were a couple of 

51
00:03:13,960 --> 00:03:15,960
stories I wanted to highlight 
from this week. 

52
00:03:16,360 --> 00:03:20,480
The 1st is some research that 
our old friends and former 

53
00:03:20,480 --> 00:03:27,240
colleagues at Cisco Talos 
released this week on a new, I 

54
00:03:27,240 --> 00:03:33,320
guess newly disclosed Chinese 
APT that they identify as UAT 

55
00:03:33,320 --> 00:03:36,520
7290. 
All of these threat Intel teams 

56
00:03:36,520 --> 00:03:39,520
have their own naming 
conventions, as we've talked 

57
00:03:39,520 --> 00:03:41,200
about many times on this 
podcast. 

58
00:03:42,400 --> 00:03:50,000
And this is a group that Talos 
identifies as a Chinese Nexus 

59
00:03:50,080 --> 00:03:53,640
APT group that's been active 
since at least 2022. 

60
00:03:54,760 --> 00:03:59,760
Teller specifically was looking 
at some of their recent activity

61
00:04:00,080 --> 00:04:04,520
into and some interesting 
targeting changes that the group

62
00:04:04,600 --> 00:04:08,600
has made as well as some of the 
malware and implants that the 

63
00:04:08,600 --> 00:04:14,200
group uses. 
So UAT 7290 historically has 

64
00:04:14,200 --> 00:04:18,160
focused on attacking telecom 
providers mostly in South 

65
00:04:18,440 --> 00:04:25,000
Southeast Asia, but recently I 
guess modified or expanded their

66
00:04:25,000 --> 00:04:29,920
targeting to also include some 
countries in southern 

67
00:04:29,920 --> 00:04:33,800
Southeastern Europe. 
So it's an it's always 

68
00:04:33,800 --> 00:04:38,920
interesting when APT teams 
decide to expand their 

69
00:04:38,920 --> 00:04:41,520
victimology. 
A lot of times, especially for 

70
00:04:41,520 --> 00:04:44,080
state backed actors, that is 
because they're getting 

71
00:04:44,080 --> 00:04:48,400
different tasking from their 
their bosses essentially, 

72
00:04:48,720 --> 00:04:51,680
whether that happens to be the 
intelligence agency that they 

73
00:04:51,680 --> 00:04:53,440
work for. 
Sometimes it's a military 

74
00:04:53,440 --> 00:04:56,920
branch, whatever it happens to 
be, a lot of times it's because 

75
00:04:56,920 --> 00:04:58,920
they essentially have different 
assignments. 

76
00:04:59,920 --> 00:05:07,560
So UAT 7290 has a dual role in 
this ecosystem and it serves as 

77
00:05:07,560 --> 00:05:11,440
both an initial access group, 
not an not an initial access 

78
00:05:11,440 --> 00:05:14,720
broker. 
They're not selling access to 

79
00:05:15,440 --> 00:05:19,720
victim organizations, but 
they're tasked with gaining 

80
00:05:19,720 --> 00:05:22,400
initial access to target 
organizations. 

81
00:05:23,040 --> 00:05:27,120
And they also perform cyber 
espionage activities, which is, 

82
00:05:27,400 --> 00:05:31,080
you know, a lot of times you see
APT teams that specialize in one

83
00:05:31,080 --> 00:05:33,400
thing or another. 
There might be groups that are 

84
00:05:33,400 --> 00:05:37,200
very good at initial access, you
know, exploiting 

85
00:05:37,200 --> 00:05:42,000
vulnerabilities, finding other 
ways in, you know, targeting 

86
00:05:42,000 --> 00:05:43,920
help desks, whatever the case 
may be. 

87
00:05:44,200 --> 00:05:47,720
And then there are other groups 
that are then tasked with taking

88
00:05:47,720 --> 00:05:53,680
over those those victims and 
gathering the the intelligence 

89
00:05:53,680 --> 00:05:56,440
that is the main goal of these 
operations. 

90
00:05:56,480 --> 00:05:59,760
This group happens to have dual 
tasking and looks like so it's 

91
00:05:59,760 --> 00:06:04,200
something to keep an eye on. 
And it, it, this group also 

92
00:06:04,200 --> 00:06:09,280
shares some common TTPS with 
some other Chinese Nexus AP TS, 

93
00:06:10,440 --> 00:06:13,760
including, you know, the 
exploitation of bugs in 

94
00:06:13,760 --> 00:06:18,760
networking edge devices, which 
is not a, a unique TTP. 

95
00:06:19,040 --> 00:06:21,200
Everybody does that because 
there's so many of them. 

96
00:06:21,200 --> 00:06:24,400
And it's a great way to get into
an enterprise network. 

97
00:06:25,560 --> 00:06:28,320
They also use open source web 
shells for persistence. 

98
00:06:28,320 --> 00:06:35,680
Again, that's a common TTP. 
And they use compromised 

99
00:06:35,720 --> 00:06:38,440
infrastructure as part of their 
operations. 

100
00:06:38,800 --> 00:06:41,800
You see this sometimes with APT 
groups as well as some 

101
00:06:41,800 --> 00:06:49,120
cybercrime groups that will look
around and find already 

102
00:06:49,120 --> 00:06:53,920
compromised boxes, routers, 
network edge devices that some 

103
00:06:53,920 --> 00:06:58,480
other actor has taken the time 
to compromise and then use them 

104
00:06:58,480 --> 00:07:00,200
for their own their own 
purposes. 

105
00:07:00,200 --> 00:07:03,760
It happens relatively 
frequently, but that's just one 

106
00:07:03,760 --> 00:07:06,520
of the things that Talos noticed
about this group. 

107
00:07:07,800 --> 00:07:11,880
They also have some really 
interesting custom malware that 

108
00:07:11,880 --> 00:07:14,080
they use. 
They have a few different ones 

109
00:07:14,080 --> 00:07:15,600
that I would encourage everybody
to go. 

110
00:07:15,600 --> 00:07:18,240
And we have a story up on this 
on Decipher. 

111
00:07:19,240 --> 00:07:21,960
You can also read Talos's 
research as well. 

112
00:07:21,960 --> 00:07:23,480
I'll link to that in the show 
notes. 

113
00:07:23,880 --> 00:07:30,200
But this group, UAT 7290, has 
several different pieces of 

114
00:07:30,200 --> 00:07:33,640
malware, both Linux and Windows 
based malware. 

115
00:07:34,640 --> 00:07:37,480
So they have a dropper that's 
called Rush Drop. 

116
00:07:37,480 --> 00:07:40,200
This is the Linux side of 
things. 

117
00:07:40,960 --> 00:07:45,880
Another piece of malware called 
drive switch which is then used 

118
00:07:45,880 --> 00:07:49,840
to execute the main implant 
which is called silent RAID. 

119
00:07:50,400 --> 00:07:54,000
So silent RAID is the 
persistence mechanism and it has

120
00:07:54,000 --> 00:07:58,720
a whole bunch of, you know, the 
typical functionality that you 

121
00:07:58,720 --> 00:08:02,640
would expect in in a malware 
implant from an APT group. 

122
00:08:02,920 --> 00:08:09,160
So UAT 7290 looks like a 
relatively new player in the 

123
00:08:09,160 --> 00:08:12,960
Chinese APT world. 
There's that's a crowded 

124
00:08:12,960 --> 00:08:17,360
landscape. 
As everybody knows, there's an 

125
00:08:17,360 --> 00:08:22,320
unknowable but large number of 
APT groups that operate from 

126
00:08:22,320 --> 00:08:27,760
China and with Chinese, you 
know, authority and backing. 

127
00:08:27,760 --> 00:08:31,960
So this is just another one to 
to put on that that menu. 

128
00:08:33,159 --> 00:08:38,400
The second big story that I 
wanted to mention this week is 

129
00:08:38,400 --> 00:08:43,159
some research that our friends 
at Gray Noise released on 

130
00:08:43,480 --> 00:08:47,840
targeting activity that's still 
going after that React to shell 

131
00:08:47,920 --> 00:08:50,560
bug that was disclosed about a 
month ago. 

132
00:08:50,560 --> 00:08:54,480
Now. 
You know, this is a critical RCE

133
00:08:54,480 --> 00:08:59,440
bug in the React server 
components library also affected

134
00:08:59,440 --> 00:09:03,280
a bunch of downstream things. 
And it was kind of a one of 

135
00:09:03,280 --> 00:09:06,000
those fire drill bugs at the 
beginning of December when it 

136
00:09:06,000 --> 00:09:08,800
was initially disclosed, there 
was a lot of exploit activity 

137
00:09:08,800 --> 00:09:11,560
going on. 
Then there was public proof of 

138
00:09:11,560 --> 00:09:14,800
concepts that came out. 
A lot of the early exploit 

139
00:09:14,800 --> 00:09:21,040
activity, interesting enough was
seen from red teams, which is 

140
00:09:21,120 --> 00:09:23,720
not atypical. 
You see that quite often with 

141
00:09:23,720 --> 00:09:29,760
something like this That's, that
affects a large number of large 

142
00:09:29,760 --> 00:09:32,200
number of organizations and a 
whole bunch of apps. 

143
00:09:32,280 --> 00:09:35,960
So, you know, you have red teams
immediately going to see what 

144
00:09:35,960 --> 00:09:38,120
they have in their environments,
what they have in, you know, 

145
00:09:38,200 --> 00:09:40,440
external red teams looking at 
their their clients 

146
00:09:40,440 --> 00:09:41,680
environments, that sort of 
thing. 

147
00:09:42,160 --> 00:09:44,960
And that can spike the exploit 
activity volume that you see 

148
00:09:44,960 --> 00:09:47,360
immediately after a disclosure 
like this. 

149
00:09:48,560 --> 00:09:52,680
That's what happened. 
But now a month later, Grainoy 

150
00:09:52,680 --> 00:09:58,240
said that they're still seeing 
after a peak of about 430,000 

151
00:09:58,720 --> 00:10:05,200
attacks, attack sessions per day
at the end of December, the 

152
00:10:05,200 --> 00:10:07,840
volume has come down a little 
bit, but it's still in the 300 

153
00:10:07,840 --> 00:10:13,520
to 400,000 range per day, which 
is a huge volume for something 

154
00:10:13,520 --> 00:10:16,720
like this. 
I mean, this is a, a big, you 

155
00:10:16,720 --> 00:10:19,840
know, vulnerability that got a 
ton of publicity. 

156
00:10:19,840 --> 00:10:24,400
It got a lot of attention from 
threat and tell teams, you know,

157
00:10:24,400 --> 00:10:28,440
Sisa, all the usual suspects 
were urging everybody to up 

158
00:10:28,640 --> 00:10:30,680
upgrade and patch and all that 
kind of stuff. 

159
00:10:30,680 --> 00:10:36,680
But the fact that there's still 
that much exploit activity a 

160
00:10:36,680 --> 00:10:40,440
month out from the initial 
disclosure is an interesting 

161
00:10:40,440 --> 00:10:43,200
tidbit. 
And it's not just coming from, 

162
00:10:43,440 --> 00:10:46,400
you know, obviously with that 
volume of of activity, it's not 

163
00:10:46,400 --> 00:10:49,560
coming from one or two places. 
It's coming from all over the 

164
00:10:49,560 --> 00:10:52,760
place. 
A lot of it is coming from cloud

165
00:10:52,760 --> 00:10:57,040
infrastructure, obviously AWS, 
places like that, but the 

166
00:10:57,040 --> 00:10:59,520
attackers them, so you know, 
whoever the attackers are. 

167
00:10:59,520 --> 00:11:03,960
But behind these, it's a wide 
range of of people as you might 

168
00:11:03,960 --> 00:11:08,800
expect, you know, cybercrime 
groups, APT groups, I'm sure 

169
00:11:08,800 --> 00:11:11,600
there's still some red teams in 
there, some offensive security 

170
00:11:11,600 --> 00:11:15,640
researchers, folks poking around
to see, you know, what's still 

171
00:11:15,640 --> 00:11:18,440
vulnerable a month after after 
the fact. 

172
00:11:18,880 --> 00:11:23,840
So if you are listening to this 
and have not updated everything 

173
00:11:23,840 --> 00:11:27,960
that has this react to shell 
vulnerable, react to shell 

174
00:11:30,640 --> 00:11:34,760
library associated with it, you 
got to do that. 

175
00:11:34,760 --> 00:11:38,240
I mean it's it's been almost 5 
weeks since the initial 

176
00:11:38,240 --> 00:11:41,720
disclosure. 
Obviously it's not always easy 

177
00:11:41,720 --> 00:11:45,920
to go and patch everything 
immediately, but this is one 

178
00:11:45,920 --> 00:11:49,200
that is obviously seeing a lot 
of attention from a variety of 

179
00:11:49,200 --> 00:11:54,800
attacker groups, you know, 
organized discipline groups as 

180
00:11:54,800 --> 00:11:58,800
well as opportunistic attackers 
that are just looking for a way 

181
00:11:58,800 --> 00:12:02,720
into any organization and then 
figuring it out from there. 

182
00:12:02,720 --> 00:12:05,680
But this is obviously something 
you want to pay attention to, 

183
00:12:05,680 --> 00:12:09,520
even though it's been, it's a 
month old, Please, you know, go 

184
00:12:09,520 --> 00:12:11,720
and patch it if you, if you 
haven't already. 

185
00:12:12,520 --> 00:12:16,640
Gray Noise said that they've 
seen a total of more than 8.1 

186
00:12:16,640 --> 00:12:18,600
million attack sessions in a 
month. 

187
00:12:19,160 --> 00:12:22,480
It's quite a large number. 
You can go and look at their 

188
00:12:22,480 --> 00:12:24,200
data. 
They have a good public data set

189
00:12:24,200 --> 00:12:27,920
that they've shared and it shows
you some of the ASNS that are 

190
00:12:27,920 --> 00:12:30,680
involved. 
So if you want to have a good 

191
00:12:30,680 --> 00:12:35,680
look at where the attack 
activity is coming from and what

192
00:12:35,840 --> 00:12:39,520
kind of apps are being targeted,
that's the place to go and look.

193
00:12:40,080 --> 00:12:42,800
So those are the two things I 
wanted to really highlight for 

194
00:12:42,800 --> 00:12:45,840
this week. 
As I said at the beginning, keep

195
00:12:45,840 --> 00:12:50,400
an eye out for my podcast with 
Jeremiah Grossman and Robert 

196
00:12:50,400 --> 00:12:53,880
Hansen that'll be coming early 
to mid next week. 

197
00:12:54,840 --> 00:12:58,320
That'll be both on this feed as 
well as the YouTube channel. 

198
00:12:58,320 --> 00:13:01,240
It'll be on the Decipher dot SC 
site as well, obviously. 

199
00:13:01,680 --> 00:13:06,680
And also keep an eye out for the
hacker movie podcasts that are 

200
00:13:06,680 --> 00:13:10,880
coming. 
If folks have suggestions or 

201
00:13:11,000 --> 00:13:15,200
movies that they really want to 
see, see us do on the podcast, 

202
00:13:15,200 --> 00:13:17,840
please let us know. 
We have a pretty long list of 

203
00:13:17,840 --> 00:13:21,640
ones that we're going to get to 
in the in the coming weeks and 

204
00:13:21,640 --> 00:13:23,560
months. 
Some of which are, you know, 

205
00:13:23,560 --> 00:13:25,560
traditional hacker movies that 
you might expect. 

206
00:13:25,560 --> 00:13:28,680
Others are not quite, as you 
know, obvious choices. 

207
00:13:29,160 --> 00:13:32,520
But we're, we have a very loose 
definition of what a hacker 

208
00:13:32,520 --> 00:13:36,040
movie is. 
So if you want to throw a few at

209
00:13:36,040 --> 00:13:39,400
us, please do. 
Again, my e-mail address Dennis 

210
00:13:39,400 --> 00:13:43,600
at decipher dot SC and I'd be 
happy to hear any of those 

211
00:13:43,600 --> 00:13:46,000
suggestions. 
So thanks everybody for 

212
00:13:46,000 --> 00:13:47,640
listening and have a great week.
