1
00:00:12,000 --> 00:00:13,880
Hello and welcome to the 
Decipher podcast. 

2
00:00:13,960 --> 00:00:16,440
I'm Dennis Fisher. 
This is a weekly news wrap up 

3
00:00:16,440 --> 00:00:19,640
episode of the podcast. 
Lots going on this week, plenty 

4
00:00:19,640 --> 00:00:24,120
of stuff happening, lots of 
news, lots of pre RSA stuff 

5
00:00:24,120 --> 00:00:27,400
going on. 
RSA is one of those things that 

6
00:00:27,400 --> 00:00:31,520
I look forward to and also look 
at with absolute existential 

7
00:00:31,520 --> 00:00:34,680
dread every year. 
We'll get into that later. 

8
00:00:34,680 --> 00:00:38,600
But before we get started on the
news here, here's how you can 

9
00:00:38,600 --> 00:00:40,880
reach us. 
If you're listening to the 

10
00:00:40,880 --> 00:00:41,960
podcast, you know how to do 
that. 

11
00:00:41,960 --> 00:00:45,520
Congrats, I'm proud of you. 
If you want to find us on video,

12
00:00:45,560 --> 00:00:49,160
you can find us at 
youtube.com/decipher Sack. 

13
00:00:49,280 --> 00:00:52,760
All our videos are up there, 
podcast interviews as well as 

14
00:00:52,760 --> 00:00:56,080
our Hacker Movie podcast 
episodes, which are super fun. 

15
00:00:56,600 --> 00:01:02,400
Our latest one was on Star Wars 
with Rich Mogul and Wade Baker 

16
00:01:02,400 --> 00:01:04,480
came out a couple weeks ago. 
It's really fun. 

17
00:01:04,959 --> 00:01:08,200
As you might imagine, those two 
guys are super Star Wars geeks 

18
00:01:08,200 --> 00:01:09,680
and I was kind of along for the 
ride. 

19
00:01:09,720 --> 00:01:13,320
It was a good time. 
We have another one coming next 

20
00:01:13,320 --> 00:01:15,720
week. 
I don't want to spoil that, but 

21
00:01:15,720 --> 00:01:17,840
it should be very fun. 
We have a couple of very cool 

22
00:01:17,840 --> 00:01:19,560
guests who are lined up for that
one. 

23
00:01:20,120 --> 00:01:25,680
And in other podcast news, we 
had an episode that went up this

24
00:01:25,680 --> 00:01:29,240
week with my friend Caitlin 
Condon from Voluntchak, who's 

25
00:01:29,240 --> 00:01:32,520
very funny and very smart and 
just one of the funnest 

26
00:01:32,520 --> 00:01:34,080
interviews I've done in a long 
time. 

27
00:01:35,120 --> 00:01:37,880
We talked about a exploit 
Intelligence Report that 

28
00:01:37,880 --> 00:01:40,920
Voluntchak put out recently that
has a lot of cool data on 

29
00:01:41,640 --> 00:01:44,000
exploits. 
As you might imagine given the 

30
00:01:44,000 --> 00:01:48,720
title, Caitlin's been in the 
vulnerability research and 

31
00:01:48,720 --> 00:01:52,280
exploit dev game for a very long
time and knows exactly what 

32
00:01:52,280 --> 00:01:54,840
she's talking about, so I'd 
encourage you to check that out.

33
00:01:55,160 --> 00:01:59,280
Caitlin's a lot of fun. 
So other ways you can find us on

34
00:01:59,400 --> 00:02:02,520
Twitter and Blue Sky, it's at 
Deciphersec. 

35
00:02:02,560 --> 00:02:06,560
I mentioned YouTube and if you 
want to e-mail us, you can get 

36
00:02:06,560 --> 00:02:11,600
me a Dennis at Decipher dot SC 
and Lindsay is Lindsay with an 

37
00:02:12,040 --> 00:02:14,920
EY at Decipher dot SC Lindsay 
will be back soon. 

38
00:02:15,640 --> 00:02:18,480
Her leave is almost over. 
So she's she's going to be back 

39
00:02:18,480 --> 00:02:20,240
in the game very soon. 
So we're looking forward to 

40
00:02:20,240 --> 00:02:22,000
that. 
All right, let's dive into the 

41
00:02:22,000 --> 00:02:24,920
news. 
So two big stories that we have 

42
00:02:24,920 --> 00:02:29,280
on the site this week. 
First one is the re emergence of

43
00:02:29,280 --> 00:02:34,840
APT 28, which is one of the more
notorious Russian APT groups, 

44
00:02:35,560 --> 00:02:39,680
also known as Sednit, also known
as fancy bear forest Blizzard, 

45
00:02:39,720 --> 00:02:41,640
all kinds of fun monikers for 
that group. 

46
00:02:42,560 --> 00:02:47,800
Been around a really long time. 
They are linked to Russia's Gru 

47
00:02:47,880 --> 00:02:52,680
which is a military intelligence
branch and very active group and

48
00:02:52,680 --> 00:02:55,240
highly capable, as you might 
imagine, being connected to 

49
00:02:55,240 --> 00:02:58,600
Russian intelligence. 
The group knows what it's doing,

50
00:02:58,600 --> 00:03:04,680
but they have been a little bit 
quiet in recent years. 

51
00:03:04,760 --> 00:03:09,840
No one's totally sure why, but 
one of the things that this 

52
00:03:09,840 --> 00:03:13,680
group is known for is developing
its own exploits, its own 

53
00:03:13,680 --> 00:03:17,920
malware, its own tools, 
obviously has a a ton of funding

54
00:03:17,920 --> 00:03:20,400
and capabilities to draw from in
house. 

55
00:03:20,400 --> 00:03:21,840
They don't have to outsource 
this stuff. 

56
00:03:23,240 --> 00:03:27,120
And some new research from ESET 
this week found that the 

57
00:03:27,120 --> 00:03:31,040
advanced development team inside
Sednet, which had been pretty 

58
00:03:31,040 --> 00:03:37,320
quiet as I mentioned, had 
actually been working at least 

59
00:03:37,320 --> 00:03:44,120
since about April 2024 with some
new tools and had been deploying

60
00:03:44,120 --> 00:03:49,840
those against Ukrainian targets 
in support of their the Russian 

61
00:03:49,840 --> 00:03:54,720
invasion of Ukraine. 
And Eset's research, I'll just 

62
00:03:54,720 --> 00:03:58,440
quote from what they wrote in 
their analysis, says our account

63
00:03:58,440 --> 00:04:02,080
of modern Senate activities 
begins with Slim Agent, an 

64
00:04:02,080 --> 00:04:05,560
espionage implant discovered on 
a Ukrainian governmental machine

65
00:04:06,080 --> 00:04:09,480
by CERT UA. 
That's the CERT Ukrainian CERT 

66
00:04:09,920 --> 00:04:13,160
in April 2024. 
Slim Agent is a simple yet 

67
00:04:13,160 --> 00:04:16,279
efficient spying tool capable of
logging keystrokes, capturing 

68
00:04:16,279 --> 00:04:18,959
screenshots, collecting 
clipboard data. 

69
00:04:20,720 --> 00:04:23,920
You know, typical espionage 
implant backdoor type thing. 

70
00:04:25,240 --> 00:04:32,040
But this is a new one that has 
had not been really seen too 

71
00:04:32,040 --> 00:04:40,000
much it, but it's got some code 
overlap, which with other tools 

72
00:04:40,000 --> 00:04:43,440
that had been deployed way back 
and you know, like almost 10 

73
00:04:43,440 --> 00:04:48,240
years ago. 
So that's one of the the kind of

74
00:04:48,960 --> 00:04:52,560
hallmarks of this group is that 
their their tools, you know, 

75
00:04:52,560 --> 00:04:56,920
often have code overlaps and and
similarities for obvious 

76
00:04:56,920 --> 00:04:58,960
reasons. 
I mean, why develop new tools if

77
00:04:58,960 --> 00:05:00,960
you can kind of steal from the 
ones you've already developed? 

78
00:05:02,800 --> 00:05:10,560
But Sidnet also has two new 
tools in its arsenal. 2 new 

79
00:05:10,560 --> 00:05:15,160
implants, one called Beard 
Shell, which is an implant that 

80
00:05:16,040 --> 00:05:23,280
executes PowerShell commands and
it abuses the legitimate cloud 

81
00:05:23,280 --> 00:05:29,200
storage service ICE Drive for 
C2, you know that kind of thing.

82
00:05:29,200 --> 00:05:34,640
Using, you know, legitimate 
commercial cloud services for C2

83
00:05:34,640 --> 00:05:37,040
is not new. 
It's something that AB TS do 

84
00:05:37,040 --> 00:05:41,160
quite a lot. 
And so the other tool in the 

85
00:05:41,160 --> 00:05:48,640
arsenal now is Covenant, which 
is a modified version of an open

86
00:05:48,640 --> 00:05:51,160
source.net post exploitation 
framework. 

87
00:05:51,840 --> 00:05:56,840
And Sednet has reworked this 
framework and replaced its 

88
00:05:56,840 --> 00:06:01,160
original architecture with 
features adapted for long term 

89
00:06:01,160 --> 00:06:03,600
cyber espionage. 
Cyber espionage. 

90
00:06:05,440 --> 00:06:09,440
And this is, you know, this is 
one of those things where you 

91
00:06:09,440 --> 00:06:14,920
see an advanced group like this 
that has these really high end 

92
00:06:14,920 --> 00:06:18,760
capabilities and can, you know, 
take legitimate tools and 

93
00:06:18,760 --> 00:06:21,760
legitimate services and bend 
them to their own purposes. 

94
00:06:23,080 --> 00:06:26,960
Common tactics for AP TS, you 
know, they're it's expensive to 

95
00:06:26,960 --> 00:06:30,160
develop your own tools and 
implants and all of that. 

96
00:06:30,160 --> 00:06:33,000
Even with, you know, the budget 
that you would assume this group

97
00:06:33,000 --> 00:06:38,320
has, you know, it's more 
efficient and probably more time

98
00:06:38,320 --> 00:06:41,960
effective and cost effective to 
take something that's already 

99
00:06:41,960 --> 00:06:45,120
out in the marketplace and 
modify it and use it for your 

100
00:06:45,120 --> 00:06:49,520
own purposes. 
So that's the lowdown on the new

101
00:06:49,520 --> 00:06:52,280
research. 
Again, the story is up on the on

102
00:06:52,280 --> 00:06:57,440
the site APT 28. 
You know, Sednit Fancy Bear is a

103
00:06:57,440 --> 00:07:01,160
group that has attracted plenty 
of attention from researchers 

104
00:07:01,160 --> 00:07:07,200
and law enforcement. 
The DOJ indicted more than a 

105
00:07:07,200 --> 00:07:12,040
dozen alleged members of APT28 
back in 2018. 

106
00:07:12,560 --> 00:07:16,600
If you go read that indictment, 
you'll get a good a good look, 

107
00:07:16,600 --> 00:07:19,760
some insights into the group's 
activities and some of their 

108
00:07:19,760 --> 00:07:22,200
targets. 
This is the group that's 

109
00:07:22,200 --> 00:07:26,960
believed to be responsible for 
hacking the DNC all those years 

110
00:07:26,960 --> 00:07:31,400
ago, which we talked about the 
ripple effects of that all day 

111
00:07:31,400 --> 00:07:33,040
long, but we don't want to get 
into that. 

112
00:07:34,240 --> 00:07:37,480
So yeah, I would encourage you 
guys to go read the the story we

113
00:07:37,480 --> 00:07:40,440
have on the site as well as 
Eset's research, which is very 

114
00:07:40,440 --> 00:07:44,440
well done as usual. 
Next story I wanted to mention 

115
00:07:44,440 --> 00:07:50,400
is a crackdown that came down at
the end of this week by U.S. law

116
00:07:50,400 --> 00:07:54,840
enforcement and Europol, which 
took down a residential proxy 

117
00:07:54,840 --> 00:08:00,080
network known as Sox escort. 
This is the second one of these 

118
00:08:00,080 --> 00:08:03,520
residential proxy network 
takedowns that we've seen in the

119
00:08:03,520 --> 00:08:06,920
last couple months. 
There was one at the end of 

120
00:08:06,920 --> 00:08:14,160
January for a network called IP 
Idea that, you know, we, we 

121
00:08:14,160 --> 00:08:16,320
wrote about at the time and we 
talked about on the podcast at 

122
00:08:16,320 --> 00:08:19,880
the time. 
In this one, it's, it's kind of 

123
00:08:19,880 --> 00:08:22,520
the, you know, the typical 
framework of these takedowns 

124
00:08:22,520 --> 00:08:25,400
that you see. 
They seized a bunch of domains. 

125
00:08:25,960 --> 00:08:32,440
the US seized or froze $3.5 
million in cryptocurrency, 

126
00:08:33,320 --> 00:08:37,000
seized 34 domains, 23 servers in
seven countries. 

127
00:08:37,000 --> 00:08:40,120
So it's a pretty international 
takedown. 

128
00:08:41,159 --> 00:08:44,800
And the, you know, these 
residential proxy networks, so 

129
00:08:45,960 --> 00:08:49,480
they're in a weird Gray area. 
Like, there are legit 

130
00:08:49,480 --> 00:08:55,400
residential proxy services that 
allow you to sort of, you know, 

131
00:08:56,600 --> 00:09:00,320
hide your location, hide your IP
address for, you know, 

132
00:09:00,840 --> 00:09:04,280
legitimate reasons. 
Activists, journalists, 

133
00:09:04,440 --> 00:09:08,680
dissidents, people like that use
networks like this because 

134
00:09:08,680 --> 00:09:12,080
they're at risk. 
But cyber criminals use these 

135
00:09:12,080 --> 00:09:15,240
networks for all the reasons you
might imagine. 

136
00:09:15,640 --> 00:09:20,640
And they've become a big problem
in the last, I don't know, 3-4, 

137
00:09:20,640 --> 00:09:24,600
five years. 
They've always been around, but 

138
00:09:24,600 --> 00:09:27,800
they've become a much bigger, 
bigger problem in recent years. 

139
00:09:29,040 --> 00:09:33,120
So, you know, cyber criminals 
love these things. 

140
00:09:33,120 --> 00:09:36,320
They're they're all over. 
They're all over the world, 

141
00:09:36,320 --> 00:09:39,720
obviously, and some of them are 
very, very big. 

142
00:09:41,200 --> 00:09:46,400
Black Lotus Labs was one of the 
cooperating security vendors in 

143
00:09:46,400 --> 00:09:51,120
this takedown. 
And their research found that 

144
00:09:51,120 --> 00:09:57,080
this this particular residential
proxy network was kind of 

145
00:09:57,080 --> 00:10:01,480
powered by the AV Recon malware,
which has been around for about 

146
00:10:01,480 --> 00:10:05,720
3 years. 
And more than half of the Sox 

147
00:10:05,760 --> 00:10:08,720
escort victims were located in 
the US or the UK. 

148
00:10:08,720 --> 00:10:12,480
In this case, you know, although
there were victims spread all 

149
00:10:12,480 --> 00:10:18,240
over the map, these were the two
largest, largest, largest victim

150
00:10:19,640 --> 00:10:26,760
victim sets geographically. 
So here's a a good quote from 

151
00:10:26,960 --> 00:10:31,920
the director of your executive 
director of Europol from this 

152
00:10:31,920 --> 00:10:34,600
takedown. 
It says cybercrime thrives on 

153
00:10:34,600 --> 00:10:38,000
anonymity. 
Proxy services like Sox Escort 

154
00:10:38,360 --> 00:10:40,760
provide criminals with the 
digital cover they need to 

155
00:10:40,760 --> 00:10:44,280
launch attacks, distribute 
illegal content, innovate 

156
00:10:44,280 --> 00:10:45,960
detection. 
By dismantling this 

157
00:10:45,960 --> 00:10:49,040
infrastructure, law enforcement 
has disrupted a service that 

158
00:10:49,040 --> 00:10:52,480
enabled enabled cybercrime on a 
global, global scale. 

159
00:10:53,640 --> 00:10:58,960
Europol has been doing a lot of 
this in the last, you know, 

160
00:11:00,080 --> 00:11:03,520
probably decade, but the last I 
would say five years. 

161
00:11:03,520 --> 00:11:08,560
They've really ramped up their 
takedown efforts and disruption 

162
00:11:08,560 --> 00:11:14,120
efforts on cybercrime networks, 
especially going after the 

163
00:11:14,120 --> 00:11:17,360
payment infrastructure and the 
cloud infrastructure that these 

164
00:11:17,360 --> 00:11:21,240
services thrive on. 
You know, without a way to move 

165
00:11:21,240 --> 00:11:25,320
money, they can't operate and 
without, you know, the C2 

166
00:11:25,520 --> 00:11:26,800
infrastructure, they can't 
operate. 

167
00:11:26,800 --> 00:11:29,200
So those seem to be the two 
pillars that they often go 

168
00:11:29,200 --> 00:11:31,120
after. 
And it's, it's been effective, 

169
00:11:32,080 --> 00:11:34,640
You know, like bot Nets. 
A lot of times these things pop 

170
00:11:34,640 --> 00:11:37,160
back up under different names or
in different ways. 

171
00:11:37,640 --> 00:11:42,000
But it's always nice to see 
these disruption efforts target 

172
00:11:42,360 --> 00:11:44,800
these kind of networks. 
You know, like I said, there's 

173
00:11:44,800 --> 00:11:47,080
still others out there. 
There's plenty more of these out

174
00:11:47,080 --> 00:11:51,080
there. 
If you want some good insight 

175
00:11:51,080 --> 00:11:56,920
into how exactly they work and 
what kind of scale they have, go

176
00:11:56,920 --> 00:12:00,680
check out the research that 
Census has done on this. 

177
00:12:00,680 --> 00:12:04,240
They've done a ton of good 
research on this. 

178
00:12:04,240 --> 00:12:07,400
They have a lot of really good 
global data on the scale of 

179
00:12:07,400 --> 00:12:10,360
these things. 
I'll, I'll try and post some 

180
00:12:10,360 --> 00:12:12,440
links in the show notes so 
people can see exactly what 

181
00:12:12,440 --> 00:12:15,880
they've done. 
But Census has, you know, some 

182
00:12:15,880 --> 00:12:19,480
of the best visibility in the 
world on these, on these kind of

183
00:12:19,480 --> 00:12:21,880
networks specifically and the 
Internet in general. 

184
00:12:21,880 --> 00:12:24,840
So you can, you can have a good 
look there. 

185
00:12:26,080 --> 00:12:29,320
So those are the two big stories
I wanted to hit this week. 

186
00:12:30,480 --> 00:12:33,360
As I mentioned, I would 
encourage everybody to go check 

187
00:12:33,360 --> 00:12:36,440
out the podcasts we have up this
week with Caitlin Condon from 

188
00:12:36,440 --> 00:12:40,320
Bolt Check. 
We have another Hacker movie 

189
00:12:40,320 --> 00:12:44,600
podcasts coming out next week. 
As I mentioned, not sure exactly

190
00:12:44,600 --> 00:12:45,920
what day we're going to post 
that yet. 

191
00:12:46,760 --> 00:12:48,400
We haven't recorded it yet, so 
we'll see. 

192
00:12:49,080 --> 00:12:54,160
But aside from that, we're going
to have a preview episode for 

193
00:12:54,160 --> 00:12:58,160
RSA, which is a week and 1/2 
from now. 

194
00:12:58,160 --> 00:12:59,800
The conference is a week and 1/2
from now. 

195
00:13:00,160 --> 00:13:02,000
We'll post that towards the end 
of next week. 

196
00:13:03,520 --> 00:13:06,520
Lindsay and I are going to look 
ahead at the show. 

197
00:13:06,520 --> 00:13:09,200
Some of the sessions with the 
major themes are going to be 

198
00:13:10,000 --> 00:13:13,520
maybe have a little fun with 
some of the over the top 

199
00:13:13,520 --> 00:13:18,800
silliness that goes on at RSA in
terms of like vendor hype and I 

200
00:13:19,200 --> 00:13:23,640
the AI theme this year is just 
like completely out of hand. 

201
00:13:23,640 --> 00:13:30,400
I knew it would be crazy, but 
just judging from the volume and

202
00:13:31,520 --> 00:13:36,560
the volume of pitches I've 
gotten for meetings and 

203
00:13:37,000 --> 00:13:41,280
interviews and the number of 
those that are connected to AI 

204
00:13:41,280 --> 00:13:43,720
in one way or another, I would 
say it's got to be upwards of 

205
00:13:43,720 --> 00:13:47,560
95% of the total is 1 AI thing 
or another. 

206
00:13:48,120 --> 00:13:52,120
And I'm going to. 
I usually try to avoid the show 

207
00:13:52,120 --> 00:13:55,640
floor, like at all costs. 
I almost never go down there 

208
00:13:56,800 --> 00:14:00,360
unless somebody is forcing me to
for some reason, but I might 

209
00:14:00,360 --> 00:14:06,000
just do it for like a 10 or 15 
minute spin through to go see 

210
00:14:06,000 --> 00:14:09,840
what the AI hype cycle is like. 
I'm sure it's going to be 

211
00:14:09,840 --> 00:14:13,280
completely absurd. 
Maybe take some video or 

212
00:14:13,280 --> 00:14:15,720
pictures of like what exactly is
happening down there. 

213
00:14:17,120 --> 00:14:19,640
It's going to be pretty wild. 
If you've never actually, if 

214
00:14:19,640 --> 00:14:21,880
you've never been to RSA, 
congratulations. 

215
00:14:22,280 --> 00:14:25,560
If you have never been on the 
show floor, major 

216
00:14:25,560 --> 00:14:30,280
congratulations. 
It is really one of those things

217
00:14:30,280 --> 00:14:34,000
that you just kind of sensory 
overload doesn't even cut it. 

218
00:14:35,320 --> 00:14:39,360
It's actually calmed down there.
There used to be a lot of, you 

219
00:14:39,360 --> 00:14:44,120
know, very questionable things 
happening on the show floor in 

220
00:14:44,120 --> 00:14:46,160
terms of like ways to attract 
people to booths. 

221
00:14:46,560 --> 00:14:48,120
That's gone away in recent 
years. 

222
00:14:48,120 --> 00:14:51,680
Now you'll just see like, you 
know, like C list celebrities 

223
00:14:51,680 --> 00:14:55,280
standing around or, you know, 
maybe an F1 car at somebody's 

224
00:14:55,280 --> 00:15:01,240
booth or you know, somebody from
Mythbusters hanging at a booth, 

225
00:15:01,240 --> 00:15:05,360
which is cool. 
But you know, it's just a lot of

226
00:15:05,360 --> 00:15:08,920
hype and a lot of vaporware and 
a lot of that kind of thing. 

227
00:15:08,920 --> 00:15:11,480
So we'll try and cut through 
some of that with the RSA 

228
00:15:11,480 --> 00:15:14,560
preview. 
And then after after RSA, we'll 

229
00:15:14,560 --> 00:15:19,280
talk more about what actually 
happened there after I actually 

230
00:15:19,440 --> 00:15:22,080
see what what it turned out to 
be on the ground. 

231
00:15:22,080 --> 00:15:24,840
So those are all the things we 
have coming for y'all. 

232
00:15:26,200 --> 00:15:29,400
Look forward to all of that. 
And that's it for this week. 

233
00:15:29,400 --> 00:15:31,440
Have a great weekend. 
Talk to you next week.

