1
00:00:12,480 --> 00:00:14,320
Hello and welcome to the 
Decipher Podcast. 

2
00:00:14,320 --> 00:00:17,160
I'm Dennis Fisher. 
We have a lot to get to today. 

3
00:00:17,160 --> 00:00:19,800
There's been quite a bit of 
security news this week, some 

4
00:00:19,800 --> 00:00:22,200
good, some bad. 
As usual. 

5
00:00:23,120 --> 00:00:26,480
Before we get started, just a 
little bit of housekeeping. 

6
00:00:26,840 --> 00:00:29,760
The ways that you can reach us 
haven't changed. 

7
00:00:30,240 --> 00:00:39,560
You can reach me at 
dennis@decipher.scandouryoutubechannelisyoutube.com/decipher

8
00:00:39,680 --> 00:00:44,800
SEC SEC and you can find us on 
all of the normal social media 

9
00:00:44,800 --> 00:00:50,520
channels, Twitter at, Excuse me,
Twitter, Blue Sky, Mastodon at 

10
00:00:50,520 --> 00:00:53,280
Decipher SEC as well. 
So we'd love to hear from you. 

11
00:00:53,720 --> 00:00:55,640
It's always great to hear from 
the listeners and the readers. 

12
00:00:55,640 --> 00:00:59,760
So feel free to send us a note 
or hit us up on on any of those 

13
00:00:59,760 --> 00:01:03,080
platforms if there's things 
you'd like us to cover or any 

14
00:01:03,640 --> 00:01:06,560
folks you'd like to hear on the 
podcast, anything like that. 

15
00:01:06,560 --> 00:01:08,920
We're open to all of it. 
So feel free to get in touch. 

16
00:01:10,480 --> 00:01:13,000
So several things I wanted to 
get to this week. 

17
00:01:14,360 --> 00:01:16,560
First of all, probably the 
biggest story of the week, at 

18
00:01:16,560 --> 00:01:22,120
least in terms of the potential 
impact is an operation that 

19
00:01:22,120 --> 00:01:26,760
Microsoft executed with some law
enforcement agencies here in the

20
00:01:26,760 --> 00:01:31,600
US as well as abroad in 
disrupting cybercrime as a 

21
00:01:31,600 --> 00:01:33,760
service platform called Red 
VDSI. 

22
00:01:35,040 --> 00:01:37,840
Have to confess, this is one of 
those cybercrime platforms I was

23
00:01:37,840 --> 00:01:41,520
not familiar with. 
But the operation and sort of 

24
00:01:41,520 --> 00:01:45,080
scope of work of these kind of 
platforms will be familiar to 

25
00:01:45,280 --> 00:01:50,920
most of you. 
I think it's a pay as you go 

26
00:01:51,240 --> 00:01:56,280
service that rents virtual 
machines and other tools to 

27
00:01:57,240 --> 00:02:00,200
threat actors of all stripes, 
mostly cybercrime groups. 

28
00:02:00,200 --> 00:02:04,800
It looks like Microsoft have 
been tracking this platform. 

29
00:02:04,840 --> 00:02:09,039
And I think one of the reasons 
that Microsoft took a took a 

30
00:02:09,039 --> 00:02:13,360
specific interest in it is that 
a lot of the virtual machines 

31
00:02:13,360 --> 00:02:18,520
that the platform ran used 
unlicensed Windows software, 

32
00:02:18,560 --> 00:02:21,760
which as you can imagine, 
Microsoft's lawyers take a dim 

33
00:02:21,760 --> 00:02:25,280
view of that sort of thing. 
And the company has a a pretty 

34
00:02:25,280 --> 00:02:30,360
long history of going after, you
know, all kinds of groups that 

35
00:02:30,360 --> 00:02:33,320
use any kind of unlicensed 
Microsoft products. 

36
00:02:33,320 --> 00:02:36,000
So this is this is one of those 
incidents. 

37
00:02:36,000 --> 00:02:40,040
It looks like in their analysis,
Microsoft said that they track 

38
00:02:40,040 --> 00:02:44,000
this threat actor as Storm 
247-O. 

39
00:02:45,240 --> 00:02:50,880
They've observed many cybercrime
actors using this platform and 

40
00:02:51,240 --> 00:02:58,200
they also have associated it 
with the raccoon Office 365 

41
00:02:58,200 --> 00:03:01,480
fishing service, which was taken
down quite a while ago. 

42
00:03:02,920 --> 00:03:08,840
Red VDS launched in 2019 and 
it's been operating since then. 

43
00:03:09,240 --> 00:03:11,280
It doesn't seem to be super 
stealthy. 

44
00:03:12,040 --> 00:03:19,400
It uses a company that purports 
to be in the Bahamas as its its 

45
00:03:19,640 --> 00:03:24,840
operating entity. 
And Microsoft went after this 

46
00:03:24,840 --> 00:03:28,480
organization with legal means as
well as seizing the technical 

47
00:03:28,480 --> 00:03:33,440
infrastructure, which is a kind 
of a typical way that they and 

48
00:03:33,440 --> 00:03:36,360
other organizations go after 
cybercrime groups, especially 

49
00:03:36,360 --> 00:03:40,960
these phishing as a service, 
malware as a service, any of 

50
00:03:40,960 --> 00:03:44,000
these cybercrime hosting 
services. 

51
00:03:45,200 --> 00:03:47,440
That's one of the ways that they
go after them both with legal 

52
00:03:47,440 --> 00:03:51,560
means and seizing their their 
actual physical infrastructure. 

53
00:03:52,320 --> 00:03:54,800
So this is one of those 
operations. 

54
00:03:54,800 --> 00:03:57,000
We have a story up on it on the 
site that you can read. 

55
00:03:57,000 --> 00:03:58,680
I'll put that in the show notes 
as well. 

56
00:04:00,160 --> 00:04:03,560
There's a bunch of different 
ways that threat actors were 

57
00:04:03,560 --> 00:04:06,000
using the red VDS 
infrastructure. 

58
00:04:06,920 --> 00:04:11,880
One of the main ways was in 
business e-mail compromise or 

59
00:04:11,880 --> 00:04:16,079
BEC scams, it was kind of one of
the primary use cases for this 

60
00:04:16,079 --> 00:04:20,000
platform. 
They would gain access to target

61
00:04:20,000 --> 00:04:23,680
e-mail accounts, you know, 
monitor the conversations and 

62
00:04:23,680 --> 00:04:27,240
then sort of insert themselves 
into those conversations as a 

63
00:04:27,600 --> 00:04:33,040
trusted party to redirect 
payments, you know, to another 

64
00:04:33,040 --> 00:04:37,560
bank account or wire transfer 
service, which is a typical 

65
00:04:38,600 --> 00:04:41,080
structure of ABEC scam. 
This is just one of the ways 

66
00:04:41,080 --> 00:04:44,280
they were enabled. 
This platform was also used for 

67
00:04:44,280 --> 00:04:49,120
large scale phishing attacks as 
well as payment diversion scams 

68
00:04:49,120 --> 00:04:53,000
tied to real estate 
transactions, which is, I don't 

69
00:04:53,000 --> 00:04:55,160
know if up and coming is the 
right phrase, but it's one of 

70
00:04:55,160 --> 00:05:03,920
those use cases for phishing and
other attacks that are becoming 

71
00:05:03,920 --> 00:05:09,760
more prevalent instead of just 
the typical targeting of SMBs or

72
00:05:09,760 --> 00:05:12,960
even enterprises with BEC scams.
The payment diversion for real 

73
00:05:12,960 --> 00:05:17,840
estate transactions, which can 
obviously be very large amounts 

74
00:05:17,840 --> 00:05:20,280
of money, are becoming more 
prevalent as well. 

75
00:05:20,280 --> 00:05:23,680
So that's something that was was
going on in this infrastructure,

76
00:05:23,680 --> 00:05:26,840
Microsoft said. 
And threat actors were also 

77
00:05:26,840 --> 00:05:32,560
using this infrastructure to 
host their own C2 infrastructure

78
00:05:32,560 --> 00:05:35,960
and fishing landing pages. 
So, you know, it was one of 

79
00:05:35,960 --> 00:05:39,680
those all around kind of 
problematic infrastructures and 

80
00:05:39,680 --> 00:05:42,000
platforms. 
So it's good to see Microsoft 

81
00:05:42,000 --> 00:05:46,640
taking some action there. 
As I said earlier, they're very 

82
00:05:46,640 --> 00:05:51,400
aggressive in doing this sort of
stuff when it comes to attackers

83
00:05:51,400 --> 00:05:55,840
either abusing Microsoft 
platforms, you know, such as 

84
00:05:55,840 --> 00:06:01,040
Azure, or anything that 
Microsoft happens to own or 

85
00:06:01,120 --> 00:06:03,000
using unlicensed software in any
way. 

86
00:06:03,000 --> 00:06:06,680
Microsoft really goes after 
those groups aggressively, as I 

87
00:06:06,680 --> 00:06:08,600
said. 
So it's not surprising to 

88
00:06:08,600 --> 00:06:11,600
Microsoft to see Microsoft do 
this, but it's always heartening

89
00:06:11,600 --> 00:06:16,080
to see things like this get 
taken down and disrupted. 

90
00:06:16,080 --> 00:06:18,760
So that was good to see. 
You can read the story that's up

91
00:06:18,760 --> 00:06:20,360
on the Decipher site right now 
as well. 

92
00:06:20,360 --> 00:06:26,600
So another interesting story. 
I mentioned last week that Cisco

93
00:06:26,600 --> 00:06:30,760
Talos had released a really good
research paper on a new Chinese 

94
00:06:30,760 --> 00:06:33,280
APT that they had been tracking 
for a little bit. 

95
00:06:33,640 --> 00:06:38,720
And this week they released 
another analysis of another 

96
00:06:38,760 --> 00:06:45,400
suspected Chinese APT. 
Cisco's naming convention for 

97
00:06:45,400 --> 00:06:53,360
these starts with UAT. 
So this one is UAT 8837 and they

98
00:06:53,360 --> 00:06:58,000
assess with medium confidence 
this is a Chinese Nexus actor, 

99
00:06:58,000 --> 00:07:04,040
but it has all the hallmarks of 
that and the TTPS are are pretty

100
00:07:04,040 --> 00:07:12,920
close to a lot of other Chinese 
AP TS and Telos's analysis shows

101
00:07:12,920 --> 00:07:16,480
that this looks like an initial 
access team. 

102
00:07:16,920 --> 00:07:21,280
So this would be one of those 
APT groups whose main job is 

103
00:07:21,760 --> 00:07:25,600
gaining access to target 
organizations, you know, whether

104
00:07:25,600 --> 00:07:28,720
that's an enterprise, a 
government agency, a small 

105
00:07:28,720 --> 00:07:30,640
company, whatever it happens to 
be. 

106
00:07:32,160 --> 00:07:37,440
The Chinese APT ecosystem, as 
we've talked about before, has a

107
00:07:37,440 --> 00:07:42,080
pretty, it's a pretty broad 
umbrella, but it also has some 

108
00:07:42,080 --> 00:07:46,120
pretty specific division of 
Labor in a lot of cases. 

109
00:07:46,360 --> 00:07:50,880
So there will be teams that are 
specifically tasked with initial

110
00:07:50,880 --> 00:07:55,080
access, then they might hand off
that access to a post compromise

111
00:07:55,080 --> 00:08:00,240
team that does the lateral 
movement and reconnaissance 

112
00:08:00,240 --> 00:08:03,520
around that network. 
And then that team may hand it 

113
00:08:03,520 --> 00:08:08,880
off to another third team that 
does the actual collection and 

114
00:08:08,960 --> 00:08:14,280
exfiltration of whatever the 
intelligence and sensitive data 

115
00:08:14,280 --> 00:08:17,320
that the the overall group is 
looking for might be. 

116
00:08:17,640 --> 00:08:22,360
So there's a lot of cooperation,
collaboration, but there's also 

117
00:08:22,800 --> 00:08:26,360
often times this division of 
Labor, which is an interesting 

118
00:08:27,280 --> 00:08:30,120
hallmark of the Chinese APT 
ecosystem. 

119
00:08:30,440 --> 00:08:34,880
See it sometimes in the Russian 
ecosystem as well, but it is a 

120
00:08:35,559 --> 00:08:41,760
very well known portion of the 
the Chinese APT ecosystem. 

121
00:08:41,760 --> 00:08:48,040
So this particular actor, UAT 
8837 has the capability to 

122
00:08:48,040 --> 00:08:52,080
exploit known vulnerabilities as
well as zero days. 

123
00:08:52,440 --> 00:08:56,000
So that tells you that they have
access to either they're, 

124
00:08:56,360 --> 00:09:00,480
they're doing their own original
vulnerability research or they 

125
00:09:00,480 --> 00:09:05,080
have access to that research 
that's being done by, you know, 

126
00:09:05,080 --> 00:09:09,240
a sister group in their, under 
their umbrella, which, you know,

127
00:09:09,240 --> 00:09:12,480
is another typical thing you see
with the Chinese groups. 

128
00:09:14,360 --> 00:09:18,120
This group has been targeting 
critical infrastructure 

129
00:09:18,680 --> 00:09:22,640
organizations in North America. 
So I would encourage folks to go

130
00:09:22,640 --> 00:09:25,640
and read Talos's analysis of 
this. 

131
00:09:26,120 --> 00:09:31,600
It's, as usual, very well done. 
And it, it lays out a bunch of 

132
00:09:31,600 --> 00:09:37,560
the tools and pieces of malware 
that this group use uses, Excuse

133
00:09:37,560 --> 00:09:41,360
me. 
And you know, some of which is 

134
00:09:41,520 --> 00:09:46,840
custom malware and custom tools,
some of which is known to other,

135
00:09:47,040 --> 00:09:49,920
you know, or used by other 
groups or some of which is 

136
00:09:49,920 --> 00:09:53,680
legitimate tools that are, 
they're just misusing as is seen

137
00:09:53,680 --> 00:09:55,240
a lot in these operations as 
well. 

138
00:09:56,560 --> 00:10:01,880
And they have a good breakdown 
of the way that this this team 

139
00:10:01,880 --> 00:10:05,840
does hands on keyboard work 
after they're into a target 

140
00:10:05,840 --> 00:10:07,680
network, which is always 
interesting to see. 

141
00:10:07,680 --> 00:10:10,640
So I'd encourage folks to go and
read that as well. 

142
00:10:12,280 --> 00:10:15,840
And the third story I wanted to 
mention, and this is a really 

143
00:10:15,840 --> 00:10:19,960
interesting one for me, I have 
like this weird affinity for 

144
00:10:20,960 --> 00:10:25,160
hardware based vulnerabilities. 
You know, you can think back to 

145
00:10:25,160 --> 00:10:28,720
things like Spectre and Meltdown
and a lot of the side channel 

146
00:10:28,720 --> 00:10:33,160
attacks or speculative execution
attacks that we've seen over the

147
00:10:33,160 --> 00:10:36,440
last 15, I guess years, 
something like that. 

148
00:10:37,480 --> 00:10:41,880
They're always fascinating to 
me, even though the depth of 

149
00:10:41,880 --> 00:10:45,400
technical knowledge needed to 
understand them is not something

150
00:10:45,400 --> 00:10:49,200
that I usually have. 
They're often like way over my 

151
00:10:49,200 --> 00:10:52,480
head in terms of the actual 
understanding of how these 

152
00:10:52,480 --> 00:10:56,000
attacks work. 
But this week there was an 

153
00:10:56,000 --> 00:10:59,040
interesting vulnerability. 
It's not a side channel attack 

154
00:10:59,040 --> 00:11:01,800
or a speculative execution 
attack. 

155
00:11:02,240 --> 00:11:06,320
It's a vulnerability that a team
from a German Research Institute

156
00:11:08,120 --> 00:11:10,160
disclosed this week. 
And it's called Stack Warp. 

157
00:11:11,240 --> 00:11:13,720
And I'm just going to read the 
the simple explanation that they

158
00:11:13,720 --> 00:11:17,080
have on their page. 
It's a security vulnerability 

159
00:11:17,080 --> 00:11:22,000
that exploits A synchronization 
bug present in all AMD Zen One 

160
00:11:22,000 --> 00:11:27,400
through 5 processors. 
In the context of SEVSNP, this 

161
00:11:27,400 --> 00:11:31,280
flaw allows malicious VM hosts 
to manipulate the guest VM stack

162
00:11:31,280 --> 00:11:34,120
pointer. 
This enables hijacking of both 

163
00:11:34,120 --> 00:11:37,240
control and data flow, allowing 
an attacker to achieve remote 

164
00:11:37,240 --> 00:11:41,600
code execution and privilege 
escalation inside a confidential

165
00:11:41,600 --> 00:11:44,120
VM. 
So that's the technical 

166
00:11:44,120 --> 00:11:46,120
explanation. 
That's their short version of 

167
00:11:46,120 --> 00:11:47,640
it. 
They have a very detailed 

168
00:11:47,640 --> 00:11:52,360
research paper that's online and
they're presenting this work at 

169
00:11:52,360 --> 00:11:54,280
USENIX in a little in a few 
months. 

170
00:11:55,520 --> 00:12:00,240
So so AM DSEV. 
If for people that aren't 

171
00:12:00,240 --> 00:12:05,320
familiar is AMD secure encrypted
virtualization technology which 

172
00:12:05,320 --> 00:12:10,760
is ACPU extension that enables 
you to use secure virtual 

173
00:12:10,760 --> 00:12:15,160
machines in the presence of an 
untrusted hypervisor. 

174
00:12:15,160 --> 00:12:19,480
So this is useful if the 
hypervisor might be compromised 

175
00:12:19,480 --> 00:12:24,400
or something along those lines. 
So this is not, as I said, it's 

176
00:12:24,400 --> 00:12:29,000
not a speculative execution or 
side channel leak or anything 

177
00:12:29,000 --> 00:12:32,440
like that. 
It's a hardware bug in a MDCPUS.

178
00:12:33,320 --> 00:12:37,720
The good news is that AMD has 
released fixes for the effective

179
00:12:37,720 --> 00:12:41,320
processors. 
So those are available. 

180
00:12:42,200 --> 00:12:47,760
There's, as I mentioned, a very 
detailed research paper on this,

181
00:12:47,920 --> 00:12:50,840
and I would encourage folks to 
go and have a look at that. 

182
00:12:52,000 --> 00:12:56,160
Fundamentally, you know, these 
hardware bugs are very, very, 

183
00:12:56,160 --> 00:12:58,920
very difficult to find. 
That's why you don't see a ton 

184
00:12:58,920 --> 00:13:03,320
of them and often quite 
difficult to exploit. 

185
00:13:04,720 --> 00:13:07,760
The good news is that this 
research team said that they 

186
00:13:07,760 --> 00:13:10,640
have no evidence of exploitation
in the wild yet. 

187
00:13:10,840 --> 00:13:13,520
Obviously that does not mean 
that it has not been exploited. 

188
00:13:13,520 --> 00:13:15,320
It just means there's no 
evidence of it. 

189
00:13:16,720 --> 00:13:19,840
But the it's good news that 
there's no evidence of it. 

190
00:13:19,840 --> 00:13:26,320
Obviously there is a CVE for it.
It's 2025-29943 if you want to 

191
00:13:26,320 --> 00:13:29,880
go read that. 
AMD has a security advisory out 

192
00:13:29,880 --> 00:13:32,840
as well. 
But this is one of those things,

193
00:13:32,840 --> 00:13:36,000
you know, I spent a lot of time 
reading this just to get the lay

194
00:13:36,000 --> 00:13:41,280
of the land and see how serious 
it was in, in how widespread 

195
00:13:41,440 --> 00:13:44,240
the, the issue was. 
It's pretty widespread for, for 

196
00:13:44,240 --> 00:13:46,040
machines that run AMD 
processors. 

197
00:13:46,040 --> 00:13:50,240
But as I said, there's a, 
there's a fix available from, 

198
00:13:50,320 --> 00:13:53,320
from AMD, which is the good 
news. 

199
00:13:53,320 --> 00:13:55,680
So folks should go and check 
that out. 

200
00:13:55,840 --> 00:14:01,440
Stack Warp is the name of the 
bug and you can find the the 

201
00:14:01,440 --> 00:14:06,320
research at stackwarpattack.com.
So go have a look at that. 

202
00:14:06,320 --> 00:14:08,920
I'll drop the the link in the 
show notes as well. 

203
00:14:10,040 --> 00:14:13,560
So that's kind of the the 
overview for this week. 

204
00:14:14,680 --> 00:14:18,080
Be back next week with another 
news Rep podcast. 

205
00:14:18,120 --> 00:14:24,160
And the last thing I wanted to 
mention was the other podcast 

206
00:14:24,160 --> 00:14:27,400
that we released this week was 
my interview with Jeremiah 

207
00:14:27,400 --> 00:14:32,640
Grossman and Robert Hansen. 22 
guys I've known for a very long 

208
00:14:32,640 --> 00:14:36,680
time, more than 20 years 
actually, and who have been 

209
00:14:36,680 --> 00:14:40,080
around the security industry for
much longer than that in fact, 

210
00:14:40,080 --> 00:14:42,360
and have done all kinds of 
different things. 

211
00:14:43,080 --> 00:14:45,960
If you're not familiar with 
their work, I'd encourage you to

212
00:14:45,960 --> 00:14:49,160
go and look them up. 
I can't list it all here, but we

213
00:14:49,160 --> 00:14:53,640
had a really great conversation 
about vulnerability management, 

214
00:14:53,720 --> 00:15:00,080
kind of the cyclical nature of 
not just vendors and enterprise 

215
00:15:00,080 --> 00:15:04,880
security teams trying to address
VM and patch management and 

216
00:15:04,880 --> 00:15:09,360
everything that goes along with 
that, but also the ways in which

217
00:15:10,680 --> 00:15:14,920
people are trying to approach it
now from more of a kind of a 

218
00:15:14,920 --> 00:15:20,920
data backed way and not just 
hey, this is a critical CVSS, 

219
00:15:20,960 --> 00:15:23,280
you know, 9.8 bug. 
We got to go patch it 

220
00:15:23,280 --> 00:15:28,680
everywhere, but more of a, hey, 
this bug isn't being used in 

221
00:15:28,680 --> 00:15:31,560
breaches and here's the result 
of those breaches. 

222
00:15:31,560 --> 00:15:33,640
So we know that it can cause 
actual damage. 

223
00:15:33,640 --> 00:15:37,360
We need to go patch this. 
Or on the flip side of that 

224
00:15:37,360 --> 00:15:40,280
coin, this bug is serious, but 
it's never been used in a 

225
00:15:40,280 --> 00:15:42,400
breach. 
It's there's no evidence it's 

226
00:15:42,400 --> 00:15:44,040
actually been exploited in the 
wild. 

227
00:15:44,680 --> 00:15:47,560
You should get to it, but it's 
not something you should, you 

228
00:15:47,560 --> 00:15:49,800
know, drop everything and go 
patch. 

229
00:15:50,120 --> 00:15:54,360
So I'd encourage everybody to go
have a listen or watch that 

230
00:15:54,360 --> 00:15:55,920
podcast. 
It's on our YouTube channel as 

231
00:15:55,920 --> 00:15:59,120
well, and it was a great 
conversation. 

232
00:15:59,120 --> 00:16:01,880
Those are two of the smartest 
people I know, and it's always 

233
00:16:01,880 --> 00:16:04,880
great to hear their perspective 
on these things. 

234
00:16:04,880 --> 00:16:09,040
We talked a lot about not just 
vulnerability management, but a 

235
00:16:09,040 --> 00:16:12,320
lot about the industry and 
security tools in general. 

236
00:16:12,320 --> 00:16:15,440
So if you're interested in that 
kind of thing, which I imagine 

237
00:16:15,440 --> 00:16:18,920
you are, go have a listen. 
So thanks everyone for listening

238
00:16:18,920 --> 00:16:20,040
here. 
I appreciate it. 

239
00:16:20,120 --> 00:16:21,880
Have a great week and I'll talk 
to you soon.

