CyberWire Daily - CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]

Episode Date: August 30, 2026

In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and ...the future of cyber espionage over the past decade. Join Dave and Maria as they explore how geopolitical factors, organizational professionalism, and emerging technologies like AI are shaping cybersecurity threats. Together, they talk about: The shift in attribution practices over the last 10 years. The role of nation states and organized crime in cyber threats. The impact of AI and emerging technologies on cyber warfare. The challenges of naming and shaming threat groups. The professionalization and organizational evolution of APT groups.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Oh, and welcome to this special edition. I'm Maria Vermazes. And in today's episode, I'm speaking with host of the Cyberwire Daily, Dave Bittner. We're continuing our celebration of 10 years of the Cyberwire Daily in our chat today. Our topic of conversation for today are 10 years of emerging threat actors and APTs. Here's our chat. It is my distinct pleasure once again.
Starting point is 00:00:55 to welcome back the host of the CyberWire Daily, the one and only Dave Bittner. Hello, Dave. Hello, good to be back. Thank you yet again for joining me as we continue to celebrate 10 years of the CyberWire Daily. Can you believe it? I still cannot. No, the time has flown by. Every time I say it, I ask you, can you believe it? I still can't.
Starting point is 00:01:16 I still can't believe it. Keep trying one of these times you'll convince me. Maybe by December, because by then by then it'll be 11 years of the CyberWire Daily. Right. So it'll be factually correct to not believe it. Anyway, so for our 10-year anniversary chat for today, we're going to talk about advanced persistent threats, or APTs and threat actor groups.
Starting point is 00:01:38 And this is a subject area that I think a lot of people, they're fans, people have fendoms for some of these groups. Yeah, which fair. I don't know how else to describe it, just there's almost a parasocial relationship in some of these situations with some of these groups. That is not the case for us. We're not fans of the work that they do because they're very harmful.
Starting point is 00:02:00 No, but we do have our favorites. We do. It's true. Because instead of talking about like a technical thing, we're talking about groups of people and their motivation. So we can get into psychology here. It's fascinating. So why don't I start with something high level
Starting point is 00:02:16 to start us off as for a question? So as you look back on the last 10 years, what do you think about changes in the threat actor landscape? just super high level. Hmm. Well, I mean, I think it was about 10 years ago that this public attribution of nation-state activity
Starting point is 00:02:33 became a lot more common. And the APTs became recognizable brands rather than mysterious anonymous attackers. And I think we saw that governments and vendors and researchers all became more willing to publicly attribute these campaigns. And then we also saw the emergence of coordinated public advisories in international cooperation. So, you know, to me, my education on this is I was getting started on the cyberwire and getting up to speed and had the good fortune of having folks around me who knew a lot more than I did and had a lot more experience with these things.
Starting point is 00:03:18 How could you not love the bears? Fancy bear, posy bear. Posey bear. right? There's Russian APTs. What a great way. It's kind of like learning your nursery rhymes, you know. They're the three bear, you know, they're cuddly, they're soft. How dangerous could they possibly be? Right. So that was my intro to all this. Yeah. I'm curious as the two really interesting things you mentioned. One is about how attribution changed from we don't do that to, oh yeah, we're going to attribute now. So I wanted to ask you about that. And then I, well, let's get into that one first.
Starting point is 00:03:57 Because that, to me, over the last 10 years, is just a seismic change. I remember when that was considered a super no-no. You just do not attribute. And now I think there's, correct me, if I'm wrong, you would know better than I would, but it seems like there's no hesitation to do that now. What do you think? What's your read on that? Well, some organizations still don't do attribution.
Starting point is 00:04:17 I think, I think like Dregos, you know, the industrial control or the industry, the organization that helps protect industrial control systems, they kind of have it as a policy that they don't do attribution. They don't think it matters. I guess what I wonder is how much of this is marketing, right? Because when we go to the RSA conference and we see vendors who have big giant superhero-looking statues of the APTs, it becomes a way to help market your defenses against them.
Starting point is 00:04:55 The adversary isn't a big, blurry, fuzzy blob on the other side of the world. No, that's fancy bear. No, that's, you know, so now we have the blizzards. And for a while, they had names based on their countries. You know, famously, the joke around the office was if there was ever a Canadian one, it would be apologetic beaver. Yeah, you kind of understand from the infosec company marketing team point of view that they're probably relieved they don't have to try and market a CVE or, you know, some script kiddies,
Starting point is 00:05:32 terrible elite speak name. Like we have fancy bear or whatever we can use it for them. The job is easier now. There's still plenty of that. There's no shortage of leet speak and, you know, you've heard me complain more than once that no one thought that someone in the world would have to pronounce this name when they named it. And unfortunately, you know, sometimes that burden falls on me to try to figure out how to pronounce a string of letters and numbers. I often come to you.
Starting point is 00:06:03 Because you have, don't I? You have more experience. I was perched in those fires. It's true. Yes, you're much better at decoding. Maria, what do you think they're going at here? Most of the time, you get there before I do. My spidey nerd sense is, you know, tingling like this kind of thing.
Starting point is 00:06:19 Yeah, I mean, a lot of the times it wasn't meant to be right out loud. That's very true. It's just the fact. Somebody thought of it at three in the morning and was like, that sounds cool. Yeah, yeah. I was doing an interview just earlier today about this malware group called God damn. That's the name of the group. God damn.
Starting point is 00:06:38 We're going to get in trouble. Someone's going to yell at us for saying that on the show. Well, when we mention them on the Daily Podcasts, because it's a family show, we refer to them as the gosh darn ransomware group, which, you know, doesn't give them quite the street cred that they have with their real name. But the person I was talking with today, the researcher, we both agreed that maybe it's gotten to the point where these groups are just trying to punk us because they know we have to say these names out loud.
Starting point is 00:07:04 And I wonder, you know, how soon are we going to just get the most, I don't know, disgusting vulgar names, just because somebody, again, somebody has to say it out loud. out. Yeah, somebody is going to be at a board meeting saying, so we got poned by this bleep-dip-de-bleep group. Right. You know, it's just, yeah. Yeah. Yeah. What do you think has led to not just attribution, but also this coordinated naming and shaming? I mean, is this all coming from, you know, federal governments doing a fantastic job with the private sector? Like, what do you attribute to this? I think it's a big part of it. I think there's been better intelligence sharing over the years between, well, amongst government organizations, but also between the government and the private sector.
Starting point is 00:07:50 I also think we've got much better confidence in attribution than we ever did. We know what to look for. We know the signs of one organization or another. So I guess the kind of table stakes when it comes to attribution has gotten much more routine. And I think more than ever people see strategic value and exposing these adversary operations publicly. They see it, and I don't think they always felt that way. I think it was spy versus spy tradecraft.
Starting point is 00:08:26 I won't say there was honor among thieves, but there were things that were not spoken of because you wanted to keep your cards close to your vest, I suspect. Yeah, no, I could see that. And I'm wondering if you noticed a shift, over the last 10 years of when stories were less about really tactical level, this specific thing has happened. This is what you need to do to mitigate versus there is a set of actions that is now happening
Starting point is 00:08:56 based on this nation state group or that sponsored group or, you know, we're talking much more strategically out loud now. Have you been noticed? You've sort of touched on that. I'm just wondering if you've been noticing that becoming, I don't know if it's the majority of what you're seeing now or just more of it. I'm just curious if you've noticed a shift.
Starting point is 00:09:17 I would maybe a way to categorize it is that we have definitely seen the professionalization of APT operations over the past 10 years or so. And so, you know, it's an interesting question to ask. Have the attackers become dramatically better or have they simply become more disciplined? I would say it's a bit of both. But a lot of the innovations have been organizational rather than purely technical. They're running like a business. They have marketing teams.
Starting point is 00:09:47 You know, there's there's the hardcore coders who are getting this stuff done. But there's a whole business side to this now. They're teams. They're not just individuals, even just for the commercial ransomware operators. So I think mature software development practices, we're seeing those outside, I'm sorry, mature software development practices. We're seeing those both inside and outside of espionage operations. I'm wondering, as you reflect, on how much of what you've been covering is basically espionage operations or touches on it. Is it more or less than you would have anticipated, do you think, when you started this?
Starting point is 00:10:27 Well, I think when I started this, we were just at the leading edge of ransomware really becoming a thing. And as you and I have talked about, I think, on one of our previous episodes, we weren't sure that ransomware was going to become a thing. I thought many of the people I talked to thought that crypto mining was going to be the thing and ransomware is going to fade away. And of course, that's not what happened. Ransomware went into high gear and we got these just huge dollar amounts going after big organizations. So I think in terms of espionage, the rise of, again, professionalism, the rise of, can we call it mob-like organizations with ransomware, the global growth of ransomware? I don't think espionage has gone away, and there's probably more espionage than ever,
Starting point is 00:11:24 because it's been accelerated by all the capabilities that we now have, and let's not talk about AI yet. But I just think this whole other industry popped up alongside of it that's able to use a lot of the same tools. certainly some of these folks who are doing ransomware came out of the espionage community right no there's no doubt about that so they kind of go side by side we hear stories about people who are probably working for the government but moonlighting on the side to make some extra money and their government handlers are looking the other way let them do it use some of the tools use some of the tradecraft so yeah there's definitely some blurriness there but i don't
Starting point is 00:12:09 I don't think anything shifted away from espionage. I just think they're both happening now, probably more than ever. Has it surprised you that these lines have been getting so blurry, you know, over the course of these years as you've been covering things? I'm just wondering if I spoke to you 10 years ago, I would imagine a lot of, I would imagine things like Patch Tuesday kind of coverage would have been, yeah, that's going to be the staple of what we do versus where we are now, where we're talking a lot about more geopolitics. more regularly. I mean, that feels just so much more relevant now. The sophistication on
Starting point is 00:12:45 certain levels. Sometimes it feels like just calling it cybersecurity feels too minimal for the scope of really what's being discussed a lot of the time. It's much broader, but it's all relevant. Has that surprised you? It surprises me. I think in some ways, one of the things I noticed early on and again when I was getting up to speed this was a question I asked my mentors pretty regularly which is why are governments including the U.S. government so reticent to draw lines in the sand and say you will not cross this line in the cyber domain we just don't really do that and the most common answer I got was they don't want to draw lines because they don't want to have lines that they can't cross. They want to be able to use these tools on the offensive side. So if we keep
Starting point is 00:13:39 everything fuzzy, it's harder to blame us for something or put a bull's eye on our back for having used the same tools. So are there things that I think we could all agree should be off the table, ransomware on hospitals? Yeah. We're still not there yet. They have a good old colleague who's cybersecurity researcher who famously says that there are certain bad actors who deserve having their front door breached by a highly precise missile. Yeah. But we're not there yet. There's no line where if you cross this line, you will generate kinetic response.
Starting point is 00:14:23 I think that's just the state of the game now. I'm not sure what it would take to change that. Because, boy, we're seeing a lot of stuff all over the world these days, aren't we? when it comes to cyber capabilities crossing over into the real world and into the kinetic world. And I don't see that changing anytime soon. I guess, well, I wonder if it will take some kind of a big event. Everybody talks about Cyber Pearl Harbor, you know, that kind of thing, or a Cyber 9-11. I'm not exactly sure what that would be or could be anymore.
Starting point is 00:14:57 Everybody has their own ideas. But I guess what I'm getting to is that there's a lot of. lot of benefit, there's a lot of strategic benefit and ambiguity when you're a nation state. And so maybe it's just a gentleman's agreement that this is how we're going to run things. I don't know for sure, but that's something I wonder about. Yeah, I also wonder how much of this maybe was just happening behind the scenes, you know, out of the public eye, in essentially just the military space that us civilians, we just weren't privy to.
Starting point is 00:15:35 And now it's just more public and how much. This is one of those things I will probably never know the answer to. I'm not part of that world. But I do wonder about it sometimes about maybe we just didn't know what was going on. Yeah. If you had to choose, I don't know, this may feel like an unfair question. If you had to choose an APT or a threat actor group, something from the last 10 years that stands out in your mind as either
Starting point is 00:16:03 the story had a lot of legs, as we might say in the industry, or it represented a huge shift, a paradigm shift, or something like that. I'm just curious if any stand out in your mind, because there have been a lot, and heaven knows there's been a lot of fun names out there, but I'm curious if there's just the one that stands out to me. No, I mean, again, you know, I like the bears.
Starting point is 00:16:25 Just I'm attracted to them just for aesthetic reasons, you know, cozy bear and fancy bear. and I think the long-time adversarial relationship we've had with the Russians and before that the Soviets and the Russian bears and all that. I just find that attractive. Whether or not we would categorize them today as being at the top of the heap, I don't know. I think the shadow brokers were certainly, they made their mark. You know, we did a whole parody of them. They were so well known at the time.
Starting point is 00:17:02 They've kind of faded away. I haven't seen much from them lately. But if you had a list of who were important groups like that, they certainly made a name for themselves. I don't know. I mean, it seems to me part of what's happened with the naming is even that's gotten more fuzzy because every group now, you know, Microsoft and Crowdstrike, and they all want to have their own naming system be the standard.
Starting point is 00:17:31 Yes. And it's so aggravating that it becomes a chain of names. Right, because now we say, you know, Fancy Bear, also known as, also known as, also known as, I kind of wish that maybe, I don't know, Sisa, who are in charge of, or NIST or somebody came up with a standard naming framework that everyone could agree to. I think Microsoft tried to do that. There's some logic behind their naming system, but their business adversaries
Starting point is 00:18:04 aren't going to take on Microsoft's naming system as a standard. They're just not going to do it. It's a poison well. Yeah, there's just too much marketing rolled into these things now. So what's the old saying about, you know, if you get together and create a common standard, now you've got all the old standards plus the new common one. Yep.
Starting point is 00:18:23 My favorite XKCD comic right there. Yeah, that's the one. I have it on my fridge at home because it's just, it's relevant. I know that's extremely nerdy, but it's just, it's so relevant to everything. I'm sure many of our listeners are furiously nodding their heads and agree because they have the same one. Who doesn't have an XKCD comic on their fridge at home, honestly, right? To the wall or something, right? The break room.
Starting point is 00:18:45 Yeah, for sure. Yeah. Well, Dave, I know I've been picking your brain about this. I'll leave you with one last question. and this is the looking ahead question. I wonder where you think the next threats, the next APTs, the next threat actor groups, where are those going to come from?
Starting point is 00:19:05 Is it going to still be nation states, or are we moving past that or evolving into something worse? Well, I think it's probably going to be more of the same for the next few years. I think the APTs are going to adapt to new technology and of course the big new technology is agentic AI. Oh, I tried not to bring it up and now.
Starting point is 00:19:28 Oh, sorry. Wow, we were so close. So close. So close. So close. So last question. I ruined it. And I think that's largely a velocity issue, right? Stuff's just going to come at us faster and more consistently with more vigor. So the defenders are going to have to run at a higher speed. But I think the defenders are going to continue to do what they do.
Starting point is 00:19:52 they're going to improve the collaboration, they're going to improve the visibility. And hopefully these AI systems will do a better job of blocking and tackling along the way. But I think in the end, this contest between the attackers and the defenders, it's really about continuous adaptation rather than decisive victories. It is cat and mouse, right? And I don't think it's not going to end any time soon. I think the players around the world, are going to continue this blend between espionage and state craft and doing things for profit.
Starting point is 00:20:28 I mean, look at North Korea, right? They have an incentive to make money that's different from a lot of the other nation states. So they're kind of an edge case. But there are plenty of nations out there who could use a few more bucks in their coffers. And this is a pretty easy way to come at the big rich nations of the world. I think that blending is going to continue. Yeah. Yeah.
Starting point is 00:20:52 Yeah. Well, anything else do you want to leave the audience with Dave or should we close out? I think it just this notion that while the tools are evolving, that the fundamentals of espionage, of trust and resilience, those are the things that continue to define the landscape. And I think that's what the future holds for us. I don't think that's going to change. So will it evolve for sure. but I think we've got a pretty good idea where we're headed now when it comes to these things. I hope.
Starting point is 00:21:26 Hope. We'll see, right? Here's hoping. Well, Dave Bittner, the host of the CyberWire Daily. Thank you, as always, for talking with me. And again, congratulations on a wonderful 10 years. No, thank you. The pleasure is mine, as always.
Starting point is 00:21:41 Thanks for joining me today. We'll see you next time.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.