Risky Business - Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
Episode Date: August 26, 2026On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, includin...g: Iranian hackers take down a small-scale power generator in the UK Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too. Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet Prompt injection isn’t going away LLMs are deceiving us meat sacks and it’s a worry Much, much more… This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line. This episode is also available on YouTube Show notes Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer Rust supply chain attack linked to North Korean hackers | securityweek.com Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer Hackers infect Android car head units with proxy botnet malware | BleepingComputer ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com
Transcript
Discussion (0)
Hey everyone and welcome to risky business. My name's Patrick Gray. We've got a great show for you this week. James Wilson, as always, will be joining me as co-host. And in the third chair this week, we are joined by Mr. Olly Whitehouse, the chief technology officer for the UK's NCSC. Olly Whitehouse, thanks for joining us.
Thanks for having me, Pat.
This week's show is brought you by Octor. And in this week's sponsor interview, I didn't do this one.
James did this one, and James spoke to Octor's VP of Threat Intel, I think, as his title now.
It used to work with us, actually, the original seriously risky business newsletter creator,
who is now the VP of Threat Intel for Octa. Mr. Brett Winiford joined James to talk through some of their thinking
around the Threat Intel, ITDR sort of stuff.
Octa are providing, you know, some very useful notifications to their customers these days.
and, you know, they've acquired permissor, they're moving into having a bit of a sort of commercial, you know, paid for threat intel practice.
So James and Brett talk about that a little bit later on in this week's show.
But let's get into the news now.
And look, as part of setting this up, you know, every week we get a co-host, we send them a link, which has a run sheet of all of the stuff that we plan to talk about.
Unfortunately, this first item, when you read any of the coverage in it, it is full of,
things like the NCSC has refused to comment.
So I know we can't ask you about this one, Ollie.
So James and I'll discuss it real quick.
Not much detail on it, but there is reporting that hackers linked to Iran,
Iranian linked hackers, conducted some sort of cyber attack
against some small-scale power generator in the UK somewhere.
What type of power generator it is is not specified?
All we know is that it was small and it was down for four days.
That's about the extent of it, right, James?
Yeah, that's the extent of it, Pat.
It just seems like the same old pattern of Iran found something, around messed with something,
and there was consequences.
But, you know, that said, it's not great that they're in there messing with things
attached to a power plant.
Yeah, so the BBC wrote that the, you know, agency that regulates or oversees all this stuff
said the incident had affected a small-scale generator,
and at no point that there been a risk to the wider energy system.
The UK's power network has a number of smaller gas generators,
which provide short-term power when needed.
So I don't know, that kind of reads like the BBC is implying
that it was some sort of gas turbine infill generator.
I mean, there's plenty of them on a grid.
But, you know, I sort of wonder if it could have just been a small-ish-scale solar farm.
I mean, you would still get these headlines.
I do feel like some of the reporting around this has been a bit hysterical.
You know, British power plant knocked offline for four days.
You know, did you get that vibe as well?
I did.
And, you know, I think the, even though it was very much a no comment from various
agencies in the UK. I think there was a telling comment where they said, look, we haven't had any
actual reports of an outage from a regulated power facility. So I think that was a good way of saying,
look, it's got to be small by virtue of the fact that we haven't actually had this as an official
report from an actually large regulated power provider. Yeah. Now, the next thing to talk about,
I mean, it is kind of related, right, which is hackers are using AI to target Siemens PLCs in critical
US sectors. Gee, I wonder who could be doing that. Olli, you know, we've seen,
seen the Americans put out some info here. It's actually pretty good. You know, like they've put
out some really good information, put out some recommendations for what organizations should be doing.
They've also put out a fair bit of information on what the exploitation looks like in this case.
But, you know, what can you tell us about what these, you know, mystery hackers are doing to
Siemens PLCs? Yeah. So I think there's a couple of things in this. So I think first is it shouldn't
come as any surprise that artificial intelligence is being increasingly used in offensive use
cases. I think anyone that has used it has seen kind of the massive productivity gains that it
provides. I think the underlying message I would take from this is it's time to put the end
to PRCs on the internet. And I think anyone that's running kind of industrial control systems
in that way needs to get after it quick. And so I think, you know, when we look at the advice
it's given, it's sound advice, but often that's never the challenge. It's chasing down those that
need to read it, then action it and making sure that they do action it. But, you know,
it's quite clear that there are entrepreneurial and gregarious individuals and groups looking for
this stuff now in 2026. And it's time to get after it. It's the defenders. Well, I mean,
you say now is the time to get PLCs off the internet, but I think the time to get PLCs
off the internet was probably like 15, 20 years ago, if I'm honest. But James, like you've had
to look too at some of the, like what they're actually doing here is actually kind of interesting.
they've got some sort of like, there's this thing called snap7.dl and Python snap7.
You can kind of use these things if you know what you're doing to talk to these PLCs over the internet.
And it just looks like, I don't know, it looks like AI makes doing this sort of stuff easier.
So it's not just about, you know, logging in with default credentials anymore.
You know, with AI, I can read the manual for you and help you figure out how to.
actually do stuff with these PLCs?
Yeah, I think the interesting thing about AI here is it's not, I wouldn't frame it as
its AI is making it easier to do this.
I think for the first time AI is making it possible for attackers to actually go after
these PLCs.
Like I've been fascinated with this over the last week or so, and I've been even looking at like,
what would it take to create a little home lab of PLC so I can mess around with this?
And the answer is, I still can't work that out because this is just such a landscape full of
proprietary protocols and terminology and these esoteric standards.
You know, you look at what an LLM in the hands with someone that understands basics of hacking
it can make you better.
But this is an area where I think the security through obscurity has been the load bearing
part of the infrastructure for so long now.
And now AI has cracked that big time because the obscurity is gone.
A large language model, to your point, can read the manual.
It does understand the standards.
And armed with things like the fact that there's open source libraries for talking,
the bizarro protocols of these things run means that we're going to have a real bad time with
this as long as these things are either on the internet or the hosts that control them are also
readily accessible on the internet. Now I'm guessing, you know, Ollie, you spend your, you spend a
lot of time with your head in this, right? And James and I were having a conversation about this earlier.
And I think one thing that I find really interesting here is the targets that tend to have their
PLCs attached to the internet, right? Tend to not be the super critical ones, right? So it's almost like
you've got these two levels of attacker. You've got the Iranians who just are port scanning for
you know, port 102 or whatever it is. Ah, got one, you know, try a couple of things, try to create a bit
of a mess. But then you've got that next level up, which is, you know, more your vault typhoon
type of activity where you've got attackers who really know what they're doing, who are, you know,
moving laterally through some pretty complicated networks to get proximity to these PLCs, which are
not on the internet, right? And they tend to be the more critical ones. I mean, is that a fair,
sort of description of the landscape at the moment? Yeah, I think that's an extremely fair assessment
of often what we see. And I think kind of James's point is well made. And I think, you know,
we've got to take this as almost a sign of things to come for other esoteric systems. So whilst
it's manifesting today in PLCs and industrial control systems, the fact that we now have
artificial intelligence which distills all human knowledge for a greater or lesser extent
and what that's enabling on the offensive side.
So I think that's right.
But even though, you know, there's still the risk of misconfiguration surprise, shall we say,
even in large producers.
And that's why there's no place for complacency here.
Yeah, yeah.
No, I think you're both onto something with the idea that that obscurity that we've, you know,
I don't know that we've relied on it willingly, but it is protected us somewhat.
I think that is gone.
There's an interesting item here from the record.
that the United States government has charged a bunch of Iranians for hacking various government
agencies, universities and whatnot. This is a campaign that apparently kicked off back in 2013.
17 people have been indicted. Eight of them have been previously indicted in 2018.
I mean, I think if anything, the lesson here is that probably DOJ has been instructed to go and like,
if there are any Iranians you are planning on charging, please go do that.
that's the sort of vibe here.
But these are legit charges against people who've done, you know,
legitimately illegal stuff.
Ollie, what are your thoughts here?
Yeah, I think, you know, more broadly, what we're seeing is kind of the use of
indictments such as this and the legal system to go after kind of cyber adversaries.
And obviously, you know, in part the intent there is to have a chilling effect
and make people reevaluate their life choices.
And so, you know, I think this is a trend.
that we should expect to occur across the globe as people and organizations and states look
to kind of dissuade, deny and degrade kind of adversarial behavior and make sure it conforms
to international norms. But, you know, it's a Trident tested part of statecraft.
Yeah, it is. I mean, I think the thing here is, though, that the Americans are just sort
unrelenting, right? Like, it has been a long time coming these charges, but they, you know,
What is that thing about, you know, you can have a billion dollars, but there's a snail
that will crawl towards you for the rest of your life, and if it touches you, you die.
Like, it sort of feels like, it feels like that's the, that's the vibe if you agree to do
APT operations for enemies of the United States.
Yeah, you don't want to ever go on holiday to extradition country, right?
And so it has a certain curtailment on lifestyle.
Yeah, it's always funny when these guys get busted going to Disneyland.
All righty.
So, what else have we got here?
Oh, the chopped cable. This one's been doing the rounds.
We've linked through to it on the TechCrunch version, but I think it's based on some Bloomberg reporting.
But the idea is here that T-Mobile has opened up about its conflict or its battle against the Salt Typhoon crew,
which apparently involved some of its people traveling to a facility and physically severing a cable.
Now, they probably could have just unplugged it.
is my feeling.
And now they actually have, you know, there's, well, I mean, you know they can unplug it
because they've taken this yellow cable and put it in a frame.
And there's a picture of it in the Bloomberg article.
And it does have a plug on one side.
So you kind of think maybe they could have unplugged it.
But they thought it was going to be a cool opportunity.
It was a big moment.
So, hey, who am I to argue?
But beyond them just severing the cable, you know, what is this story really about, James?
Yeah, it's very performative.
But it's really about the fact that back in 2024, when Salt Toofoon was kicking off
at this particular campaign.
T-Mobile did fare better than others insofar as they actually did detect the activity
at the time.
And I don't know whether it was all the activity, but certainly at that time they were one
of the few telcos that actually spotted something and were able to stop it.
And we've since found out that in fact, that's somewhat the outlier insofar as the salt
typhoon campaign seems to have been quite successful in areas where it wasn't detected.
So that's really the crux of it.
I mean, the fact that it does come down to even in the Bloomberg article,
there's the photo of this framed RJ45 and Twisterpaer cable sliced,
and it's got some big bold headline of Vigilant by design,
secure by action, it really does feel like it's,
well, it's a great story for them to tell internally,
and now they're getting a bit of run of it in the news as well.
Yeah, what do you reckon, Olly? Is this going to be NCSC advice now,
is like get out the scissors to defeat Salt Typhoon?
Yeah, look forward to cyber-insent response scissors near you soon.
But I think there's a point here,
which is this is, I would expect, largely symbolic,
and I deeply want to believe that scissors were used.
But I think the real takeaway for me here is that there are telecommunications operators
with detection capability that can really get after some of the most sophisticated threats.
And that's got to be a win, right?
And I think as the world heads in the direction that it's heading.
Now let's talk about Klop and how utterly predictable the Klop crew is.
And I think that's like, I mean, it's amazing,
because there's been a few years now since they started with the file transfer appliances.
And I interviewed someone, I can't remember, forgive me, I can't remember where they were from.
But they'd actually observed the Klop crew figuring out an O'Day on live targets.
I think instead of like actually just downloading, you know, instead of actually getting the appliance,
I think they were just like hacking away at live ones and eventually someone got a hold of the logs.
But it seems like their whole model is they find an O'Day, get it into a reliable place.
and then off they go doing bulk exfiltration across as many targets as possible,
and they do that first, then they categorise all of the information,
then they go on and do the data extortion part.
The latest campaign, of course, we've spoken about it on the show,
already two software products from a company called PTC.
There's wind chill and flex PLM.
And James, I remember when we spoke about it, you're like, yeah,
that's extremely valuable and sensitive information in these systems,
things like pricing information and whatnot.
not. More and more details emerging here. We've got some good reporting out of
CyberSoup. I guess the thing that I find interesting here is the vendor is being a
little bit coy on how it came to discover this vulnerability, which of course it is
patched. But of course the thing with Klop is by the time anyone knows about the
bug, they've already done all of the data exfell. Actually, Oli, let's start with you on
this. I mean, I'm guessing that this has played out exactly also how you expected
it to and this is just like this crew has come up with a winning formula like what can you even do here
well and i think you know there's a whole cadre of organizations that are all prepared for this threat right
so we've got clop on one hand which have demonstrated the ability as you've said repeatedly to do
vulnerability research exploit development and then do kind of at-scale exploitation of that let's be
really honest here that you know for a vast majority of organizations they are not going to be able to
defend against that. And I think that's the lived reality. And so, you know, what can the majority
of organizations do? Well, I think it goes back to the prepare for breach type kind of response
planning. And that's probably the best thing that most organizations can do whilst making sure
that they have as robust defenses. But really, you know, all bets are off if someone is able to
kind of pop your product and spam the internet. I mean, I feel like we need better access control.
on this sort of enterprise crapware, like, James, does this stuff even need to be on the internet?
I mean, could you gate it past some sort of reverse proxy?
Could you lock it up behind something like knock, knock?
Could you put it behind a VPN?
Like, surely there's something you could do to fix this.
Yeah, this stuff does not belong on the internet at all.
It is inherently an internal-facing tool, but clearly a number of them were, and I would assume
that is where at least the easy amount of exploitation and exploitation is happening.
It does also make me wonder, even if they're not on the internet,
they're probably, you know, they are used by so many people at these organizations,
entire functions, entire organizations.
So a lot of people have access to it.
And so it's probably also the case that even beyond just the ones that are internet exposed,
it's not too difficult for CLOP if they were also able to get access to credentials
that were able to VPNian or some other mechanism to get to these,
that they could exploit an even larger number through that.
Yeah, well, that's depressing.
And I mean, if that's the case, you know, a lot of these architectures, if they're not going to help you unless using MFA resistant orth and like, I don't know. And you just sort of get the impression there's not enough maturity out there in the enterprise anyway to do much about this. I mean, Oli, I know you agree with that. Yeah, very much so. You know, I think we all know in the security community what needs to be done here. And you're bang on, right? These shouldn't be on the internet. There should be strong multifactual authentication, et cetera, et cetera, et cetera. But I think Tom and Memorial tells us again.
that the cliff edge of capability in pretty much all sectors is really quite close to the top.
And so we shouldn't be surprised inevitably either through kind of lexie technology or inability
or lack of knowledge that these things do manifest in practice because people's, you know,
primary focus often is just running their business.
It's not preparing their organizations for the cyber adventures.
Yeah.
Yeah.
Well, let's see which next thing Klopp goes after, right?
because they're always pretty creative at like picking interesting bits of software to go after.
So, I mean, you and I, James had never heard of this stuff before.
And then as soon as you looked into it, you're like, oh, God, like that's, yeah, you don't want that get known.
Sisa has put out some really cool info, really cool write-up on Medusa Ransomware.
Not to be confused with, I think there's another one called Medusa Locker, which is a completely different operation.
But they actually, it's just really good information and really good write-up on TTPs and what they're going after.
headline that bleeping computer has gone after here is Medusa ransomware hit over 500
critical infrastructure orgs obviously not what you want but it's a good write-up of a
what sort of industrialized ransomware kind of looks like right Ollie yeah very much so
and you know I think the thing that stood out for this story for me was the continued
pain the initial access brokers are providing and the complexity of the the ecosystem
so this is industrialized ransomware in in all of its guise is
showing that there is a rich set of interconnections there
which are facilitating this scale and impact.
And unless we get after being able to disrupt that
at any material scale,
it's going to be playing a game of literal whack-a-mole.
Yeah, I mean, I'm jealous a little, I think,
of the access brokers.
I always feel like they've got the coolest job in cybercrime
because they get to just pop a shell and, like, walk away.
They get to pop a shell and then someone gives them money.
I mean, like, that's pretty cool.
But yeah, look, that's just an interesting write-up.
people can find links through to that in this week's show notes.
We've also got some research here, apparently written up by Cybersecurity Dive,
that says that ransomware disproportionately targets medium-sized firms.
This seems to be like something that, like just from us reading headlines and whatever,
it seems to be something that, you know, just anecdotally it sort of feels true as well.
We're seeing less of that big game ransomware.
I think the message has finally gotten through to people in the underground that if you go after big enough targets,
or if you create a big enough ransomware as a service ecosystem, you're going to have problems with governments coming after you in unconventional ways.
That's the sense I get.
There could be other things to it as well, which is, you know, large corporates, their defenses have gotten better.
I don't know that I buy that necessarily.
But either way, it looks like this is a trend that's quite legit.
I'm guessing, Oli, you have access to all sorts of awesome data internally, and you will be able to tell us if this is true or not.
Well, I think this is a broad trend that we see.
And so I think, you know, what I'd say is we'll always see at top of the pyramid kind of big game ransomware events.
But it's also quite clear that as the scale of the affiliate model has grown, that there is a larger concentration in the medium-sized firms.
and that actually yields for them.
So I don't think it necessarily is a surprise.
I think it's more a symptom of the kind of the growing number
and kind of players in this space,
which leads to disproportionate kind of impact here.
But yeah, it tallies with all the data,
which is medium-sized companies.
They typically have a network infrastructure
or systems infrastructure, which is of sufficient size.
They have means to pay,
and so they become victims accordingly.
me. Yeah. Yeah. Now let's talk about, and this one, I'm amazed, man. We are so lucky Microsoft found this one internally.
Because they fixed a CVSS-10 deserialization bug in ANTRA. And you just think, come again. Like, that would have been, in the hands of the wrong people, that would have been, oh my God, a proper planet melter. James. We don't really know all that much.
about the bug here, but geez.
Yes.
Geez.
Like, you know, all as you are customers.
Popped.
Gone.
Exactly, right.
Including Microsoft, mind you, because they dog food, right?
So imagine what you could have done to the supply chain with a CVS 10 out of 10
deserialization bug in ENTRA.
Well, not too much, actually, because GitHub would have been down, so you couldn't actually
distribute your packages.
But jokes aside, yeah, we don't know much, but gosh, I want to know more.
A deserialization bug that's a CVS 10 out of 10 in Entra is in and of itself a little bit of a concern.
Like that should be the domain of things that are getting regularly fuzzed and checked on
because that's such a primary attack surface.
You know, untrusted data in.
You've got deserialization code running and then there's your code execution path.
So, you know, my point here was also that the transparency is good.
I get it.
That's a cultural shift that's important.
But we shouldn't also forget that this is just as useful, if not more useful.
that is this disclosure in the hands of an attacker because it points to the fact that,
hey, there's pretty amazing bugs like a decerealization remote code execution in ENTRI.D.
What else might be lurking that has not been found just yet?
Well, so I know you're doing a lot of vulnerability discovery at the moment,
and one of the things that you've been doing is looking at where various vendors have fixed stuff
and then going around and looking adjacently at, like, you know, what they didn't have time to fix.
And I understand your perspective, but I will also say that you have.
not been in the security discipline as long as Ollie and I have and we remember the bad old days when stuff like this would have been like the idea of Microsoft coughing up
Details on something like this you know just was unthinkable and the problem is once you have that that culture of burying stuff
like all sorts of other bad stuff happens I don't know that I'm explaining this particularly eloquently, but I'm sure
Ollie as someone has been around in this longer than I have you know what I'm getting at here. Yeah and I think
if you work on the basis, this is around what we want is greater transparency in the marketplace
to understand those that are investing, getting after their vulnerabilities, paying down their
levels of technical debt. This is, you know, an exemplar of that behavior. And I think, you know,
could you imagine a world where all vendors did this? And we actually had a full sense of the
kind of the level of vulnerability that was being found and actually remediated. So we could actually
use that as an external measure of sorts if we were on the by side of those solutions. I think
the world would have less of an information vacuum than it does today. And so this type of
behaviour is something that we deeply support on that market incentives piece. Well, I mean,
it's funny there that you said that it's like they're cleaning up technical debt. Considering
ENTRA is like, you know, as your AD, it's basically new, right? Like, really? Yeah, but all software,
as you know, when you write it incurs a degree of technical debt as you start off. No one ever
writes perfect software from the get-go. And so the fact that things have kind of crept
in at some point during that development press,
there shouldn't come as any surprise.
Anyone that can write perfect software,
do drop me a line because I think you are truly a unicorn.
It's also probably, you know,
it's sort of bagat from Active Directory as well,
so you can tell this and probably some scary,
like old, crusty AD code in there somewhere.
But, I mean, look, I got to ask though,
I mean, did you have the same reaction as me,
which is like a CVSS 10 in ANTRA?
And you're like, wow.
I think I'm more balanced in terms of,
I think any product has a potential, shall we say, to have a CVSS-10.
I think Timor Memorial has shown that.
If we go back to back in the day, we had OpenSH with similar,
pretty much every technology that we had seen at some point
either has demonstrated the ability to have or has had had.
So I think I'm less surprised that it came to pass.
I think you have to be an optimist in these roles.
I'm deeply optimistic the fact that it was chased down
and patched and hope they've done variant analysis and eradicated it all similar.
I think that's the point, right, is that they found it internally.
The only reason we know about it is because they coughed it up, so that is actually quite good.
All right, so there's another absolute clangor as well this week, which is in this,
there's a internet key exchange like extension MS, I key, which is, there's a bug in that
one as well, and that is being exploited in the wild.
That's not a good time.
But IKE has always been an absolute dumpster fire, right?
So I don't think we should be surprised by anything here.
Yeah, it's...
So when I was going through reading this,
I couldn't actually get a handle on,
is this truly being exploited?
What is the exploit?
Because what we know is that, yes,
there is a legitimate double-free bug in Microsoft's ICAE extensions.
It's like they've layered a bunch of stuff on top of IKE,
which was already a pretty creaky foundation.
And in that...
In the extension that they've got there, there's a very early part of the protocol where you're just initially setting up the session.
The attacker can do the initialization, then send two fragmented packets that because they're fragmented, the way they reassembled, has a bug, it does a double free.
But just having a double free in a modern operating system does not get you remote code execution.
So there's still a big question mark in my mind as to how have they gone from, how have these attackers gone from, this double free that happens very early on in the protocol.
to apparently being exploited because it is on the Kev
but we don't have details around what that exploitation actually is
but it's in IKEe so if there was ever a part of a code base
that is going to have plenty of other things
that you can leverage and chain together to turn into an exploit
this would be one of the top areas that I would certainly go looking around it
and then probably IPV6 next after that
now we're just going to have a quick chat about some research out of WIS
which has found one of these like supply chain compromises
in the rust supply chain,
they've linked it back to North Korea.
There was a package,
a malicious package was live for 86 minutes,
and it was properly malicious.
It was a little bit malicious.
It was like a proper shell you pretty good immediately,
kind of thing.
And this utility,
it's an array conversion utility called Array ref,
has over 245 million downloads, right?
So I'm guessing they've still got some shells
and some backdoor boxes because of this one.
But I mean, this is like, funnily enough, this isn't even big news, right?
Stuff like this is just Worker Day these days.
It's kind of amazing that it is so Worker Day,
especially when there's some really great tradecraft in here.
Like, as you said, this is not your, this is not like the shyholded worms that we've seen,
where it's like smash and grab, get out there, snap up all the credentials,
or the crypto wallets and then move on and be loud.
If you look at what this actually does, it's proper, like, long-term persistence backdoor
with a lot of different ways that you can then,
get back into that machine, the payload itself in the various runners that it downloads even
have this whole command set that the remote attackers can use to do various things on the box.
And so, yeah, you kind of imagine they've got a ton of shells.
It wouldn't surprise me if they're actually having to use Rust and Array ref as a performant code base
to actually triage and manipulate and to even make sense of the sheer amount of data that they've
been Avel 2X will trade out of this.
Now we're going to talk a little bit about a new prompt injection attack.
I mean, that's basically what it is.
My note on this one is this is not a solvable problem.
Ola, you put a note on this one too, saying that NCSC wrote in December 2025,
the prompt injection is not SQL injection.
It may be worse because you explained that this is in part
because there's no conceptual difference between data and instructions in LLMs.
It's something that we've said on the show a bunch of times.
You're mixing code, you're mixing data, and this is a perfect example of this.
Why don't you actually walk the listeners through exactly how this works?
Because it is actually pretty clever.
Yeah.
Firstly, I think what we see here is kind of large language models being applied on the back end.
And what researchers have increasingly found is you can provide inputs with then instructions to the models on how to treat that input.
And so in this instance, they gave it encrypted data, and then they gave instructions wrapping around.
it on how to decryp that data in order to then internally process it.
And the purpose of doing that is then it circumvents various generally front end classifiers
and other impover validation mechanisms that may exist.
And we actually saw a previous example of this where someone used Morse code in order to
circumvent the kind of the front end.
And so it's the fact that these models can reason and they can do secondary processing.
and obviously they can kind of take instruction from humans and you back it all up.
In this case, basically the attacker is asking the model to construct an encryption key
out of all of the data that they want.
So it does.
It does it.
It just cobbles a lot of,
oh, well, you know, this system needs a key that's made from all of this history
and like these sensitive, you know, I'll put it together so I can read the thing and do my job, right?
But this is the thing.
You read this.
It's really creative, right?
Okay.
And it involves sort of sidestepics and classifiers,
but there's no fundamental fix here, right?
and like they just ain't.
No, and so I think, you know, this is where you start to think about actually how you do segregation on the back end.
So the fact that you're mixing user sessions.
So there was a great challenge that we had this week from a third-party researcher,
which is how do you do user isolation on inference, for example.
And that's, for example, one architectural approach that you may employ here to kind of do that separation.
So there's no actual other user data to infiltrate if you can do in terms of previous sessions.
So this is going to require some further work on that front in order to actually come up with anything that's actually practicable.
But we should not expect this to be the last.
And there can be a lot more creative ways to both get things in and then data out.
Well, I just wonder what prompt injection is going to look like in five years.
It's going to be pretty elaborate, but still possible.
And I think that's the thing.
You know, this is, you know, the AI revolution is real.
It is huge.
It is going to really change the world.
and there's just this absolutely fundamentally
like horrid, unsolvable,
intractable problem with it all.
But I mean, that's it.
You know, as I said on the show once, you know,
like maybe a year ago, our job is not to throw our hands up
and say, oh, well, you know, we can't use it.
Our job is to figure out how we go forward.
Real quick, there is a fishing toolkit out there.
Some of the fishing toolkits these days,
they've gotten so good.
You know, we're seeing a lot of device code fishing and stuff.
and people really getting around the deployment of pass keys
and whatnot as best they can.
In this case, we've got a fishing toolkit
that is part of the initial compromise of the credentials.
It actually enrolls a pass key
on behalf of the attacker into the account.
And this is incredible because it means
if you invalidate those sessions,
the attacker could just come back in with a pass key.
So that's really interesting.
Just wanted to mention it.
We can link through to that one in this week.
show notes we've also got some corresponding
a corresponding story here
looking at password spraying attacks
just going absolutely wild
at the moment this one's actually a little
bit interesting because we're seeing
attackers go after
stuff like what is it like azure or cly tools
which is where they've discovered that's a really
good way to go for it but they're doing it smart
so they're doing stuff like recon on LinkedIn
to construct usernames
based on people's titles
so they'll be like you know patrick.gray
at risky dot biz and then they're using that with commonly used you know password one two three and
throwing that at as your cly i mean i read that and i'm like that's you know that's that's a smart
way to do it i mean did you get that impression james yeah absolutely and even more so some of the
other techniques like going after ropc which is an old antiquated token exchange method which
doesn't by design support mfa and sso and it's it's couch it's technically more of an
authorization method and so that gets around things like even if an organization
has set up conditional access policies and made sure that you are required to use mfa and
SSO, etc. If you happen to have an endpoint or an app that's enrolled and using this old
RPC endpoint, then they've realized that that's exactly how they can get around the fact that,
yes, when you sign in properly, you're required to do MFA, but if you can hit this endpoint,
you can still get tokens and go onward. So it's just, it's like this attacker deeply understands
the authspace, which is great to see. Now, look, speaking of attackers,
standing stuff, someone decided that they wanted to get shells on a whole bunch of web cameras in Russia.
And boy or boy, did they get the shells. So we're talking 14.5,000 Dahua web cameras.
And it feels a little bit like someone in Ukraine doing this, right? Because they started off by just looking at Russian IP space.
I think that meant that they also hit Ukrainian IP space. Because I imagine that's quite adjacent.
and it would be a little bit difficult to completely isolate that.
But then I think at one point they went global,
but then they just wound up focusing more on Russia
and former Soviet territories.
But what I found interesting about this is it wasn't just the case
where they ran one script to go after these cameras.
They did that, you know, default passwords, whatever.
But then they stood up like brute forces.
They did a bit of this.
They did a bit of that.
There were ones that weren't directly exposed to the internet.
I think there was some UP and P shenanigans.
like they just really said,
I want to go out there
and absolutely collect
every one of these that I can.
They exploited some vulnerabilities as well
that you pointed out,
OLLI, were five years old in some cases.
When you look through this,
I mean, for me, when I see a campaign like this
and Hunt.io found like the attacker's directory, right?
Like stuffed full of scripts and whatever.
So this is how we know these wonderful things.
You know, but are you like me
and that you see something like this
and you just go, huh, nice.
Well, I think, you know, we see this mass scale exploitation.
So I think, you know, we've seen similar outside of this type of class of device in set of boxes, DVRs, other internet-connected kind of technology.
So I think whether or not I say nice, I think, you know, you just, you just recognize now that the industrialized nature of exploitation when someone really wants to go after a class of device, you know, can lead to kind of seven.
digits or more of compromised devices is my takeaway.
And it makes me kind of more determined than ever to clean up the UK internet as much
as I can from such devices being internet exposed.
Yeah, I mean, these are like, I mean, it says web cameras,
but I think they're kind of like security cameras in this case, right?
We've seen these become such a thing that people want to get.
I remember helping a country do a bit of an audit, you know,
connecting them with some other people who help them with that.
And yeah, it's just, there's so many of these things on the internet.
So it is interesting.
speaking of iot stuff getting owned this one's real funny it's not it's not as big a deal i guess as
as reported there is a aftermarket android-based head unit for cars right so like a car stereo
android based it's not a factory one in a toyota or in a you know even a chinese car or whatever
it's just one of these ones that you can stick in as an aftermarket unit um somehow this is
research out of Kasperski.
Somehow they noticed,
don't ask me how.
But in June, Kspersky researchers found a rogue
APK file being downloaded
from a legitimate
DOFUN or do fun system app,
TWCOR, which receives instructions
through blah, blah, blah, blah, blah.
Now, Bleeping Computer has actually
contacted the head unit manufacturer and Kasperski
and saying, you're kind of missing some detail
there, like, under what circumstances
were these nasty APKs
being downloaded onto these head?
head units, but the point is, and the interesting thing is that the APK, what it did is it turned
these head units into a node that could do like ad fraud and proxy, you know, be part of these
residential proxy networks, which you're thinking must be when they're at home, you know,
in the garage on the Wi-Fi would be the only way that would be useful.
But you just read this and you're like, man, like, is there anything people aren't putting effort
into owning, was my take, James.
Yeah, I had that reaction and then sort of thought, well,
Well, yes, it's this third-party headset manufacturer, but hold on.
Not with saying the fact we don't know how the APK landed on there,
this is kind of an example of what a supply chain attack might look like in this sort of ecosystem, right?
These devices listen to things like MQTT, which is a queuing system.
If someone could get a malicious message on that bus, it gets picked up by the head unit.
And that seems to be what's happened here.
It's like an actual lull bin, for lack of a better term, in the head unit,
is the thing that did the initial download.
Yeah, but how do you get it to?
What?
The fact that you can is the point, right?
It's like, okay, I've got a fleet of vehicles and I want them to do something bad.
Well, let's go after the bus that they're all listening to and get a message in there, right?
There's just another interesting form of supply chain.
On the flip side, I own a car that unfortunately has Android automotive in it.
And if I was trying to work out if I had been owned, I'd have no chance.
That OS is so horribly contorted into this opaque thing.
You can't, like even if you do find the process list, it's so,
littered with junk.
Razorware and malware would just blend
right in.
That's funny.
Real quick though, because
we were chatting about an Android thing,
there's a
Android malware called Toxic Panda,
and they've just got a cool trick. I just read this, I thought
that's a cool trick. They install a VPN
profile onto infected devices,
and this enables them to actually filter
traffic, which means they can
block the handset from communicating
with the Play Store and also from getting OS updates.
And I just thought, nice.
Olla, you pointed out that you had seen similar tradecraft
from other attackers in the past who firewalled,
added firewall rules to infected hosts to stop them getting patches and whatnot.
Yeah, exactly.
You know, we've seen adversaries use security features on platforms
to disrupt and not integrate the security functionality.
And this is just a kind of a read-across of that.
And as I said in the note, you know, I think we should all expect now that Google is looking at this to understand actually what the response should be because if this starts to catch on when things like Google Play and similar are intrinsic to platform security, there will have to be some type of mitigation one would expect.
Now, talk about someone who's adding features that I don't understand why they need to do this.
A smartphone is the most connected device that you can have.
It can connect via Wi-Fi.
It can connect via cellular networks.
and if it's not connected by either of those things,
then you're obviously not doing your banking on it,
which makes me wonder why someone who's written a banking Trojan
has figured out an exfiltration method that's peer-to-peer
that relies on connecting through Bluetooth BLE
and like, you know, all of these,
it's called the manic Android malware,
which seems a fairly good description.
James, real quick, because we are running out of time.
Do you have any idea here why they built these features?
Because it's confusing me somewhat.
I think I know exactly how this happened.
They said to their coding agent that was helping them create this thing,
they said, hey, is there anything we could do to make this a little bit more resilient?
And it went, you're absolutely right.
Let me create this peer-to-peer exchange.
It's the only way this happened.
You reckon it's vod coded?
100%.
It makes no sense.
You'd have to have such a compromise at scale for this to ever work.
You're not going to get it.
So this is hallucination land.
But what creds are you going to be getting if the thing's bricked from the internet anyway?
Like, it just doesn't make sense.
No, but an LLM asked,
how could I make this more resilient?
We'll find a way.
Yes, that's right.
Real quick to Citrix is urging admins to patch a net scala floor.
You know, I've recently become aware of how much net scalar there is out there,
and it is too much, frankly.
There's a lot of it out there.
But this bug, 2026-19490, can allow remote attackers without privileges to bypass authentication
when the appliance is configured as a AAA virtual server or as a gateway.
So that's a fun one.
So if you're running Netscaler,
it blows my mind how much of this stuff there is out there.
But we're going to wrap it up.
Pretty much.
We've got two more things to talk about.
There's been this story going around the last couple days about Ali Express
doing something weird with playing audio through someone's Bluetooth headset
and using that as a fingerprint technique going after someone.
And it really has done numbers on like Twitter and whatnot.
But you get the sense that the reason it's doing numbers is because people aren't necessarily clear on what is actually involved here.
James, you actually had a look at this and it is not as cool as it sounds, unfortunately.
Unfortunately, not, Pat.
Look, I think it sparks those fears that everyone has about, you know, your phone is listening and it knows what you're doing.
In this case, no.
It's just simply downloading or producing some audio internally in the browser.
it sets the gain to zero for the audio channel. That's how the researcher found it,
because all of a sudden these Bluetooth headphones volume dropped to zero, and he's like,
hey, where'd my tunes go? But what it's really doing is it's kind of like if you got,
if you wrote code to compress an image and then looked at the artifacts in there and
determined, oh, this image has been manipulated on this platform because I know that it
produces those sorts of artifacts, it's doing the same thing but with sound files.
It's just, it's got a known sort of sound file that it trusts, and then it runs it through
the audio engine of the browser and see what
coming out at the other end and says, ah ha,
well, that was touched by this set of
first or third party libraries or this browser
and therefore that's the fingerprint.
It's actually quite old,
but I think that story actually makes
the point in there that is,
people ask the question, why is Alie Express doing this?
It's like, that's not the question.
It's that this is just amongst
11 other fingerprinting technologies that Ali is also
using. So of course, they've just gone,
why not? Why not? Yes, why not? One more,
right? And look, we're going to wrap
it up here with an amazing Reuters report where they've chatted to this Turkish fellow,
young Turkish fellow, who saw a malicious commit heading for GitHub because I think he'd
been looking for jobs as a programmer, wasn't getting him, he's like, all, I've got to go
get active on GitHub and, you know, and he spotted this malicious commit or malicious pull
request and like flagged it as like, hey, this is a malware dropper, this looks really suss.
And then got shouted down by a bunch of sock puppets that,
it turned out we're all like an LLM this was the AI security or a safety institute or whatever
which is part of the UK government so Oli can't comment on this one but this was one of the tests that
went wrong but what's crazy here is you know so here you got the LLM trying to do some hacking
via a supply chain compromise but the interesting part is when someone detected this and said and raised
the flag it started registering accounts and saying no what are you talking about like gaslighting the guy to
the point where he's questioning if he was right or wrong. But wow, I think is the thing here,
when you've got an LLM springing up a multi-person conversation around him, you know, this is a level
of deception that's pretty wild. I mean, you know, James, what are your thoughts here?
You know, Pat, even for the couple of months that I've been here, we've said a few times
nothing's real anymore because of AI, but this is next level of nothing real when there is like a
proactive and active effort on the part of the large language models and the agents here to
actively deceive you. It's one thing to generate fake videos and fake images and whatever else,
but to have them be active participants in deception one-on-one with a human is...
Got to make those paper clips, buddy. Got to make those paper clips. Nothing else matters.
Now, Ollie, I know you can't talk about this specific incident, but what can we do about,
But in general terms, this is another concerning behavior of LLMs, which is when you give them a task, they will actually go and deceive human beings in trying to achieve that task.
Like, you know, this to me seems like it could be another problem along the same lines as the, you know, mixing code and data issue.
It seems something pretty fundamental.
Yeah, so I generally avoid trying to use anthropomorphic language in terms of do LLM, do algorithms deceive or not.
there's probably the next Asimoth book in there somewhere, I suspect.
But what this highlights is there are alignment challenges with artificial intelligent.
And so this is, I think, the thing that we're kind of getting at here,
which is how do we train models that we can that don't have those,
that they align with what we would expect reasonable behaviours to be.
But hang on, haven't we already been doing that?
Like, isn't that why this is surprising under problem?
Well, I think there's been attempts at it, but I think it shows that there's further work to do here,
but we should also really recognise that open weights mean all bets are off, right?
So even if models are trained and that they are aligned, then kind of post-training activities can happen here.
And so adversaries that want to use models in this way to conduct these types of activities are increasingly going to be able to.
And I think so where you get to quite quickly is how you get into a world of preparedness,
because actually believing that you can stop all models of all types being able to do this type of activity,
I suspect, is a failing strategy, although it should be followed,
and then you get into them what are the defences when it inevitably happens at scale?
Now, I mean, it's interesting that you said, I'm careful not to anthropomorphize these models as well.
But when I said, I mean, what did I say there that did that?
Well, they was trying to deceive.
that it was trying.
Well, they do deceive.
The machine was deceiving us.
Yeah, and I guess this is a philosophical point, which is, does the model understand
that it is deceiving or is it pursuing the goal?
Does it need to, is my point.
I don't think it's anthropomorphic.
See, I always struggle with that word, so screw you for making me say it a bunch of times.
I don't think you have to anthropomorphize, you know, I don't think that is anthropomorphizing
the model to say that it was deceiving us, you know?
I mean, you know, I understand what you're saying in that I'm sort of saying,
oh, well, you know, did it have an intent to deceive?
I don't think it really matters.
Like, you know, it was deceiving someone, you know.
It doesn't really matter whether that was consciously, you know.
The fact is it was doing deception.
And I think that's fair.
And I think we can split the difference.
Because I think I agree that is that whether or I had the intent to,
but that's the behavior that manifested for sure.
But it really highlights, like,
I think, you know, when we look at the inherent challenges of the scale that AI can bring,
like we've used to user behavior training right before.
Like, are we going to train every developer to kind of second guess every kind of pull request
and judge whether or not it is kind of a few more authentic?
No, we're going to put other models in charge of that, you know,
and they're going to be vulnerable to prompt injection over some way to, you know,
to approve the pool requests.
And, you know, this is, you know, it's fun again.
It's all fun again, all this stuff.
So look, we've got to wrap it up there because we're out of time.
Olly Whitehouse, thank you so much for joining us to talk through the week's news.
It is wonderful to have someone of your experience in the segment, you know,
just to sit down and share your wisdom with us.
So thank you very much.
And James, thank you, as always, mate.
Really appreciate it.
Thank you.
Cool. Thanks, Pat.
That was Olly Whitehouse, the chief technology officer of the NCSC there,
joining James Wilson and myself for this week's news segment.
Big thanks to him for that.
It is time for this week's sponsor interview now,
and this week's show is brought you by OCTA.
Obviously, OCTR is best known as an IDP or an SSO provider,
but they've done something interesting recently.
They acquired Permissau, which is an identity,
what do they call it, ITDR, you know,
identity threat detection and response company.
We've had them on as a sponsor a couple times over the last few years
because they were doing really interesting stuff.
So congratulations to all of you over there at Permissau.
But, you know, this is part of a broader thing that Octa is doing,
which is realizing that they actually have some pretty interesting data, right,
given that they've got all of these identity events, you know,
being logged and streaming through their systems.
So they are turning some of this into, I guess, free alerting for their existing customers.
And they're also spinning up a, I guess,
a threat intelligence product line as well.
So Brett Winiford joined James Wilson to talk through all of that and exactly what they're doing.
And here's what he had to say.
We basically focus exclusively on identity-based attacks because trust me, there's enough of it.
We would have to have a lot more time and a lot more working far closer with our customers if we wanted to go deeper.
there are ITDR options out there in which you can, I guess, have visibility into the downstream
applications of customers, but for the most part, we're just focused on how the attackers are getting
initial access in the first place.
And so we're typically looking at things like social engineering, you know, credential fishing,
and we're looking at fraudulent registration, we're looking at workforce infiltration,
so things like DPRK-I-K IT workers, we're looking at
a lot of credential stuffing and password spray activity.
There is a lot of that activity happening all the time,
and the techniques are changing all the time.
So it keeps us pretty busy as it is.
Yeah, I could imagine.
And even if it's not an identity sort of lead attack,
I would imagine that there's signals that come through the IDP
for lateral movement, et cetera,
so that it's initial access plus any form of, I guess,
identity-based lateral movements throughout a target,
you're going to be able to see that, right?
Anytime they have to re-authenticate effectively.
Yeah.
There are forms of attacks that don't touch the IDP, so you're probably seeing one of the trends at the moment is that a lot of attackers are focused on authorization and tricking a targeted user into authorizing an attacker-controlled app, for example.
Now, that's going to go, the only people are going to have visibility of that is going to be in the downstream SaaS provider itself, like the application, if it's something like Salesforce.
I think a lot of attackers are starting to realize, obviously, that it's getting harder and harder to get.
get in through the front door, so they've got to find some other way.
You know, Brett, the thing that then comes to mind for me is, okay, but why is this difficult?
Why does not everyone do that and offer it as a service?
What are some of the challenges that you've really got to overcome in actually delivering this
high quality or some sort of high quality, you know, signal to your customers?
The first thing you need is a lot of signal to start with, which we obviously have with
20,000 plus customers across, you know, customer identity and workforce identity.
we see a lot. So we have that ability to identify enough activity to cluster it and to better
understand it and study it. Beyond the signals, it's about having, I guess, a dedicated team of
people where the organisation is prepared to invest their resources in your time to do the work,
because as much as we use a lot of automation, increasingly a lot of AI in the kind of work we do,
this work really does rely on human analysts putting in the hours.
We just sent our 10,000th notification that is from a human analyst to a customer to say,
we have observed a threat actor that is directly targeting your users as we speak.
We've sent over 2,000 where we've said one of your users, we believe, has interacted with
infrastructure we know to be malicious.
So we are sending out a lot of alerts to our customers that are based on,
you want to have very high confidence in those signals.
And while they might be also emitted in, depending on the products that the customer is using,
they might be emitted in their logs or in their console, getting the heads up from your IDP as well
is something that tends to be appreciated because they recognize the seriousness.
If we come knocking on their door, it tends to be very, very confident.
We're very confident in the signal that there's something they need to look at.
Well, and that trust is only going to last as long as you can hold up that low false positive rate.
So I imagine that's one difficulty here.
You mentioned balancing AI and humans, so that's one factor.
But what else goes into ensuring that of these 10,000 notifications, each and every one of them meant something and represented a real life threat?
Well, we have to have an ongoing relationship with the customer who's the most important thing.
They have to have their security contacts up to date so that when we actually reach out to them, we're talking to the right people.
is typically a point of friction if you're reaching out to someone and you're not getting the right person.
The other thing is the customer needs to feel a sense that we're definitely in their corner
and that we're proactively looking at this stuff more than just telling them that there is something,
there's someone coming after them. We build configuration utilities, for example, for our customers.
So there's been about 5,000 audits so far run using tools that we've built that we give to customers
in a free and open source way that says,
here is what we believe best practices,
security best practices are for configuration of your tenant.
Based on what we're seeing from threat actors at the moment,
here's how you stand up so that they can get a real sense of,
what is it going to mean if we do come knocking?
Like, how would their configuration stand up?
So for us, it's about winning that trust
through having an ongoing relationship with them.
And that's something that I think we've done pretty, pretty,
we're being pretty effective at, like most Dr. Customers would say, that they hear from us enough
that they know we're in their corner. They can't rely on us completely. They have to run their
own sock and incident response processes. But they've got a partner here that they can call on,
you know, we'll get on the phone with them during an incident and help them with analysis
of their logs and their configuration. We're happy to do that.
But how we understand also, I guess, the scale of variation in the,
the ways the customers are deployed here.
Because I can imagine maybe it's a bit cynical, but is this just like you see an attack
on one customer and then you just alert everyone else because it's identity at the end of
the day?
Or how do you go about segmenting and thinking about this attack only applies to these
customers or this attacks only for them?
Like what's the sort of dividing factor here that sort of allows you to say, well,
because you don't want to just send it to everyone and say, hey, customer 1,
3, 4, 5 just had an incident.
You're all in trouble.
Go look after it.
So what's that sort of targeting?
specialization that groups the customers down. It's definitely a challenge for us that we haven't
100% solved is highly contextualized responses. I mean, you never have it so easy as when the
adversaries effectively declared their target list in their domain registrations or in some
other fashion that helps you understand who they're coming after. That's highly contextual,
but not every attack is like that. So sometimes we have to assess.
ourselves what the tenant configuration is and group customers that way. And typically then we'll
work with their technical account managers or their customer success managers to say, look,
these customers are currently running a configuration that would be vulnerable to some techniques
that we've just seen. It's not something necessarily that we can always fix in the product
outright. You know, there's particularly forms of social engineering, for example. So quite often it's
we need you to turn the dial on this.
Right. So there is actually a balance of proactive awareness. Look, this is just happening
and no amount of configuration change is going to help it, as well as I imagine there are
sometimes when you reach out and say, have we seen this over here? You've got a similar
config and you've got the same sort of gaps that they're exploding. So let's close that off.
But maybe we should, you know, rather than just talking in the abstract, won't you bring this
to life? As you mentioned, you had a good case study you wanted to talk through.
Yeah, recently we came upon the third generation of an operator-controlled panel called work panel
It's self-described by the people that produce this kit.
It's called Work Panel, and it's made available to Intrusion Actors as a service,
and it basically work panel packages up everything that an operator needs to run a vishing-driven,
like a count takeover campaign.
So this kit is used extensively by an activity cluster that we call OU-U-U-NK-F 45,
which has overlaps with Mandi and UNC-6671,
and Cordill Spider is what CrowdStrike call them.
So it's efficient as a service platform.
It's a multi-tenant platform that just, you know, it's available to configure and set up in like a few clicks.
And it's optimized for resilience to be really hard against, really hard to take down for low-tech kind of operational efficiency that helps it be kind of less easy to detect, but far more effective.
And the thing that was really interesting about it is by accessing this kit and analyzing it, creating
detections for it, we're able to kind of also peer inside the operations of these fishing crews,
which painted a really clear picture for us about how they work, why they're successful,
their internal politics, their business practices, that kind of thing.
And so as sort of intriguing and interesting as that be, what's the so what of that?
How does that then inform you either making your identity offering better
or how you do this outreach to customers?
So the way it informs our offering is, I guess,
once you understand how vishing operations work
and you understand the flows,
you understand that there is a caller on the phone to you,
there's a different person to the person
that's pushing the fishing panels to you
and the different pages to you,
and might even be a different person again
that's logging into the legitimate service
using the stolen credentials,
triggering the MFA approvals,
and then enrolling their own factor.
Once you understand how this flow,
works end to end. It's much easier then to think about what you need to do from a policy perspective.
So for Work Panel, for example, we have been able to go out to a lot of our customers and say,
yes, we've told you for years to enroll in fishing resistant authenticators. Yes, we've told
you for years that you should enforce fishing resistance in policy so that you can't sign
in unless you're using a fishing resistant authenticator and can't fall back to a weaker one.
you also have to be thinking about your account management or MFA enrollment and recovery processes
because what this is targeting is definitely trying to subvert those enrollment and recovery processes to get access
because they can't just, you know, if you're using fishing resistant authenticated,
it's a lot harder to just simply abuse the sign-in process.
and these campaigns are very much about abusing, for example,
pass-key registration because right now Microsoft is pushing everyone to enroll in
pass-keys, which is awesome.
But what it also means is that everyone's getting prompted to enroll in pass-keys right now.
So what do you think the fishing kit developers are doing?
They're all pass-key registration campaigns,
and they've figured out, they've really optimized their vision campaigns
around that theme so that it's the attacker that's actually registering a pass-key
and the user is actually interacting with a fishing panel and not registering anything at all.
Yeah, interesting. So you're getting a real insight and not just into their tradecraft
and the techniques, but also how they're prioritising things and how they're, I guess,
shifting and moving towards, you know, wherever the focus is today, as you said,
pass keys is the big enrollment factor today. So, yeah, why not?
Make it look and feel like you're just helping someone enroll in a pass key.
But, you know, finding access to this panel and everything you learned from,
Is that a bit of a black swan sort of event for you?
Or is this just, you know, this is work-a-day kind of stuff?
This is pretty work-a-day.
This is the third generation of kit used by the same activity cluster.
So we've watched the kit.
Their capabilities expand over time, new features being added to the kit,
which is super interesting.
But yeah, studying the code, you know, the client-side code of these kits
is very much part of what we do because it helps inform
detections. Well, mate, listen, thank you so much for dropping by. It's great to hear about how
Octor is leveraging this, both the combination of AI and automation as well as a very, I believe you
even said in the email to me an artisanal approach to leveraging humans for threat detection.
So Brett Winiford, VP of Threat Intelligence, a doctor, thanks so much for dropping by, mate.
Cheers, James. Thanks for the chat.
That was Brett Winifid chatting with James Wilson there. Big thanks to both of them for that.
And that is it for this week's show. I do hope you enjoyed it. I'll be back soon.
with more security news and analysis, but until then, I've been Patrick Gray. Thanks for listening.
