[00:00.000 --> 00:01.400] Hi, good evening. [00:01.760 --> 00:04.780] Thanks for coming for Ransomware Gone Kinetic. [00:04.940 --> 00:12.500] We have a riveting discussion happening this evening, and I'll start by introducing myself. [00:12.760 --> 00:29.940] My name is Ashley, and I am a cyber threat intelligence operative at Afterdark, and today I am with the CEO of Afterdark, James Taliento and Guillermo Christensen, our attorney. [00:30.700 --> 00:34.180] And I'm going to allow them to introduce themselves. [00:35.580 --> 00:38.260] So, we're working on skeleton crew. [00:38.520 --> 00:42.240] We're missing one person, and it looks like our slides aren't working, but we're going to get through this. [00:42.340 --> 00:45.920] We're going to make it enjoyable, and thank you for joining us. [00:46.080 --> 00:48.200] So, as Ashley said, I'm James Taliento. [00:48.780 --> 00:50.040] Everybody calls me JT. [00:50.300 --> 00:52.320] I'm the founder and CEO of Afterdark. [00:52.520 --> 00:56.240] We're a cyber threat intelligence provider, and our focus is on Ransomware. [00:58.920 --> 00:59.880] Good afternoon. [01:00.120 --> 01:09.360] My name is Guillermo Christensen, and while I am technically their lawyer at the company, I'm not here because they're in trouble or anything like that, okay? [01:09.460 --> 01:10.900] Just to be very clear. [01:11.060 --> 01:12.000] Not at the moment. [01:12.000 --> 01:14.340] And hopefully not at the end of this talk either. [01:15.080 --> 01:21.560] My role here is I run a cyber national security practice at a law firm. [01:21.680 --> 01:32.420] I have been involved in the cyber world from before I became a lawyer when I was intelligence officer with a three-letter agency that you can look up. [01:32.560 --> 01:35.500] It starts with a C, ends with an A, and has an I in the middle. [01:38.500 --> 01:51.500] I have been working in this field for a very long time, and with a deep abiding interest in knowing our opponents, and that's one of the reasons that I work very closely with James, Ashley, and their team. [01:51.500 --> 02:05.040] A lot of the work we do in this space is edgy in the sense that we are looking, peering into networks and activities of people who don't want to be found or known. [02:05.040 --> 02:11.360] And that often creates some legal questions, which we are pretty experienced at dealing with. [02:11.620 --> 02:30.520] In addition, I work a lot in incident response, protecting victims around the world, and being able to tap the resources and the knowledge that threat intelligence brings is key sometimes in understanding how the heck we're going to get a client out of a really bad ransomware situation. [02:30.520 --> 02:40.120] And by clients, I don't just mean companies that work for profit, I mean schools, hospitals, courthouses, you name it. [02:40.240 --> 02:41.640] Thank you for coming today. [02:43.080 --> 02:57.740] Okay, so quick note, since the slides are not showing up here, for those of you watching online, the slideshow presentation isn't going to align exactly with this lecture. [02:57.740 --> 03:07.980] It's just images, videos, things that we have collected on the dark web, and some of our research. [03:08.340 --> 03:10.060] So we'll start with JT. [03:10.360 --> 03:23.880] For those who don't know or who are only familiar with the technical capabilities of ransomware, can you describe the business model and the ecosystem that orbits ransomware? [03:23.880 --> 03:31.640] So first, let me ask, how many people in here have experienced a ransomware event? [03:32.800 --> 03:34.360] All right, that's good. [03:34.940 --> 03:42.500] How many people are working in incident response or actively working on ransomware cases on a daily basis? [03:43.380 --> 03:43.700] Okay. [03:44.920 --> 04:02.540] And with that being said, would you say any of you folks who are in the security ecosystem who are reporting to leadership or even just having discussions about it in your place of business, how often does, or let's just say, is it a frequent topic that ransomware comes up? [04:03.380 --> 04:04.040] All right. [04:04.160 --> 04:04.180] All right. [04:04.180 --> 04:04.900] I see some nods. [04:05.060 --> 04:05.420] Okay. [04:06.120 --> 04:06.620] All right. [04:06.860 --> 04:13.040] So, everybody knows ransomware, it's an attack on availability for the most part. [04:13.600 --> 04:30.140] You know, it's an encryption event, locks files up, locks systems up, prevents people from getting to the data, and in return, bad guys hope to extort the victim or elicit a payment out of them in return for a recovery key, a decryption key, right? [04:31.660 --> 04:36.920] 2019, towards the end of the year, we had a big shift in that to what we refer to as a double extortion model. [04:37.120 --> 04:46.720] So, maybe the ransomware that you guys are all familiar with today, these big, big hacks, they really emanate around big game hunting, right? [04:46.720 --> 04:51.480] So, at the end of 2019, group called Maze, took it to the next level. [04:51.780 --> 05:00.980] Instead of, you know, demanding things like, you know, $1,000 in Bitcoin or getting paid money-packed gift cards, they went after the big fish. [05:00.980 --> 05:17.040] They were encrypting corporations, exfiltrating large amounts of data, banging them over the head for, you know, six, seven, sometimes eight-figure ransom demands, and then hitting them up again to prevent the disclosure of information. [05:17.040 --> 05:18.960] So, it was a really effective business model. [05:19.240 --> 05:24.320] So, while that group didn't really operate as a franchise, right? [05:24.440 --> 05:32.300] Like, so that one, I guess, development or business development in terms of ransomware changed the course of it forever. [05:32.800 --> 05:39.880] Since then, there's been a lot of innovation, mainly in the business model, not so much in the ransomware itself, but in the business model. [05:39.880 --> 05:43.820] And the most popular business model out there is RAS or Ransomware as a Service. [05:44.380 --> 05:48.960] And the way Ransomware as a Service functions is like a franchise, right? [05:49.140 --> 05:58.260] So, there is a shared capability or a set of shared capabilities that are innovated by a ransomware administrative crew, right? [05:58.360 --> 06:03.480] So, there's an admin that runs the business, there's a malware developer, sometimes they're one and the same. [06:04.100 --> 06:07.120] They provide the locker or the actual ransomware. [06:07.120 --> 06:09.300] They provide the decryption capability. [06:09.800 --> 06:17.700] Now, with most of the online lockers or online RAS that are out there, they are providing, you know, chat support panels. [06:17.700 --> 06:25.720] They're providing escrow for crypto payments and what have you, and then automatic distribution of keys and those funds. [06:25.900 --> 06:38.720] So, what they do is they go out, they recruit bad guys that want to go make money, guys that don't necessarily know how to develop their own malware and ransomware capabilities, but they're really good pen testers at the end of the day, right? [06:38.920 --> 06:40.980] They're good at getting into networks. [06:41.280 --> 06:42.380] Maybe not getting in. [06:42.520 --> 06:48.160] There's a whole economy to access brokerage, but they're good at pen testing. [06:48.320 --> 06:52.800] They're good at navigating, doing the post exploitation activities and locking things up. [06:52.800 --> 06:56.920] And as a result, they net themselves some pretty high dollar amounts. [06:57.040 --> 07:07.980] And then the RAS, that franchise model, they're taking a cut, usually anywhere between five and 20%, depending on the volume of attacks that the affiliate does. [07:08.200 --> 07:13.580] So, that's really what the landscape generally looks like today or what the ecosystem generally consists of. [07:13.720 --> 07:16.420] A lot of these operators are going into that model. [07:18.700 --> 07:39.600] So, one thing I wanted to add to James' description is, when you look at the evolution of these cyber criminal groups, they're starting to look in a lot of ways like the high-end APTs and, in particular, the types of operations that governments run. [07:39.600 --> 07:44.000] You have specialized teams that do the entry. [07:44.300 --> 07:49.220] You have specialized teams that manage the lateral movements. [07:49.380 --> 07:50.740] Because those are very different skills. [07:51.420 --> 07:55.060] One is very much attuned to figuring the way in. [07:55.220 --> 08:02.200] The other is persistence, moving quietly, not triggering any of the sensors, not giving up that hard work. [08:02.700 --> 08:09.140] And it's that specialization, which is the same thing that successful businesses do in the commercial space. [08:09.140 --> 08:13.080] You bring in people who are focused on the things that you can do the best. [08:13.540 --> 08:28.280] And what I think has happened in the evolution here, and we'll talk a little bit more about that, is they have become unbelievably entrepreneurial and successful small businesses that often leverage technology at a rate that, frankly, is kind of amazing, [08:29.020 --> 08:32.420] considering the business that they're in, which is obviously criminal. [08:32.420 --> 08:33.800] So... [08:34.760 --> 08:39.060] Guillermo, nobody likes the idea of paying terrible people. [08:39.300 --> 08:44.560] It sounds like there is significant risk even considering paying a bad guy. [08:44.780 --> 08:59.920] Because we have seen more frequent economic sanctions being announced, from your experience, is law enforcement effective at disrupting these operations, or do you think that there is a better way? [09:01.660 --> 09:15.280] So I think the first thing is, just to level set, there is no federal law that prohibits a victim from paying a ransom in the United States. [09:15.420 --> 09:18.380] There are some countries where there are laws that limit that. [09:18.480 --> 09:23.740] But in the United States, if you're the victim of ransomware, there's no federal law that says you can't pay it. [09:23.980 --> 09:36.560] There are some trade sanctions on certain countries and certain people that make it so that if you pay, you have to ask the government for a license. [09:36.720 --> 09:40.020] This is the Office of Foreign Assets Control, OFAC. [09:40.200 --> 09:45.700] And if you don't, then you're violating that law and those regulations. [09:46.180 --> 09:50.960] And theoretically, the government could prosecute you for that if you did it intentionally. [09:50.960 --> 09:54.560] So far, they haven't done that to anyone. [09:54.780 --> 10:03.960] And it seems like it would be a hard thing for the government to prosecute someone for trying to save their business or unlock their patient files. [10:04.140 --> 10:06.860] But stranger things happen with the government. [10:09.440 --> 10:23.000] The issue these days with the entire problem set of ransomware, I think, comes down to government was caught, I think, flat-footed on a lot of this. [10:23.120 --> 10:28.720] They didn't really see the potential impact until 2021. [10:29.800 --> 10:34.820] And there was an incident, an attack on a pipeline, colonial pipeline. [10:35.520 --> 10:46.680] Most of you here, if you're on the East Coast, had some experience with it because you maybe weren't able to get gasoline at the pump or you paid more for it. [10:47.200 --> 10:54.900] That was the kind of the watershed event for ransomware in the United States because it had a political effect. [10:54.900 --> 11:00.500] And in our system, politics usually is the thing that really drives change. [11:00.640 --> 11:13.520] And it's the first time that I'm aware of where the President of the United States was being briefed every day on what was happening with this pipeline that had been shut down because of the ransomware attack. [11:13.520 --> 11:27.140] Now, I think we'll talk a little bit about why that wasn't really a true attack on control systems, but it was a massive attack on an infrastructure, critical infrastructure in the United States. [11:27.360 --> 11:29.320] And since then, the U.S. [11:29.420 --> 11:36.600] government has taken a very much more active role in trying to interdict the ransomware. [11:36.720 --> 11:38.520] And I think it's showing some results. [11:38.520 --> 11:56.440] We'll talk perhaps a bit about the takedowns of some of these ransomware as a service groups, where the FBI working with a lot of other law enforcement around the world has been able to get to their infrastructure, penetrate it, observe it, and then in time, take it down. [11:57.540 --> 12:03.660] And in the meantime, to help victims decrypt their systems instead of having to pay the ransom. [12:03.660 --> 12:12.100] So there's some progress, but it's not anywhere near what we would like to see. [12:12.600 --> 12:19.600] And, you know, you only need to read the newspapers to see the impact of ransomware now on healthcare change. [12:20.260 --> 12:24.760] Anyone here try to buy or service a car in the last two months or a month or so? [12:25.820 --> 12:31.020] The dealers were shut down because their infrastructure was taken down by another group. [12:31.020 --> 12:40.020] So generally speaking, I think government's trying, but this fight needs a different type of approach, I think. [12:40.120 --> 12:42.280] And we can talk about that a little bit more. [12:42.980 --> 12:43.540] Sure. [12:43.860 --> 13:04.200] Being that our conversation this evening is around ransomware and its impacts with critical infrastructure, what do you think the government should do when it comes to critical infrastructure, being that it manifests itself into a national security threat, more so than espionage or being financially motivated? [13:11.580 --> 13:34.660] So one thing that I wanted to also highlight is, I would say two or three years ago, and James can speak to this as well, you would see these groups holding back or almost having buyer's remorse when they did something that impacted critical infrastructure or hospitals. [13:34.660 --> 13:42.740] In some cases, they would actually provide the decryption keys free so that the hospital could begin operations. [13:42.940 --> 13:49.420] And they had, you know, these are criminals, so we're not going to call them ethics or morals, but they had a limit. [13:49.420 --> 13:58.980] And the limit really was around, don't push it beyond the point where you're going to turn the government against us in a serious way. [13:59.820 --> 14:01.680] Colonial pipeline is a classic case. [14:01.880 --> 14:11.620] In that situation, the sense that we had was that they realized they may have overreached and that they should stay away from that stuff. [14:11.620 --> 14:17.820] And then, of course, something very significant happened when Russia invaded Ukraine. [14:19.460 --> 14:29.400] And there is now, I think, a sense among Russian hackers, which make up the majority of these groups, that this isn't just about money. [14:29.400 --> 14:37.440] It's about politics and war and doing their part for their cause. [14:38.000 --> 14:51.580] And so, I think some of the limits that they had put on themselves are now completely off, which means the critical infrastructure that we're talking about is much more susceptible to these attacks. [14:51.580 --> 15:08.800] And one reason for that is, for those of you who work in that lovely space between IT systems and OT systems, the operational technology, the control systems that you usually connect to the Internet, because they're old and they're very simplistic systems, [15:09.860 --> 15:11.360] increasingly have been connected. [15:11.740 --> 15:29.160] And when those are exposed to ransomware attacks, or even if they're not exposed to ransomware attacks, like in Colonial Pipeline, if you're operating those, your first reaction is, let me shut things down, because I don't want something to go boom, or I don't want something that should be moving to [15:29.160 --> 15:33.800] stop moving, until I know what the potential damage is. [15:34.060 --> 15:44.160] And so, sometimes, what happens is, you are turning systems off as a precaution, and then bringing them back online can take a long time. [15:44.540 --> 15:48.700] These systems were not really meant to be shut down, especially be shut down all of a sudden. [15:50.720 --> 16:02.720] Also, if you shut down in the middle of an encryption event, while it's in the process of encrypting your data, you shut it down, there's a good chance you're going to cause some damage, like corrupt some files, making the recovery process that much more difficult. [16:03.020 --> 16:14.140] Even if you had the appetite to, you know, make a payment and obtain a decryption capability, it's... it might not even be possible. [16:14.340 --> 16:15.620] It might have no efficacy whatsoever. [16:18.550 --> 16:32.380] JT Kierma, traditional ransomware operators, hacktivists, and nation-state threat actors, can you describe their motivations and how they have potential to overlap in the ransomware landscape? [16:32.380 --> 16:39.560] For example, Medusa is a Russian-speaking ransomware as a service operation. [16:39.940 --> 16:49.120] To the untrained eye, they appear to be no different than any other financially motivated cybercrime outfit. [16:49.560 --> 16:52.680] Eminent Pazirgaard is an Iranian threat. [16:52.740 --> 16:57.140] Many of their members have made their way onto sanctions lists. [16:57.140 --> 17:03.060] Are people assessing the risk correctly when responding to ransomware events? [17:03.340 --> 17:09.300] Specifically, do they understand the motives may extend beyond financial gain? [17:09.460 --> 17:14.760] And do they understand that there is potential for a sanctions nexus? [17:16.540 --> 17:27.500] Well, first and foremost, I think everyone here fully expects that there might be some level of state sponsorship involved in many different aspects of cybercrime. [17:27.700 --> 17:46.640] And when you have folks that are operating in non-extraterritorial jurisdiction, like in Iran, North Korea, and Russia, places that aren't going to cooperate with our law enforcement, it extends a level of plausible deniability to those governments and those intelligence communities over there, [17:46.780 --> 17:54.400] where they could leverage their, you know, their criminal citizens to do some of their dirty work, right? [17:54.400 --> 18:07.180] And in return, maybe offer them some type of safe harbor or to have their own operatives work within those groups to carry out their motives and appear to be criminal in nature. [18:07.400 --> 18:12.100] So, as you mentioned, Medusa, it's a very, very interesting use case. [18:12.600 --> 18:14.480] We've seen many Medusa cases. [18:14.780 --> 18:18.780] There's a couple of different ransomware crews and malware out there named Medusa. [18:18.780 --> 18:21.940] The one we're referring to just goes strictly by the name Medusa. [18:22.180 --> 18:23.320] It's now a RAS. [18:23.540 --> 18:38.180] But in 2020 to about the end of January of 2022, the group was financially motivated, conducting digital extortion events, just hacking companies, leaking the data on their Telegram channel. [18:39.200 --> 18:56.700] And, you know, just before the conflict in Ukraine officially broke out, before the invasion took place on the ground, the group shifted gears and started targeting organizations that were in support of the Ukrainian government and their defensive capabilities for a period of about nine months. [18:57.060 --> 19:07.020] At the end of September of 22, the group shifted gears again, now starting this autonomous ransomware operation. [19:07.020 --> 19:15.220] And then earlier this year, they started a recruitment model or a franchise model, a RAS, under that brand, and they've scaled it up dramatically. [19:15.500 --> 19:19.560] So now they're a group that appeared financially motivated. [19:20.460 --> 19:22.080] So they were going after everybody. [19:22.080 --> 19:38.220] And all of a sudden, for a period of, say, nine months, completely shifted their attention to Ukrainian targets, specifically government and defense contractors and anybody supplying weapons and tools to Ukrainian soldiers. [19:39.460 --> 19:44.720] Then, in addition to that, you see a level of sophistication with a group like this that's really interesting. [19:44.940 --> 19:47.360] So most people are familiar with the idea of a leak site. [19:47.520 --> 19:53.820] All these threat actors, they want to, you know, dangle the carrot or put something out there, have a little leverage over their victims. [19:53.820 --> 19:57.940] So they have a dedicated leak site usually on tour operating as hidden service. [19:58.800 --> 20:00.140] These guys are a little different. [20:00.480 --> 20:07.720] So not only do they do that, but they operate a series of personas that are disguised as security researchers. [20:08.140 --> 20:16.420] And those security researchers are publishing content, spun content from legitimate news sources, blogs, and what have you. [20:16.620 --> 20:21.080] But they're only reporting on leaks that are related to Medusa as well. [20:21.200 --> 20:24.220] So the only leaks they ever report on are related to Medusa. [20:24.220 --> 20:32.420] And the reason that they're doing that is they're trying to exploit freedom of speech and DMCA takedowns, right? [20:32.560 --> 20:42.520] So they can spread the impact wider and have things on social media that would normally be taken down because it's operated by a criminal group. [20:42.600 --> 20:43.660] Now it's just journalistic. [20:44.160 --> 20:47.600] They're doing things on Telegram, which many, many groups are. [20:48.300 --> 20:49.900] They're on Facebook. [20:50.140 --> 20:52.320] They're on... they have their own blog. [20:52.560 --> 20:57.620] So they've really extended it beyond the reach of just keeping things on the dark web. [20:57.760 --> 20:59.360] And there's a level of sophistication there, too. [20:59.800 --> 21:00.660] Like, think about that. [21:00.900 --> 21:03.220] Does that sound just financially motivated? [21:03.420 --> 21:04.500] I mean, yeah, it could. [21:04.500 --> 21:20.480] But when you look at their targeting practices over the course of a year, their sentiment towards Ukrainian targets, their sentiment towards Russia, and then also the way they've been operating and scaling and improving the ability to make such a negative impact on their victims. [21:20.480 --> 21:23.580] Yeah, I would say that there's a good chance that group is state-sponsored. [21:23.780 --> 21:28.080] If they're not directly sponsored, maybe they're operating under duress, right? [21:28.140 --> 21:29.040] Maybe they're being tasked. [21:29.400 --> 21:30.740] That's a very common thing as well. [21:31.080 --> 21:36.440] And then you mentioned Eminem Pazagard, who is an Iranian group. [21:37.180 --> 21:40.820] They've also found their way into ransomware in a different sense, right? [21:41.020 --> 21:44.800] So this group will absolutely target critical infrastructure. [21:45.100 --> 21:47.420] They'll absolutely execute ransomware attacks. [21:47.420 --> 21:50.800] But now we see them posing as Russian operators, right? [21:51.000 --> 21:55.520] Because there's a level of plausibility and plausible deniability in doing that as well. [21:55.680 --> 22:09.280] So you have a bunch of different state-backed agendas now entering the financially motivated cybercrime space because it's overt, it's destructive, it's disruptive, and it's got the best cover story ever, right? [22:09.360 --> 22:10.480] You need to acquire data. [22:10.700 --> 22:12.520] Well, these guys, these criminals stole it. [22:12.520 --> 22:16.720] You need to take down or disrupt a target, a critical target. [22:17.180 --> 22:17.640] Yeah. [22:17.900 --> 22:19.860] These ransomware operators did it, right? [22:19.980 --> 22:20.620] It makes sense. [22:22.940 --> 22:37.020] The other example of this that I think is very instructive is right after the Russian invasion of Ukraine, one of the most, I'll say, ferocious ransomware groups, Conti. [22:37.020 --> 22:44.160] I'm sure that name, it's been in the press, it's probably better known than most, basically imploded. [22:44.800 --> 22:50.840] And it imploded because some of the members were in Russia, and some of them were in Ukraine. [22:51.200 --> 22:54.780] And basically, they entered into a bit of a civil war. [22:54.780 --> 23:08.180] And one of the members of the inner core of the group decided to part ways in a very kind of spectacular way. [23:08.380 --> 23:20.800] They did their version of, say, a WikiLeaks, and they dumped a huge amount of internal communications about the group into the open community. [23:21.420 --> 23:30.120] And I think that there are a lot of interesting stories out there that have been written analyzing the messages inside the group. [23:30.560 --> 23:38.480] The things that I found most interesting and validated some of our thinking, they had an HR team, right? [23:38.700 --> 23:44.160] They had a human resources team because there were human resources issues operating a business. [23:44.160 --> 23:47.940] People would complain about not getting, you know, their benefits. [23:48.280 --> 23:51.600] Or there would be issues around who was getting paid on time. [23:52.780 --> 24:02.060] All the same issues, and by the way, a lot of complaints about the long hours, being stuck inside, behind a keyboard. [24:02.360 --> 24:08.180] You know, all the things that probably most of us who have some experience in IT were dealing with at some point in our career. [24:09.700 --> 24:18.720] So, not a whole lot different than some of the scenarios that you would probably see if you got the chats from any kind of an IT support service kind of company, right? [24:20.400 --> 24:25.140] So, Conti blew up, and people thought, okay, this is great. [24:25.640 --> 24:26.820] We're rid of them, right? [24:27.980 --> 24:28.580] No. [24:29.280 --> 24:32.780] It's actually what we've seen now, and there are some other examples. [24:33.000 --> 24:39.640] When one of these groups blows up, it's a little bit like one of these big tech companies that fails. [24:39.880 --> 24:51.880] And all the very imaginative entrepreneurial people who were suffering, perhaps, under, you know, the bureaucracy, go and start doing their own things. [24:51.880 --> 24:58.460] And so, you actually create, potentially, two or three new groups out of something that fails. [24:58.660 --> 25:01.600] They all know each other still, and they all collaborate, too. [25:01.720 --> 25:02.980] The collaboration doesn't stop. [25:03.140 --> 25:10.620] So, it actually creates more of a diffuse and sometimes more difficult network of ransomware operators out there. [25:10.780 --> 25:13.600] So, sometimes you have to be careful what you wish for. [25:14.980 --> 25:16.600] They even had office space. [25:16.740 --> 25:17.380] It was kind of awesome. [25:19.760 --> 25:27.220] Looking back at attacks on American critical infrastructure, there are several cases that come to mind. [25:27.220 --> 25:36.360] The IRGC attacks Bowman Dam, and also the Aliquipa Municipal Water System. [25:36.360 --> 25:47.440] There is also the attack everyone knows about, Colonial Pipeline, which was done by financially motivated ransomware operators known as Darkside. [25:47.820 --> 25:59.780] Lesser known is the attack on Dusseldorf University Hospital by Rievel that even resulted in a death due to the inability to provide emergency care. [26:00.360 --> 26:04.740] Guillermo, could this be constituted as acts of war? [26:07.840 --> 26:11.440] So, let me start by saying that I think we're at war. [26:11.940 --> 26:13.060] We've been at war. [26:13.840 --> 26:16.080] No one declares war anymore, right? [26:16.220 --> 26:19.340] So, for a long time, there's no such thing as a declaration of war. [26:19.340 --> 26:22.000] So, in a lot of different places, we have been at war. [26:22.300 --> 26:28.400] These things, these acts to me, definitely can cross the line into an act of war. [26:28.540 --> 26:33.340] They definitely cross the line into very malicious crimes where people are being hurt. [26:33.340 --> 26:41.100] And there certainly are many reports of individuals, of people dying as a consequence of a ransomware event. [26:42.400 --> 26:47.680] That said, one of the difficulties here is the attribution problem. [26:48.140 --> 26:50.880] And we can talk some about that. [26:51.240 --> 26:57.640] Sometimes, when you're dealing with one of these things, you don't necessarily want the attribution to be too much of the story. [26:58.580 --> 27:03.140] And I do find it sometimes interesting that someone will say, well, we were attacked by a nation-state. [27:03.340 --> 27:04.100] What could we do? [27:04.520 --> 27:06.420] And then you look at how they were attacked. [27:06.520 --> 27:11.900] Well, you had no multi-factor authentication on your VPN appliance. [27:12.300 --> 27:14.640] This thing has been end-of-life for five years. [27:15.520 --> 27:19.440] I don't think a nation-state really needed to spend much effort to get in there. [27:19.520 --> 27:20.760] In fact, my son... [27:21.420 --> 27:22.900] Actually, I shouldn't bring him into the story. [27:23.180 --> 27:24.260] Probably get in there, right? [27:24.400 --> 27:24.760] So, no. [27:24.760 --> 27:30.420] Sometimes, because look, the story of hacking is very simple. [27:30.560 --> 27:33.780] You only do the minimum necessary to get the job done, right? [27:34.260 --> 27:35.900] That's... you should find the shortcut. [27:36.420 --> 27:42.400] So, when these stories talk about nation-state, you have to be very, very careful about that conversation. [27:42.840 --> 27:51.460] If you're talking solar winds, some of the other caseya, these big, complex, and sophisticated attacks, that's one thing. [27:51.460 --> 27:56.820] The other thing I wanted to mention, and I alluded to this before on Colonial Pipeline. [27:57.100 --> 28:03.420] So, first, in 2012, the Iranian... this is the attribution. [28:03.600 --> 28:15.080] The Iranian Ministry of Intelligence took a... did a retribution attack on the Saudis, through attacking the largest company in the world, effectively, Saudi Aramco. [28:15.080 --> 28:24.100] They launched the same software that we would consider to be equivalent to ransomware, but it doesn't have a decryptor. [28:24.360 --> 28:26.440] We call it a wiper, right? [28:26.680 --> 28:31.440] And basically, what it does is it destroys the hard drives on computers. [28:31.440 --> 28:32.760] This is a simplified version. [28:32.900 --> 28:34.040] There are many kinds of them. [28:34.120 --> 28:40.320] But, essentially, it destroys the sectors on a disk, so that the computer can't boot up. [28:40.440 --> 28:41.560] It's basically dead. [28:41.760 --> 28:53.160] And they did that across Aramco's IT infrastructure, so that Aramco could not sell fuel in Saudi Arabia. [28:53.740 --> 28:59.320] Now, their solution was pump the fuel free, so that nobody would be really upset. [28:59.320 --> 29:06.160] And then they went and they bought all the drives that they needed to replace those that had been destroyed in Malaysia. [29:06.160 --> 29:16.040] And we joke about this premium you paid for hard drives during that year because they almost cornered the market. [29:16.800 --> 29:18.080] That's 2012. [29:21.200 --> 29:27.520] 2021, when Colonial Pipeline gets hit, it's a very similar issue. [29:27.520 --> 29:35.940] It's not their operational technology that's being attacked, their ICS systems. [29:35.940 --> 29:37.340] It's not their pumps. [29:37.360 --> 29:38.380] It's not the pipeline. [29:38.620 --> 29:40.320] It's their customer systems. [29:40.660 --> 29:46.840] But they didn't know how far the attack went, and so they brought everything down. [29:47.880 --> 29:49.900] So, it's only nine years later. [29:50.140 --> 29:52.440] I think by then people would have learned some lessons. [29:53.000 --> 29:53.880] Clearly not. [29:54.760 --> 30:02.320] There was an incredible amount of security deficit in that organization, and that's why they were hit. [30:02.320 --> 30:09.340] That's why that attack was successful, because normally that kind of an attack should have been contained. [30:10.100 --> 30:13.840] But it ran through their system very quickly, and then they had to turn it off. [30:13.840 --> 30:30.700] So, that's why I think in the discussion of critical infrastructure, what's really challenging is those systems behind the information technology are all quite old, often decrepit, and very hard to update. [30:30.700 --> 30:35.400] You know, it's one thing to take, you know, buy the iPhone 16 when it comes out. [30:35.680 --> 30:48.340] It's a totally different thing to take a pipeline and replace the controllers, replace all the measuring devices that have been designed to work in place for 20 or 30 or 40 or sometimes 60 years. [30:49.160 --> 30:53.060] Taking them down, replacing them, you shut it down, you're losing money. [30:53.860 --> 30:57.140] Sometimes people don't even make those devices anymore. [30:57.860 --> 31:06.420] So, it's a very... the critical infrastructure as a security problem is a much more difficult one even than the enterprise systems that we deal with. [31:08.580 --> 31:29.900] Taking it to today, I've observed foreign threat actors conducting attacks on water and municipalities, as well as telecommunications, and these are considered critical infrastructure. [31:30.860 --> 31:38.760] Where are threat actors gathering to discuss taking action against critical infrastructure? [31:38.780 --> 31:40.660] Who is having them? [31:40.780 --> 31:43.140] What are they doing to conduct these attacks? [31:43.540 --> 31:50.120] What critical infrastructure sectors are also being targeted today, JT? [31:53.240 --> 31:56.040] So, the short answer is telegram. [31:57.220 --> 32:15.960] A lot of threat actors, a lot of ideological, you know, threat actors with, you know, let's say an extremist agenda, they gather on telegram, they're collectives, they're usually young and crazy, and there's some older, more mature, senior level hackers that are kind of running the show, [32:15.960 --> 32:18.220] maybe running multiple teams of these individuals. [32:18.460 --> 32:22.740] That's where a lot of the quote-unquote gathering is taking place. [32:23.000 --> 32:32.080] For the more sophisticated groups or the ones that are a little bit more mature and business savvy that aren't necessarily hacktivists, right? [32:32.180 --> 32:36.260] They're more financially motivated or motivated by means of espionage. [32:36.260 --> 32:44.320] Those folks are either eating offline or in small circles, which is why it's not visible what they're doing, right? [32:44.440 --> 32:47.940] Like, I hate to say this, but we kind of love the extremists. [32:48.120 --> 32:49.500] They're the ones that are the most overt. [32:49.500 --> 32:51.720] Like, it's very easy to see what they're up to. [32:51.800 --> 32:52.500] They don't hide it. [32:52.660 --> 32:53.940] They're posting pictures. [32:53.940 --> 32:55.500] They're mentioning targets. [32:55.660 --> 32:57.820] They're talking about ops that they're working. [32:58.040 --> 33:01.420] They're talking about people that they're working, tools that they're using. [33:01.420 --> 33:15.540] They're sharing tons and tons of documentation information, publications about drones, about PLCs, and different proprietary technology that exists from corporations that they've exfiltrated data from. [33:15.540 --> 33:17.860] So they're usually the best ones to track. [33:18.640 --> 33:25.360] It's the sophisticated ones or the semi-sophisticated ones that are operating behind the scenes in these smaller circles. [33:25.560 --> 33:31.660] And yeah, they might be meeting online, but I think the real threat is meeting behind the curtain, behind the scenes. [33:31.920 --> 33:39.400] They're usually, again, it's that level of state sponsorship that we don't have a whole ton of visibility into, and they're tasking that stuff out. [33:41.680 --> 33:48.140] Guillermo, given what JT has described, what are your thoughts on how the government should weigh in? [33:48.400 --> 33:55.460] Should there be a shift in policy or in the approach to tackling those types of threats? [33:55.700 --> 33:57.580] Better yet, does the U.S. [33:57.740 --> 34:07.020] government fully understand the involvement of state sponsorship and extremism that have now intersected with ransomware? [34:15.280 --> 34:16.280] Thank you. [34:16.440 --> 34:20.420] I do think that something has to change. [34:20.760 --> 34:25.140] And so-called hacking back, I think, is one part of that. [34:25.240 --> 34:29.820] So let me explain what the government's campaign has sort of been focused on. [34:29.820 --> 34:32.500] One, you know, these are crimes. [34:32.680 --> 34:37.440] So the FBI tries to investigate and bring people to jail, right? [34:37.560 --> 34:39.860] They try to find them, extradite, and bring them. [34:40.160 --> 34:41.620] They've had a few successes. [34:41.620 --> 34:45.580] I mean, like, on the fingers of two hands, perhaps. [34:46.520 --> 34:47.620] Very hard to do. [34:47.800 --> 34:49.880] The Russians don't extradite their people. [34:50.340 --> 35:00.240] And now they've learned not to go to Florida and visit Disney World, because that's where they were usually being caught when they traveled there for their vacations. [35:00.500 --> 35:05.220] So they go to the Crimea, which they now also happen to occupy. [35:05.580 --> 35:10.760] So that tactic is of very limited use. [35:11.160 --> 35:17.560] Another tactic was to try to reduce the incentive for people to pay ransoms. [35:17.560 --> 35:26.160] This was sort of the sanctioning of groups, but it's really not had much of an effect, because there have not been many groups sanctioned. [35:26.300 --> 35:37.380] And the other problem is, how do you sanction people who are, by their nature, very secretive, anonymous, hard to pin down? [35:37.600 --> 35:43.800] And even if you knew that they were involved, could you really say that they were the ones behind that keyboard at that time? [35:43.800 --> 35:44.760] Very difficult. [35:45.620 --> 35:54.680] And then the other effort now is to bring countries together to operate a more of a multinational approach. [35:54.960 --> 36:00.760] And I think there's around 50 or so countries now that are aligned to try to do this globally. [36:00.760 --> 36:20.340] So do those things, but do them globally, which I think is also not a bad idea, but unlikely to fix the problem, as long as the majority of the groups we're dealing with are in Russia or Iran, places where, again, we're not going to get any assistance from the local authorities. [36:21.140 --> 36:32.520] So the next question that's come up, and I think it's not a widely shared view, but I think that there's got to be some more active measures taken against these groups. [36:32.700 --> 36:38.060] Now, the FBI and other law enforcement agencies have been successful at this. [36:38.120 --> 36:40.180] I mentioned that they've taken down some of the groups. [36:40.700 --> 36:50.660] Sometimes they've even been able to intercept some of the funds that have been wired, effectively, right, into their digital wallets. [36:51.600 --> 36:56.940] But there's a limited number of FBI agents capable of doing this work. [36:57.080 --> 36:59.260] The FBI is not a very large organization. [37:00.280 --> 37:03.980] The organizations in the UK and other countries are even smaller. [37:04.260 --> 37:15.820] So one idea that I think merits some serious thought is something that actually goes back to our Constitution, and that's something called Letters of Mark. [37:15.820 --> 37:26.140] And that's where you provide... the government authorizes private individuals to undertake certain operations. [37:26.780 --> 37:32.180] And in doing so, to go after, for example, the crypto that these groups are holding. [37:32.560 --> 37:35.840] Sometimes when you're in their networks, you can see where their wallets are. [37:36.400 --> 37:43.960] Other times you could try to take down their infrastructure, basically, to make it so that they don't have a quiet night. [37:44.500 --> 37:46.040] Because they operate at night, obviously. [37:46.380 --> 37:50.100] That they don't have the space to do as much as they're doing right now. [37:50.300 --> 37:51.640] Is it going to beat them? [37:51.760 --> 37:51.960] No. [37:52.180 --> 38:02.040] But any sand you put into their gears makes it more likely that they don't have as much time to do what they're doing, and frustrated. [38:02.300 --> 38:04.100] And that's part of the strategy. [38:05.920 --> 38:07.400] Thank you, Daniel. [38:07.880 --> 38:11.100] We have a couple minutes left. [38:12.260 --> 38:13.060] We... [38:13.060 --> 38:14.300] Real quick. [38:14.660 --> 38:16.180] Spitfire this, JT. [38:16.520 --> 38:21.080] Targeting critical infrastructure requires strong and knowledgeable skill sets. [38:21.440 --> 38:28.120] How and where are these threat actors learning by conducting these levels and style of attacks? [38:28.360 --> 38:31.020] How advanced are these attacks currently? [38:31.020 --> 38:36.860] What are they doing once in the SCADA ICS infrastructure? [38:38.080 --> 38:39.460] So I'll answer quickly. [38:39.660 --> 38:40.500] We don't have a lot of time. [38:40.660 --> 38:47.120] But I think Guillermo mentioned it, is that it doesn't take much to break into these environments. [38:47.120 --> 38:49.540] They're old, deprecated. [38:49.920 --> 38:51.320] They're not well protected. [38:51.400 --> 38:58.360] And they're probably not well resourced with people that are doing a phenomenal job in securing that environment altogether. [38:58.820 --> 39:00.600] So it's, it's not a heavy lift. [39:00.620 --> 39:04.460] And as you said, nobody's breaking out the big guns to break into critical infrastructure. [39:04.460 --> 39:05.380] And I'll leave it at that. [39:10.490 --> 39:13.750] Um, we have time for a couple of audience questions. [39:13.750 --> 39:17.870] So please come to one of the microphones and we have the first one right here. [39:17.870 --> 39:30.270] Uh, so my question is related to, uh, the Maersk NotPetya hack and the speed at which that worm went through the system. [39:30.270 --> 39:36.930] Um, just wondering, like, I don't think Maersk is 300 million to repair, uh, their IT systems. [39:37.210 --> 39:38.630] I don't think Maersk was the target. [39:38.950 --> 39:49.750] Like at one point, are we going to have an accidental critical infrastructure attack where something gets loose and it just spreads because these systems are so old and antiquated? [39:50.730 --> 39:52.590] I think it's very possible. [39:52.890 --> 39:59.830] Um, there's a lot of development taking place in, I would say malware innovation with automated propagation. [40:00.210 --> 40:07.210] And, um, you know, we do occasionally see, you know, guardrails are not properly implemented. [40:07.210 --> 40:22.150] I mean, there's a, a very famous case, maybe not here, but definitely over in Russia with a group called the silence, um, where their malware author made a mistake and didn't put guardrails in place to prevent the infection of systems within the Commonwealth of independent states. [40:22.590 --> 40:35.710] And, uh, it was believed that they were targeting organizations within the Commonwealth and there's many discrepancies around that, but he broke the cardinal rule of hacking within, uh, you know, post-Soviet countries and it landed them in a lot of trouble. [40:35.710 --> 40:40.650] Um, that's one small example, but we've seen this kind of stuff happen where it gets out of control. [40:40.810 --> 40:44.670] I think the most, uh, notable one is Stuxnet, right? [40:44.790 --> 40:47.430] Like it was discovered because it got loose. [40:47.730 --> 40:49.490] So I, I do think it's very possible. [40:49.490 --> 40:57.750] And I, and I think it is something that's very likely coming because there aren't a lot of controls, there aren't a lot of guardrails in place within, uh, those types of environments. [40:57.890 --> 41:16.370] So you pair that, uh, situation with a knowledgeable, um, uh, threat actor that maybe either doesn't care or improperly implements stuff or just they're again, if they're financially motivated or they're, uh, ideological, they're not testing their stuff effectively like a nation state would. [41:16.610 --> 41:23.610] So, uh, what is the scenario most likely that's happening right now in 2024? [41:23.610 --> 41:32.850] If there's a university that is attacked with a ransomware attack and they're told, give us 10 grand and you'll get back your university computers. [41:33.750 --> 41:38.270] Are they then giving them 10 grand and do they then get their data back? [41:38.490 --> 41:43.090] Is it spreading so much because it's actually, they actually work ransomware attacks? [41:44.610 --> 41:47.990] Well, for 10 grand, they'd get away very, very light. [41:48.390 --> 41:53.890] Most of the ransoms we're seeing these days are in the millions of dollars and effectively... [41:54.650 --> 41:55.130] Yes. [41:55.470 --> 41:55.610] Yeah. [41:55.930 --> 41:56.330] Yes. [41:56.630 --> 42:01.310] And well, so, well, they unlock their systems. [42:01.850 --> 42:06.430] So it's, remember what, what's happening is it's, their data is being encrypted. [42:06.430 --> 42:09.450] So the data is there, it's just encrypted and they don't have the password. [42:09.450 --> 42:13.990] The other thing is their data was also usually stolen, exfiltrated. [42:14.230 --> 42:20.990] And so the, and the bargain we strike is that the bad guys are not going to post that data on their public leak site. [42:21.070 --> 42:27.150] But everybody here, I hope recognizes that when they say we're going to delete it, that's worth, right? [42:27.470 --> 42:30.530] Um, but that's part of the bargain that they deleted. [42:30.790 --> 42:35.090] We pretend effectively that they're doing that and they don't post it. [42:35.090 --> 42:42.170] And by and large, I'd say about 95% of the time they follow through on those commitments because they're a business. [42:42.570 --> 42:54.370] And if I deal with them, if JT's dealing with them and they're the kind of business that doesn't follow through on that commitment, then I'm going to tell the client, listen, as bad as this is, it's not worth paying because you're not going to get what you're paying for. [42:54.370 --> 42:56.670] Uh, very interesting stuff. [42:56.850 --> 42:57.390] Thank you for this. [42:57.550 --> 43:05.210] Um, so I think that largely now nation states are performing ongoing reconnaissance. [43:05.390 --> 43:08.430] Pretty much every Internet connected system is being constantly surveilled. [43:08.910 --> 43:14.890] Microsoft did a report about activities of like sandworm and so forth and the run up to the invasion of Ukraine. [43:14.890 --> 43:30.730] And so I think a lot of zero days get stockpiled by, you know, three letter agencies and, and their, uh, counterparts, uh, you know, in other nation states in preparation for such events, you know, for the day the bombs drop and all of a sudden, you know, [43:30.810 --> 43:33.870] the power goes out and water isn't available and things like that. [43:34.250 --> 43:42.450] Um, but the vast majority, I think of financially driven activity seems to take advantage, not of, uh, such high value exploits. [43:42.570 --> 43:46.130] It's more like failures of blocking and tackling and basic due diligence. [43:46.370 --> 43:50.870] Um, things that are out of date, things that go unpatched, access controls that are insufficient. [43:51.130 --> 44:07.190] So my thought process is that, um, in order to reduce a lot of what we're seeing out there, there has to be some either positive or negative measures taken at the regulatory or policy level. [44:07.330 --> 44:12.050] Like my mind goes to what just happened today or which was disclosed with AT&T. [44:12.430 --> 44:28.990] Um, so do you think it's more likely that the government is going to implement, say, harsher penalties for basic failures or that they will implement some sort of positive input to say, we're going to fund these things to a greater degree or some combination, [44:28.990 --> 44:33.250] or are we just going to kind of cruise at the status quo and keep doing what we're doing? [44:34.250 --> 44:48.570] I'll tell you exactly the same thing I tell our clients, and that is expect a lot more pain coming from the government because the regulations that are, have been put forward that are going to be implemented. [44:48.810 --> 44:56.770] A lot of them this year will require companies, for example, in critical infrastructure to report within days of an incident. [44:57.710 --> 45:13.250] If it's ransomware within 24 hours, if it's a publicly listed company, they'll have to make this report publicly if it's material to their financial, to their, to their sector within four business days of reaching that decision. [45:13.610 --> 45:21.010] All of those things are generating greater liabilities because it's not just the government that brings the pain. [45:21.550 --> 45:27.990] It's attorney generals at states when there are infractions of data protection laws. [45:28.130 --> 45:29.990] And then there are legal measures. [45:29.990 --> 45:35.050] So shareholder suits, individuals have been harmed, companies that have been harmed. [45:35.330 --> 45:37.670] All of those things are starting to add up. [45:37.790 --> 45:45.430] And in the United States right now, the majority of the costs around a significant breach are not dealing with the incident. [45:45.650 --> 45:46.830] They're not the recovery. [45:47.030 --> 45:57.210] It's the litigation costs that may last two to five years as the company has to defend itself against multiple lawsuits and everything that goes into it. [45:57.350 --> 46:02.250] So some of that is dealt with through insurance. [46:04.170 --> 46:06.510] But that also has some costs, so. [46:08.450 --> 46:10.390] Unfortunately, we're out of time. [46:10.930 --> 46:16.190] So please join me in giving a huge thanks to Guillermo, James, and Ashley, for a great talk. [46:17.090 --> 46:18.070] Thank you very much. [46:19.870 --> 46:20.170] Good work. [46:20.430 --> 46:23.250] Can I just make a statement real quick? [46:23.590 --> 46:24.410] Real quick. [46:24.650 --> 46:36.610] If you work in this, in anything with SCADA and keeping our lights on and our water clean, please don't misconfigure FTP. [46:37.430 --> 46:42.850] I would like to live with my electricity and just be a hermit on the computer. [46:43.190 --> 46:44.970] So, I can figure it right. [46:45.210 --> 46:46.170] Thank you, everybody. [46:46.450 --> 46:47.150] Thank you, HOPE. [46:47.350 --> 46:48.550] Good closing argument. [46:49.750 --> 46:51.130] We need to decide real quick.