![From small-time scams to billion-dollar threats. [Research Saturday] — CyberWire Daily cover](https://megaphone.imgix.net/podcasts/58ab7ae0-def8-11ea-b34c-b35b208b0539/image/daily-podcast-cover-art-cw.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress)
Loading summary
Dave Buettner
You're listening to the Cyberwire network, powered by N2K.
Selena Larson
Cyber threats are evolving every second, and staying ahead is more than just a challenge, it's a necessity. That's why we're thrilled to partner with ThreatLocker, the cybersecurity solution trusted by businesses worldwide. ThreatLocker is a full suite of solutions designed to give you total control, stopping unauthorized applications, securing sensitive data, and ensuring your organization runs smoothly and securely. Visit threatlocker.com today to see how a default deny approach can keep your company safe and compliant.
Dave Buettner
Foreign.
Selena Larson
And welcome to the Cyberwires Research Saturday. I'm Dave Buettner and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems, and protecting ourselves in our rapidly evolving cyberspace. Thanks for joining us.
Dave Buettner
In my opinion, the impact to real life individuals, the disruption to their work, to their healthcare, to their schools, cities, libraries, homes, is very, very significant by threat actors, especially ransomware threat actors. And I just think that historically it has been underappreciated and under resourced in terms of defense against these threats.
Selena Larson
That's Selena Larson, threat researcher and lead for intelligence analysis and strateg at proofpoint. The research we're discussing today is titled why Biasing Advanced Persistent Threats Over Cybercrime Is a Security Risk.
Greg Rat
Well, let's walk through some of the history here together. I mean, how, how did we coin the term advanced Persistent Threat and what led us to where we are today?
Dave Buettner
Yeah, so it's funny because the apt moniker, which is of course advanced Persistent Threat and is essentially only used for threat actors that are operating on behalf of states. Right. So Russia, China, dprk, all of these big time bad actors that are operating on behalf of intelligence agencies all over the world. Advanced persistent threats. So I was digging through the history, the resources, and it was reportedly first coined in 2007 by a US Air Force colonel named Greg Rat. So this is of course, you know, based off of stuff that people have posted on Twitter, blogs. There's no real sort of like point in the dictionary definition when it was added to, you know, the Webster's English Dictionary that we can say this is when it was created.
Greg Rat
I can add, just as a name dropping aside here that I have interviewed Greg and he did indeed claim attribution of the term.
Dave Buettner
Yeah. So it's been around for quite some time. You'll notice that it did come out of the government, which I think a lot of folks who work in cyber threat intelligence and cybersecurity and are working in defense now have backgrounds in whether that's military, government intelligence agencies. And I think in many ways that has contributed to this bias of focusing on nation state adversaries. I mean even the term adversary, right. Like that's, that's something, it's tossed around a lot in our industry. But to the average person, it's not an adversary, it's a hacker. It's someone who's messing with my life.
Greg Rat
It reminds me of, you'll see on the local evening news, there'll be some sort of local crime and the police will use what I call cop speak, which is a perpetrator entered the edifice and drew his weapon. And it's like a bad guy went in and had a gun.
Dave Buettner
Yes, exactly. Exactly. Yes.
Greg Rat
So I mean, thinking of the roots here, does it, when we look back on the history, does it make sense that there was a focus on APTs, particularly in the time before the explosion of ransomware?
Dave Buettner
I think so. But again, I think that kind of goes back to the bias. Right. So I think how we know about APT, whatever threat actors is large part due to Mandiant APT1 report back in 2013 that was Chinese cyber espionage and that's how it really became this industry standard standards. So we're thinking about apt, we're thinking about nation state actors, we're thinking about the trouble that they cause in large part because that's the mindset and the focus of a lot of people that are working on these problems. But cybercrime ransomware and certainly banking trojans, even before ransomware were a multimillion dollar business, right? You have threat actors that were working on banking trojans essentially to steal people's money and they were using real money as opposed to cryptocurrency to commit crimes. But you know, in the early and mid 2000s, that's consumer focused ransomware. So it's not the big game hunting that it evolved to in, you know, 2014 through 2016. But you have in 2007 banking Trojans, Zeus, Gozi, they really created this business models where threat actors were targeting banking details and at very large scales. Right. And then when bitcoin really came on the scene, that was again 2009. So this was early days of bitcoin, but it really disrupted the criminal ecosystem. And you have things that grew out of the sort of usefulness of crypto as a criminal enterprise. So you have Gable versus Cryptolocker ransomware. As I said in the paper, they sort of kick started the age of the cybercrime kingpin in the mid 2010s. So you have the big sort of botnets that started as banking trojans, evolved to be loaders for ransomware that we know today. Emotetric bought Dridex, and then this is really when it started becoming a problem. But I don't think we focus on that enough as an industry in general writ large. Because I do think in part we were still very much biased towards apt, and I think to the benefit of the threat actors, frankly, because they were making lots of money and going after schools, hospitals, city and state governments, a lot of entities that were getting hammered by ransomware. But it wasn't really until Colonial Pipeline happened in around 2021 that we started thinking, oh wait, maybe ransomware can be bad. Certainly there were people working on this problem for a long time. But I think I told this story at sleuthcon last year. But my sister has been impacted by ransomware four different times. She's worked in the healthcare industry and since 2016, she's had multiple different ransomware attacks impact her life in different ways throughout the years. Most recently even last year, she was impacted by it and took down an application that she was using for, you know, important life things. And she's just like, this is just my life now. You know, like, I guess this is just what happens. She's like, you'll never guess what happens, Selena. And I'm just like thinking like, this is. My sister is just a regular person who's had her life disrupted by criminals multiple times. And she just feels like that's the norm. And that is what really makes. Makes me sad.
Greg Rat
How much of the bias do you think we're dealing with today? I mean, your average CISO who's out there deciding how to divvy up their resources, how are they dialing it in?
Dave Buettner
I think actually I do have to give a little bit of credit to marketing and journalism in general as well for highlighting apt, because frankly, spies are cool. You know, like you, you think it's very cool to have these stories on espionage and disruption and, you know, stealing information to improve, you know, their standing in the, in the global economy. But I think a lot of it is just like apts. People think apts are cooler and so they want to learn about them, they want to know about them, they want to, you know, make sure that they are, you know, protected by them. But in general, your average organization is at a much, much greater risk of being impacted and targeted by cybercrime than any nation state threat actor in general. And I think, you know, I think it's changing a little bit as we continue to talk about it and continue to have these, these types of conversations. But I still think it's very much there because there's this idea, you know, APT's are cooler.
Selena Larson
We'll be right back. And now a message from our sponsor Zscaler. The leader in cloud security Enterprises have spent billions of dollars on firewalls and VPNs. Yet breaches continue to rise by an 18% year over year increase in ransomware attacks and a $75 million record payout in 2024. These traditional security tools expand your attack surface with public facing IPs that are exploited by more easily than ever with AI tools. It's time to rethink your security. Zscaler Zero Trust +AI stops attackers by hiding your attack surface. Making apps and IPs invisible. Eliminating lateral movement. Connecting users only to specific apps, not the entire network. Continuously verifying every request based on identity and context. Simplifying security management with AI powered automation and detecting threats using AI to analyze over over 500 billion daily transactions. Hackers can't attack what they can't see. Protect your organization with Zscaler Zero Trust and AI. Learn more at Zscaler.com Security your business needs AI solutions that are not only ambitious, but also practical and adaptable. That's where Domo's AI and data products platform comes in. With Domo, you can channel AI and data into innovative uses that deliver measurable impact. Secure AI agents connect, Prepare and automate your data workflows, helping you gain insights, receive alerts and act with ease through guided apps tailored to your role. Data is hard. Domo is easy. Learn more@AI.domo.com that's AI.domo.com I wonder too.
Greg Rat
Because it seems to me like particularly in the earlier days of apts, it was kind of a get out of jail free card for any organization who got hit. You know, you would just, your communications person would stand up in front of a microphone and say there was nothing we could do. We were attacked by foreign adversaries with endless resources and so, you know, poor us. There's absolutely nothing we could have done. And people would kind of say, well that makes sense and go on with their business.
Selena Larson
And only occasionally would we later find.
Greg Rat
Out that it was a kid, you know, in a clubhouse or a tree house or their parents basement, you know, who brought down this major organization or something.
Dave Buettner
Yep, yep. I mean, absolutely. So the way that we talk about different threat actors impacts the way that we think about different threat actors. And I think having that sort of APT moniker is a little bit of a get a jail free card. However, I would say on the flip side of that though, not all apts state actors are advanced and many cybercriminal actors are considerably more advanced and sophisticated than some state adversaries. We've even seen some crossover with cyber criminal threat actors operating on behalf of of governments. There are certainly examples of this happening in Russia for example, and there's overlap there too. And I think from just a fundamental defense in TTP perspective in many ways, and this is my super mega hot take, and I know a lot of people are going to disagree with me, but in many ways attribution doesn't actually matter. It doesn't matter if there's a financially motivated threat actor or an espionage threat actor. What matters are the behaviors and making sure that your organization is defended against them. There are of course situations in which attribution does definitely matter. It depends on where you're looking at it. But from a fundamentally technical perspective, if we're seeing the increase of ransomware actors, cybercriminal threat actors, using zero days, investing and developing tooling and resources that are in many ways more advanced than what we're seeing from APT or state actors, there's not that sort of distinction between oh, state actors are a lot more advanced or oh, cybercriminals are just dumb kids, we don't have to worry about it and you know, my insurance will take care of that or whatever. They're operating at a level that is very high and you have to be very, very mindful about it. And the impact is so much greater to the general population and our communities at large. A ransomware attack on a school has significant impacts to the students safety, their education, their resources. If a school's closed because they can't go to because they had a ransomware attack, parents can't go to work so they have to rearrange their lives. There's all of these sort of follow on repercussions from a lot of this activity that in my opinion makes it a threat to our communities and our way of life and national security in different ways from the state actors stealing IP or pre positioning potentially for potentially critical infrastructure disruption, which of course would have its own very large impacts. But yeah, I don't think it's an either or anymore. And I think we have to be very, very mindful of that. We have to check our biases at the door when we're thinking about cyber defense and fighting back against these adversaries.
Greg Rat
What about some of the federal organizations and I'm thinking specifically of folks like cisa. Are they overly focused on apts at the cost of the hospitals, of the schools, of those sorts of things? Or is a sense that they're out there fighting the good fight, doing the best they can with what they've got?
Dave Buettner
That's a good question. I know it's a very hard problem to solve. There are of course limited resources that various agencies have to be mindful of. But I do think that there is still a bias in what we're thinking about what we're looking at from sort of a national level, you know, sort of assessment. I think we've seen a lot of great success in other countries kind of dealing with this. I think the NCA is a great example. The National Crime Agency in the uk they have done a really, really great job prioritizing ransomware in particular. But a lot of these cybercriminal operations that are having very, very big impacts to the people in their communities. And we've seen the destruction of lock bit cronos. We've seen some certainly Operation Endgame, which of course US law enforcement and US government agencies were involved in as well, which was a massive, massive blow to cybercriminal operations, which was a huge win. But yeah, I do think it could be talked about and focused on a little bit in some of these conversations. But of course I do know that I think China is really the main apt that I think a lot of organizations and intelligence agencies are really focusing on, which of course is totally reasonable with the various activity that has come to light over the last year. It is impactful and it is very, very important. So I do understand that there of course is a balance and it can be very, very difficult to, to figure out where to put those resources when we have limits.
Greg Rat
I wonder, because I find myself, and this is just my personal take on this, that I find myself sometimes frustrated that we have situations, for example, where hospitals have to shut down and you brought up the point that we have lost lives because of this. If a foreign nation were sending people here and physically shutting down hospitals, the response to that would be one of.
Selena Larson
Overwhelming force, I believe.
Greg Rat
And yet here we are. Do you understand my frustration or I guess maybe head scratching is a better word for it.
Dave Buettner
Dave? Absolutely. I have the same, I have the same reaction. I have the same reaction and I think it's really challenging to focus on this and say, well, it's understandable or to kind of be working in a Space. And you're like, this is such a big problem. Why aren't we doing more? Why can't we do more? And I mean, certainly just people in my own life who have been impacted by this and have had some of these experiences, certainly in healthcare in particular, the impacts are just so awful to the people, like not being able to get your medication, not being able to have your surgery, potentially having ambulances diverted to other places for care. You know, it's like, it's very, very impactful to the human experience. And I don't know why it has taken quite such a long time for everyone to be like, oh wait, this is a big problem. And I don't, I think in general, the cybersecurity industry could use a little bit more empathy all around. Not just for ransomware impacting, you know, various organizations that, you know, have a really, really, really very difficult time and often times are shut down. But also, you know, we've talked about this in the past too, like romance scams, scams in general, people being impacted and targeted by crime that is, you know, quote unquote, just digital. Like the same reason someone came up and purse snatched you in person. People are going to care about that. That's going to be really, really hard. But if someone social engineers you and steals your money, there's just this lack of empathy. And to me, that's been probably one of the most difficult parts about working in this industry is sort of seeing that and being like, wait, this is a big deal, we should care about this, we need to focus on this. And, and you know, other people maybe not necessarily agreeing.
Greg Rat
So how do you suggest we move the needle here? How can we redirect the conversation and get the emphasis where it needs to be?
Dave Buettner
So I think it's really important to, you know, change the mindset across the board, how we're talking about these threat actors, how we're understanding some of the risks and impacts. I mean, I mentioned this before, but the reality is most organizations are at a far greater risk of being targeted by cybercriminals. And I think it's really important threat intelligence practitioners, people reporting on this certainly in the media, is to make, to tell those stories and the impacts from a business perspective, but also very much a human perspective. And I also think it's very important for us to focus on the ttps, the tactics, techniques and procedures, and not necessarily the who, but the how. So if you're in your organization and you're developing detections and you're trying to prioritize what do we care about? Maybe think less about the who, but think about the how. What are the major techniques that are being used by these adversaries? What are the ways that we can make sure that our organization is offended? How can we be educating our users to not necessarily fall for some of these techniques and really make sure that regardless of who is behind the behaviors, do as much as you can to prevent any sort of exploitation of known TTPs so that you're defended whether it's a state actor that's using them or whether it's a ransomware that actor that's using them. I think too, we've seen some really great successes over the last year in terms of when it comes to disrupting cybercrime. And I think that old chestnut, public private partnerships, which is a phrase that I think gets thrown around a lot, but it is also very important. And I think Operation Endgame is really sort of the standard at which all of these things should be upheld to. Right. I mean, we saw it was a cross government, cross country, many, many different organizations were involved and they went after not just the ransomware itself, but the ecosystem that enabled ransomware. Right. It was, of course, a long, long time investigating, but it was a lot of sharing between many, many people to having a common collective goal of disrupting these things, cutting the head off the snake, so to speak. But of course it was five different heads because it was multiple different malware families. But it's huge. I mean, Europol called it the largest ever operation against botnets, which played a major role in the deployment of ransomware. That was a huge win and I really, really hope that we can learn a lot from that and hopefully moving forward, see much, much more of that.
Selena Larson
All right, well, the research is titled.
Greg Rat
Why Biasing Advanced Persistent Threats Over Cybercrime Is Risk. Selena Larson, thanks so much for joining us.
Dave Buettner
Thanks so much for having me, Dave. I will happily talk about E crime with anyone.
Greg Rat
There you go.
Selena Larson
Our thanks to Selina Larson from Proofpoint for joining us. The research is titled why Biasing Advanced Persistent Threats Over Cybercrime is a Security Risk. We'll have a link in the show notes. And that's Research Saturday brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com this episode was produced by Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher. And I'm Dave Buettner. Thanks for listening. We'll see you back here next time.
CyberWire Daily: From Small-Time Scams to Billion-Dollar Threats [Research Saturday]
Release Date: February 22, 2025
Host: Dave Buettner (N2K Networks)
Guest: Selena Larson, Threat Researcher and Lead for Intelligence Analysis and Strategy at Proofpoint
Contributor: Greg Rat
In this episode of CyberWire Daily, host Dave Buettner engages in a compelling discussion with Selena Larson and Greg Rat about the evolving landscape of cybersecurity threats. Titled "From Small-Time Scams to Billion-Dollar Threats," the episode delves into the prevalent bias within the cybersecurity industry that disproportionately emphasizes Advanced Persistent Threats (APTs) linked to nation-state actors, while often underestimating the pervasive impact of cybercrime like ransomware.
Selena Larson introduces the core research topic: "Why Biasing Advanced Persistent Threats Over Cybercrime Is a Security Risk." She and the guests explore the origins and definitions of APTs.
Dave Buettner explains the term "APT," stating:
"The apt moniker, which is of course, advanced Persistent Threat and is essentially only used for threat actors that are operating on behalf of states. Right. So Russia, China, DPRK, all of these big-time bad actors..." [02:10]
Greg Rat adds historical context:
"It was reportedly first coined in 2007 by a US Air Force colonel named Greg Rat." [02:20]
The conversation highlights a significant industry bias towards focusing on nation-state actors, often at the expense of addressing more widespread cybercrimes.
Dave Buettner critiques this focus:
"In many ways that has contributed to this bias of focusing on nation-state adversaries... But cybercrime ransomware and certainly banking trojans... were a multimillion-dollar business." [04:01]
He emphasizes that cybercriminals have long been financially motivated and sophisticated, challenging the notion that APTs are inherently more dangerous.
Selena Larson and Dave Buettner discuss the tangible effects of cybercrime on individuals and institutions. Dave shares a personal story to illustrate the pervasive disruption caused by ransomware:
"My sister has been impacted by ransomware four different times. She's worked in the healthcare industry... she's had multiple different ransomware attacks impact her life in different ways." [07:52]
This narrative underscores the normalization of cybercrime's impact on everyday lives, from healthcare disruptions to the closure of schools and libraries.
The guests examine how organizations, guided by prevailing biases, allocate resources to defend against threats. Dave argues that most organizations face a higher risk from cybercriminals than from nation-state actors:
"The average organization is at a much, much greater risk of being impacted and targeted by cybercriminals than any nation-state threat actor in general." [08:23]
He contends that the allure and media portrayal of APTs overshadow the more immediate and widespread threats posed by cybercrime.
The discussion turns to federal agencies like the Cybersecurity and Infrastructure Security Agency (CISA) and their focus areas. Dave acknowledges the challenges these agencies face due to limited resources but points out the persistent bias toward APTs:
"I do think there is still a bias in what we're thinking about what we're looking at from sort of a national level, you know, sort of assessment." [15:50]
He praises international counterparts, such as the UK's National Crime Agency (NCA), for effectively prioritizing ransomware and disrupting cybercriminal operations through initiatives like Operation Endgame.
Greg Rat expresses frustration over the lack of a robust response to cybercrimes compared to physical attacks:
"If a foreign nation were sending people here and physically shutting down hospitals, the response to that would be one of overwhelming force... And yet here we are." [17:27]
Dave Buettner echoes this sentiment, highlighting the human cost of cyberattacks:
"The impacts are so much greater to the general population and our communities at large... It’s a threat to our communities and our way of life and national security..." [18:10]
To address the imbalance, Dave proposes several strategies:
Change the Mindset: Shift conversations to prioritize cybercrime alongside APTs, emphasizing both business and human impacts.
Focus on TTPs: Concentrate on Tactics, Techniques, and Procedures rather than the identity of the threat actors. Dave states:
"What are the major techniques that are being used by these adversaries? What are the ways that we can make sure that our organization is defended?" [20:11]
Public-Private Partnerships: Strengthen collaborations between government and private sectors to disrupt cybercriminal ecosystems, drawing lessons from successful operations like Operation Endgame.
The episode concludes with a reiteration of the research title and a call to action for listeners to engage with the findings. Dave emphasizes the importance of reevaluating industry priorities to better defend against the more immediate and widespread threats posed by cybercrime.
Selena Larson summarizes:
"The reality is most organizations are at a far greater risk of being targeted by cybercriminals." [20:11]
Bias in Focus: The cybersecurity industry disproportionately focuses on APTs linked to nation-states, potentially overlooking the pervasive threat of cybercrime like ransomware.
Real-World Impact: Cybercrime has significant real-life consequences, affecting individuals’ daily lives and essential services such as healthcare and education.
Resource Allocation: Organizations and federal agencies may need to reassess how they allocate resources to balance the focus between APTs and cybercriminals.
Strategic Defense: Emphasizing TTPs and fostering public-private partnerships can enhance defenses against both state-sponsored and financially motivated cyber threats.
Dave Buettner [02:10]: "Advanced Persistent Threats... are essentially only used for threat actors that are operating on behalf of states."
Greg Rat [12:18]: "You would just... say there was nothing we could do. We were attacked by foreign adversaries with endless resources."
Dave Buettner [08:23]: "The average organization is at a much, much greater risk of being impacted and targeted by cybercriminals than any nation-state threat actor in general."
Greg Rat [17:27]: "If a foreign nation were sending people here and physically shutting down hospitals, the response to that would be one of overwhelming force... And yet here we are."
This episode of CyberWire Daily underscores the need for the cybersecurity industry to broaden its focus, ensuring that the response to cyber threats is as comprehensive and nuanced as the threats themselves. By addressing biases and promoting strategic defenses, the industry can better protect organizations and individuals from the multifaceted dangers of the digital age.