Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
Hello, everyone and welcome to the Hacking Humans podcast, where each week we look behind the social engineering scams, phishing schemes and criminal exploits that are making headlines and taking a heavy toll on organizations around the world. Dave. I'm Dave Buettner and joining me is Joe Kerrigan. Hey, Joe.
C
Hi, Dave.
B
And our N2K colleague from the T minus Space Cyber Briefing, Maria Ramosis.
A
Maria, hello, Dave. And hello, Joe.
B
We've got some good stories to share this week, but first we've got some follow up. Maria, you want to take the honors here?
A
Oh, do I ever. So we got this comment from a listener and it goes like this. Longtime listener, first time writer. I am cranking the album Jealousy by X Japan as I type this. I nearly choked on my morning coffee when Maria mentioned X Japan. And I nearly spilled it when so claimed heavy metal fan Joe said he never heard of them. Why is there chicken talk when we could be talking about the greatness that is X Japan? I totally agree. Love the show. Maria is a great addition. Thank you very much. Keep up the great work. You guys do a great job with the Hacking Humans podcast. Thank you. Thank you so much.
C
Let me go grab my phone right now. Hold on. Let's see. All right, pulling up Spotify and I'm going to.
A
Just for the record, what? N2K wants to do a Japanese metal podcast. I am here for the hosting duties on that one.
C
See, I did not know they were metal.
A
I mean, it's like symphonic metal. It's. They had their name. Yeah, like late 80s hair band, but like very melodic music.
B
Okay.
A
Don't think thrash music. Think more heavy orchestrations. Drama.
C
Not really fresh.
A
All right. Yeah.
B
So sounded, I don't know, the one song I listened to in response to this feedback. Sounded plenty thrashy to me.
C
It did sound. I heard.
A
It depends on the song. Depends on the song. Yeah.
B
All right.
C
This album is from 1991, Jealousy. I am putting it on my Spotify right now. So when I get in my car, it will play and I will listen to the album and let you know what I think next week.
B
All right.
A
I would be very curious. Well, I won't be here next week, so you're going to have to let me know next time. I'm trying to remember.
B
Next time Maria's back, we will compare notes.
A
Let me see what's on the track listing. Okay. Not my favorite album of theirs, so I'll be curious to hear what you think. I will give you and anyone, if this makes it into the final cut. The vocalist is extremely polarizing. So if you go, music's great, but I can't stand the vocalist. It is known. Okay.
C
So that's how I feel about just about every single death metal band.
A
Yeah, I had a really hard time with the vocalist like that. He's just, he's known for his style. It's just very distinctive. I'm not gonna describe it, but yeah, my favorite song of theirs is probably their most famous song, so I'm pretty basic. It's called Kurenai and it's like the most fun song to sing at karaoke in existence. It's so, so fun. But it's not on that album, Joe. So I'll send it to you separately.
C
Okay.
A
Yeah.
B
All right. Well, thank you to the listener who sent this in. Greatly appreciated. We love getting follow up from you all and love to read your comments. Let's take a quick break to hear from our sponsors and when we come back, we will get into our stories. Every attacker counts on one thing. Environments that trust too much. Threatlocker closes that gap with default deny at execution. Unknown software blocked, trusted apps contained with ring fencing, configurations verified with Threat Locker DAC so you stay secure and compliant. ThreatLocker delivers the visibility and control CISOs need without adding operational pain, making zero trust real for teams of any size. Stop ransomware at its earliest point. Book a demo@threatlocker.com N2K. All right, we are back and Joe, you are up first this week. What do you got for us?
C
So this is not really a social engineering story, but it is an interesting story that I think is relevant to all of our listeners, whether or not they are cybersecurity experts or not. We have talked in the past about how many devices we have in our house connected to our Internet services.
B
All of them.
C
All of them. Right. And it's a lot. Well, the Wall Street Journal has an article by Robert McMillan called How Hackers Found a Backdoor into the American Living Room. This is from like the middle of last month. And it starts out with a story about two years ago. A top Microsoft security executive reaches out to his counterpart over at Comcast and Microsoft is investigating some kind of like, hack digital break in linked to one of the most capable cybersecurity foes in the world is what it says here. But they needed to investigate six IP addresses which are what your it's how the Internet knows which computer to send things to or one of one of the parts of the ways that it does that. And this article keeps referring to it as the Internet's equivalent of a phone number. And I think that's probably a helpful analogy, not really accurate. But if you don't know what an IP address is, you can just think of it as the phone number for your house on the Internet.
B
Okay. Right.
C
Comcast found that an organization called Midnight Blizzard. I love these names for these hacking same. This is a hacking group from Russia's foreign intelligence service had accessed email accounts and they had accessed email accounts from senior Microsoft leadership and they were using these consumer Internet connections to mask their traffic. Because if you just come in from Russia and try to log in on a Microsoft server, Microsoft has very basic security that says, hey, there's no way you're in Russia. No, you can't have access to. So here's what Comcast found when they were investigating this. They found that there is a low cost consumer devices shipped to the US with backdoor software pre installed on it. And this software is also being installed in mobile apps and pirated games, pirated video games. Right. So if you're downloading pirated software from wearer's sites, if you will, there's a very good chance that you have some kind of malware on there.
A
Well, yeah, I mean I think anyone who's pirated video games knows that that's going to happen.
C
Right.
A
I'm just saying I've never done.
C
I don't care, I just want to play the game, right?
A
No, I've definitely never done that.
C
No, of course not.
A
No, no, no, no, not at all.
C
So what, what has happened is this software, this backdoor software has turned tens of millions, literally tens of millions of consumer devices and app computers as well into a criminal cloud computing network. And these networks have a name, they're called Residential proxy networks. So what that means is residential is just in somebody's house or parts of it are in the house. It's a proxy that lets you represent like you're coming out of that house's IP address or coming from that house and network is just, you know, all these things linked together. And government industry officials have said that this problem has ballooned. Absolutely Gotten huge over the past couple of years. And there's an organization called the Digital Citizens alliance that is a digital advocacy group. And they are estimating that There are about 20 million of these devices in the back with backdoors in the US alone. 20 million.
A
You know, this reminds me, Dave, does this remind you at all of the conversation we had with Brandon Karp recently about Sort of malicious GPS signals that are squatting on genuine ones. And they were seen to be also coming from Russia. Do you remember that conversation we had?
B
I do, I do, yeah.
C
Oh, was that the. I saw a YouTube video about this.
A
Yes.
C
That was coming from the satellite. Yes, veritasium. Yeah, yeah, yeah, I watched that video.
A
Yeah. And it was basically using legitimate GPS signals to mask what is presumed to be sort of tests of an emergency system, which just is sort of a similar thing going on, using a legitimate service as a smokescreen, but also presumably from Russia. That's very interesting.
B
Right, right.
C
I don't know that there's anything anybody can do about a Russian satellite broadcasting information across the GPS part of the spectrum. That's a different problem.
A
Yes, right, yes. These sort of rhyme. They're not the same thing.
C
Yes, correct.
A
To me, they rhyme, that's all.
C
So the IP addresses that Microsoft provided belonged to customers who were on one of these networks. It was put together by a Chinese provider and they called themselves IP Idea. And IP Idea gets a software installed on devices. Like it gets it preloaded on video streaming boxes and digital picture frames. Do you have a digital picture frame, Dave?
B
Not one that's hooked up to anything.
C
Right. I have never had a digital picture frame. I've just. From the very get go, these things have always seemed sketchy to me. And there have been multiple stories about these things coming with malware on them. So I just don't buy them, you
B
know who loves them?
C
Who?
B
Grandparents.
C
Grandparents. Come on.
A
They sure do.
B
They do, yeah.
C
Right.
B
Yeah. When my parents were around, they had one. I can think of several grandparents I know who have them. And what's great about it is the grandchildren can update the photos on them remotely. And so grandma comes in and I
C
don't know if that's a great idea. Cause right now I've got a nephew that's getting into, you know, getting into computers and stuff and is looking at. He would definitely do something awful.
B
Okay.
A
To his grandma. Really?
C
Yeah.
B
To his grandma.
C
Yeah.
B
In a normal family.
C
Right. I mean, it would be funny. It would be something that would make me laugh.
B
Right.
C
It would be hilarious.
B
Sure.
C
It would not be my. And my mother would probably be like, I'm gonna strangle Ethan or Joe next time I see them. One of the two. No, I'm sorry, not Ethan, it's Colin.
B
But I think it's these low cost devices that aren't very well scrutinized as they make their way over here.
C
Yes. So Comcast, our engineers took a Look at these 6 IP addresses and found now, this number is staggering to me, that they were part of a network that was about 750,000 IP address networks located in homes and businesses. Three quarters of a million IP addresses. Now, when you're a Comcast customer, you get one IP address on the Internet, right? Right. Now, your machines, your machines inside all have different IP addresses that are subnetted out differently than the rest of the Internet. And there's something called network address translation, which manages communication between your machine and the outside world. But you get one, that means there are 750,000 homes or business locations that are part of this network. And there could be multiple devices inside these things. And that's just from Comcast. So this thing is huge. Now, in January, Google got a court order to go ahead and dismantle IP Ideas infrastructure. Guess how long it took them to get it back up and running?
B
Well, we talk about machine speed, so I don't know, are we talking nanoseconds, days? Weeks?
C
Number of weeks?
B
Number of weeks? Okay, yeah.
C
Okay, guess how many weeks?
B
I don't know. Maybe a month or so.
C
Two weeks.
B
Two weeks. Two weeks.
C
It was back up and functioning. So, of course, as you know, this is not really a technical podcast, and this is a very technical story. And I will put a link to the show notes in the show notes to the story. There is another story in the middle of here that talks. It says how to protect yourself from these networks. And it has a link to a tool from a company called Spur Us. And I have not done this on my home network, but I am going to do it tonight. And if you click on the link for Spur Us, then it will tell you when you click on it, there's a field there that says Observe Risks. And it may say N A or none. As long as there's nothing in that field that says observe Risks, you're probably okay. But if there's something in that field, you need to pay attention to that.
B
Yeah, I want to say, I don't know. In the past year or so, there was a story about how the FBI had gotten permission to go out and basically patch a bunch like thousands, tens of thousands of people's home routers.
C
They weren't Netgear, were they? They were TP Link routers.
B
Yeah, I think that's right.
C
Because TP Link doesn't sunset their routers. Netgear and other router manufacturers will say, yep, your router no longer works.
B
Yeah, and you can understand. Cause it's one of those. If it Ain't broke, don't fix it kinds of things.
C
Right.
B
Your router just sits there doing its job, minding its own business. But if you're not keeping its firmware up to date, which nobody does, then maybe every five years, just go buy a new one.
C
Yep.
B
Right.
C
You could do that. That would be a great help.
B
And first thing you should do is change the password.
C
If you are technically inclined, you can take that old TP link router and install an open source routing operating system on it, if it's compatible. And there's. If you're technically inclined. If you're not technically inclined, just go buy a new router.
B
That's the simplest solution.
C
It's gonna save you the most amount of time and effort.
A
Yeah, but have you ever been to someone's house and the router's like 15, and they're going, why doesn't my TV have streaming video worth a damn? I mean, I've been in that situation.
C
Yeah, yeah, that's. That's a hardware issue, you know?
A
I know, but. But just like, buy a new router every five years. It's like that. That's very ambitious for a lot of people.
B
Right, well, that's my point, though, right? Like, you know, I mean, if I would. If you're, like, on the cutting edge. Well, how often do these protocols get updated? Every two or three years.
C
Maybe we get like.
B
Like WI FI protocols. WI FI protocols.
C
Oh, yeah. Well, the old WI FI protocols still work, right?
B
Right. But they get better and faster and more robust and more secure and all those kinds of things. So every few years to invest in a new router, because they're not that expensive, and get the security updates that come with it. To me, that's money well spent. So you put it on your calendar. Every five years, it pops up, it says, hey, knucklehead, go buy a new router.
C
Right. That's a good idea. That is the easiest way to get around the router problem here. Now, that doesn't solve this other problem of these residential proxy networks from cheap devices that you buy and put on your network because they just hop right over the firewall. Because they're making connections from the outside.
B
Right.
C
Or from the inside, rather, just real
B
quick, in case folks are still not 100% clear on what this is about. Basically, this is somebody putting some software on a device in your home so that they can pass their data through it remotely so that it looks like it's coming from inside your home.
C
Correct.
B
Rather than from them.
C
Correct.
B
And so the places that they want to get to the places they want to do the bad things they want to do. They're more likely to have their defenses down for something coming from a home in middle America than from, like Joe said, Russia.
C
Right?
A
Yep.
B
So that's what the residential prox. That's what they're doing here. They're trying to mask their traffic to make it look like it comes from somewhere benign. And they're very good at it.
C
Yeah.
B
All right. We will have links to that story in the show notes. My story this week comes from the folks over at Bitdefender, and this is about some fake emails that are being sent out to folks claiming to be from Interpol, which is the European law enforcement agency. And they're targeting small businesses with ransomware. And this is a phishing campaign that seems to be focusing on small businesses. This article says across Europe, Asia, the Middle east, and the United States with fake investigation emails impersonating law enforcement officials. So, of course, as these things work, the email comes and gets your attention right away. They have a copy of one of the emails here, and the email title is Emergency Response Needed.
C
Don't send me an email.
A
Yeah, I'll get to it in, like, two weeks. What is wrong?
C
You're not getting an emergency response from me via email, no matter what. Yeah, that's just not happening.
B
Yeah.
A
Plus, I don't take inbound calls, so you gotta send emergency. I don't know what else to tell you.
B
So it says, dear Compliance, we're writing to bring your attention. We are writing to bring to your attention information that may be relevant to your organization's compliance and security review. Based on information that has come to our attention, there may be activities involving account systems or services associated with the organization that warrant further examination. We have obtained information and video material that may assist in your assessment of that matter. So it goes on and continues to be a scary email.
A
So generic. Yeah.
B
They give you a link to a Proton Drive account, so a cloud storage area. And they're telling you that there's this video file that you need to check out. And when you go to check out the video, download it. It is a compressed file. When you open it up and go to View installs malware. It is password protected, which makes it the archive hard to inspect by.
C
So Proton can't open it up and go, what's in here? And do a virus scan on it and go, hey, you're distributing malware.
B
Right? Right. So they're disguising this executable file as a video file and taking advantage of the fact that most people are probably innocent or ignorant to how that's even the thing. Right. And of course they're curious. They want to see the video that has to do with videos a little more interesting than other types of media they might send you. Like, what could they possibly have a video of that has to do with me or my business? But no, it's just malware. And once it's installed, they encrypt your files and they present you with a ransom message. Yeah.
C
So this is run of the mill ransomware.
B
It's run of the mill ransomware. But the phishing technique is particularly interesting just again, in how they're short circuiting your emotions by telling you there's an emergency.
C
Right.
B
They're sending you to a third party location. Right. With the proton mail. They're getting you to open a mysterious file and telling you that it's one thing when it's another. And when you open the file, it installs malware. And that's the ball game.
C
This is very old school.
A
Yeah. I was just thinking, it reminds me of the. Is this you sort of video DM scam? And there's like versions of this that go way, way back. But yeah, this is.
B
Now this is the first one, Maria, I think this is. This is BM before Maria on the hacking humans.
A
Please let's not use that acronym again.
B
I like it. Kind of has a nice ring to it, don't you think, Joe?
A
It's very gritty.
C
I do not like it.
B
But Joe, you're no fun.
C
I snicker every time you say it. Yes.
B
So, yeah, before Maria. Before Maria. Yeah. So I fell for one of these. It was before we were doing the show. I think it was before I was working with the Cyberwire. Really? Yeah, I was just.
A
Cause it is bc.
B
That's right.
C
Bc.
B
But it was exactly that. It was just text message from someone I knew. And it said like, hey, Dave, did you see this video? And I was like, what video?
C
Yeah, no, let me look.
B
Yeah. And so I think it led to like a Facebook login, which of course was fake. And anyway, they pwned me. We all learned a valuable lesson that it happens, Dave.
A
Yeah, it happens. It happens. There's been a lot of flavors of that one. And I mean there were email versions of it, there were SMS versions of that. There were. I mean, I remember when Twitter was still the. The big one. There's a lot of Twitter DM scams around that specific issue. You know, someone, hey, I got this video of you, can you, you know, you're doing something very untoward in it, you know?
B
Right.
A
Can you verify that this is you? I don't know if that's a terrifying allegation.
C
That's a missing video of you from the Christmas party.
B
That's right,
A
yeah.
C
That's a terrible Patrick Starbuck.
B
All right, well, I will have a link to that story in the show. Notes again, that is from Bitdefend. They got some good tips in there of how to protect yourself against this sort of thing, but like Joe said, this is kind of an old school, greatest hits sort of thing. There are lots of opportunities along the way, along the attack chain for you to interrupt and stop this. But starting from the very beginning, you know, someone tries to set you off your game, tries to put you on edge and mess with your emotions, that's about as big a red flag as you can get.
C
Yeah. Just respond to this with another email that says, you'll never take me alive, coppers.
B
Come back with a warrant.
C
Right. Don't do that. Don't just delete the email. Move about your day.
B
All right, we're going to take a quick break here before we come back with the rest of our show. We'll be right back. Most environments trust far more than they should, and attackers know it. Threat Locker solves that by enforcing default deny at the point of execution. With Threat Locker allow listing, you stop unknown executables cold. With ring fencing, you control how trusted applications behave. And with Threat Locker DAC defense against configurations, you get real assurance that your environment is free of misconfigurations and clear visibility into whether you meet compliance standards. ThreatLocker is the simplest way to enforce zero trust principles without the operational pain. It's powerful protection that gives CISOs real visibility, real control, and real peace of mind. ThreatLocker makes zero trust attainable even for small security teams. See why thousands of organizations choose ThreatLocker to minimize alert fatigue, stop ransomware at the source, and regain control over their environments. Schedule your demo@threatlocker.com N2K today. And we are back. Maria, what do you have for us this week?
A
Well, I have the end of hacking humans. Ah.
B
Oh, great. At last. Yeah.
A
There was an opinion article in Dark Reading by Arun Vishwanath and the subthought the title is the beginning of the end of social engineering. And I went, okay, it's over. Finally, we can all retire. And so this opinion piece is about the idea of with the advent of AI. Everybody drink? I just talked about AI we may be seeing AI actually as something that can help detect all sorts of inbound malicious behavior that might normally socially engineer the average person. So, for example, when you have mobile operating systems like iOS or whatever Google uses. Because I'm not an Android.
B
Android.
A
Android, yeah, just Android's, whatever their. Their OS is flavor of the month. Because they always name them, like, interesting things. I don't know what they call now.
C
They just give them numbers.
B
Oh, didn't they used to be like ice cream sandwich?
A
Yeah, yeah.
C
They were named after desserts. Alphabet.
B
I see.
A
Okay, so it's just numbers now. It's been a while since I've used an Android phone, so that's why I was like, I don't know what the current one is anyway.
C
Stupid and cutesy. I hated it.
A
All right, I'm going to go try that one again. With a lot of the operating systems for mobile systems now, whether you like it or not, and I don't really like it, they have AI systems embedded. Vishwanath is arguing that these AI native operating systems could make it so we don't have to maybe work so hard to train human beings to sniff out malicious incoming phone calls or phishy SMSs or just phishing emails in general, because the onboard AI systems will actually do that work for you. So I thought this was just like a really interesting idea. And I remember going, when I was reading it, this is an interesting idea. I don't know if I want to live in that future, but at the same time, this could be great if this actually works. If it actually works. So the idea is that again, the burden goes away from the person and then the device itself becomes a thing that protects people. And I was just. It's a very interesting op, ed. It's not terribly long, so definitely, please everybody, read it. I'd love to get your thoughts on it.
B
You know what my thoughts are, Maria?
A
Yeah.
B
Fool me once, shame on you. Fool me twice, shame on me. That's right. Because I remember we all thought, oh, wouldn't this be great? We'll have targeted advertising. They'll be able to gather information about us, and then I won't see ads for things that I'm not interested in.
A
Yeah, that definitely never happens.
C
No, it did not.
B
Who are we going to trust to look over our shoulder when all this stuff is happening? To look out for us, but simultaneously, like, what's the deal with the devil we're gonna have to make here?
C
Oh, we can trust these big tech giants.
A
Yeah. Yeah. And definitely using AI is not like just essentially a slot machine. Whether or not you actually get something accurate is just a matter of chance. And it's definitely repeatable. Yeah. So his argument. And again, I found it interesting. I'm not saying I think it's valid necessarily, but he's more of an expert than I am. He was saying, you could imagine that your phone is gonna be telling you this person is who's calling you, is claiming to be your bank or you. At the same time you're getting a password reset email. And all of these patterns put together mean that this is probably something fraudulent going on. Don't trust it. That is interesting to me that the idea is that maybe your device could be your helper in saying there's a lot of things happening inbound at you at once. Putting all of this together, this is a pattern of behavior saying something's not right here. Maybe don't trust whatever's coming at you. But yeah, is it repeatable? Is it trustworthy? I'm remembering when AI summaries of stuff came out for a lot of people's mobile phones. Those summaries were often really comically wrong.
C
They were awful, right?
A
They were hilariously wrong. I remember we were all trading sort of war stories about that. Maybe they've gotten better. I don't use any of this. I have disabled as much of it as I can on my phone because I just don't want it. Which is another angle right there. But another wrinkle to this story that the author mentions also is that, well, scammers will also get wise to this if we start using AI to help protect the user on device. So maybe the scammers will go, well, to heck with you. I'm not going to try and even scam the person anymore. I'm going to try and fake out the AI protection, just go around the human entirely and just mess with the AI system. So maybe the AI assistant would instead become the first target. So I guess our show would become hacking AI agents instead of on behalf of humans. Right. But it's not as catchy of a title, so, you know.
B
No, it just doesn't really work.
A
No harder than a T shirt.
B
Yeah, hacking.
A
Hey, I. No, it doesn't work.
B
I like the idea of this. Yeah, I like the idea of. And again, I tend to. For better or for worse, I tend to think back of my parents and how helpful it would have been to have some kind of full time assistant. We all know their names, right?
C
Don't say it.
B
No, don't say it. But not only Listening all the time, but tapped into their network. So monitoring their phone, their devices, that's the ideal thing to think about. Someone who is vulnerable has this device, this Persona, watching their back. I love the idea of that.
A
Yes.
C
Yeah. It's a good idea.
B
Yeah. But I am so, I guess, worn down and cynical about the potential execution of it, and rightfully so, I think.
A
Yeah, I would agree with that.
B
How much has been burned?
C
Won't social media be great? You can get in touch with everybody and you can have relationships with people you've. You haven't seen in years. You can keep in touch.
A
You can hear the opinions of literally anyone in the most remote corners of the world.
B
That's right.
A
Including.
B
People have an equal voice. Oh, yeah.
C
It's just a dumpster fire, though. And no, everybody does not have an equal voice. There's plenty of examples of these social networks silencing people that dissent that they don't like, that are saying things they don't like. I heard somebody saying, hey, they just didn't like what I had to say, so they muted me or something. Ridiculous.
A
That guy who stands on the street corner in your town center who just raves at passing cars. Well, he's now your town's most active Facebook commenter. And they gave him a badge. That's right.
B
That's right.
A
He never misses a post. Yeah. And he drives the loudest voice on there. Yeah. Lots of engagement. So we make sure that you always see what he has to say.
B
Right.
A
Great.
B
Yeah.
A
What a world.
C
Yeah.
A
Yeah, yeah, yeah.
B
I wonder how you could balance it, though. I don't know. Again, love the idea,
A
but, yeah, I had the same reaction. Like, whenever I'm sort of talking family members through a lot of this stuff, I often think it would just be easier if before they answer email or the phone, they just talk to me first.
C
Right.
A
How do I duplicate that? Obviously can't, but wouldn't it be nice to just have a sense of your friendly neighborhood nerd just keeping an eye out for you at all times?
C
Pocket nerd.
A
Pocket nerd.
C
That's what you can call it because it's on the phone in your pocket.
A
Maybe a squad of geeks. Wait, no, that's been tried. Yeah, we've seen this play out before, but again, in theory, it sounds great. In theory.
B
I wonder if there needs to be either a custom OS or an OS overlay for vulnerable populations. You know, that. That has this kind of thing built in.
C
That's not a bad idea.
B
You know, the. I don't want to Say dumbed down, but with higher, taller walls and deeper moats.
C
Right.
A
I mean there's this WI Fi landline for kids thing. Dave, I think I've mentioned it's called Tin Can I got for my kid and I've heard that actually a lot of people are buying them for their elderly parents because it works through allow listing for phone calls. So it's, it's super simple. There's no apps, it's just, you know, WI fi calling. But because it is explicitly allow listing, you can't get any phone calls from anyone who's not already pre approved, which is real nice. Yeah, I don't know. Yeah, I'm a big fan.
C
It's called Tin Can.
A
Tin can, yeah.
C
I mean app or is that a piece of hardware?
A
It's a physical piece of hardware. It's just, I'm not getting paid for this. I'm just, I'm a customer. It's like I feel like we should bleep the name because like they're not sponsoring this podcast. But it's, it's, it is a very unfancy, you know, wifi, just, just a VoIP phone. I mean there's nothing really complicated about it, but it doesn't have any screens. It's just a physical phone like the kinds we all used to have. And on the back end it is fully allow listed and you can also put quiet hours and we don't have to run any of this for the podcast.
B
I'm just, I've mentioned it here before that I'm only half joking. You know, Sony used to have a brand called My First Sony which were little devices for little kids. So you had, and they were just, you could beat the crap out of them. Right. So it was like a cassette player, you know, that you could throw across the room, it would be fine. So my first Sony, I say my last Sony.
A
Yeah. Honestly, a lot of these apps and devices that I see on the market for, you know, in theory to help kids have a more social media free childhood I think are going to be great for a lot of us adults who are just sick of it.
B
Yeah.
A
And you know, allow listing for phones. I mean, I would have just gone back to proper going through my local phone company and getting a landline. I had done that actually when my husband and I first bought our house, but we got so many spam calls that we just, after I think of two months, we just disconnected it. So.
C
Yeah, I wonder, can you port a number to this one of these services? Cause if you could port A number to one of these services.
A
You're like, I'm doing it.
C
I'm doing it.
A
I have no idea. I have absolutely no idea. I've never tried that.
B
So it's another thing for Joe to report back on. He's got Japanese metal music.
C
I will listen to that. I doubt I actually do anything with this because this sounds great, but it also sounds like a lot of research and work, and I just don't have time for that.
A
Yeah, no, no, it's. But I. I just think it's. I've seen this for a few different things, like GPS watches for. So to keep an eye on where your kids are so they don't get lost. Same thing. People are saying maybe Gam Gam could use that.
C
That's. That's really the actual valuable use case. Right?
B
No, no, I. Yeah, no, I had a. What's the. What's Apple tag thing?
C
Little GPS air tags.
B
I had an air tag on my father's keychain because he kept losing his keys, you know?
A
Yep.
C
Right.
B
It was great.
C
My son has that. Has a tile on his keychain because he keeps losing his key.
B
Same thing.
A
Yeah, Same for me.
C
Right. I don't think that's age related, though. I think that's.
B
No, no, some people. Yeah.
C
Yeah, you do.
B
Yeah. Well, money well spent. All right, we will have a link to Maria's story in the show notes. And of course, we would love to hear from you. If there's something you'd us to consider for the show, please do email us. It's hackinghumans2k.com. All right, Joe, Maria, it is time for our catch of the day.
C
Dave, our catch of the day comes from the scambait subreddit R. Scambait. And the title of this one is Polish Frank Part one. And this is like a bait in progress. So it's not gonna go to finishing. I've started reading this and I have no idea what's going on here.
A
It's really, really long. I feel like we should just. On the production side, it is very, very long.
B
Yeah. I have a feeling we will know when to stop.
C
Okay.
A
Okay.
B
Having read through this and the clue is in the title.
A
Oh, boy.
B
Maria.
A
Yep.
B
All right.
A
Jesus Christ.
B
So I will be the instigator. Maria, you're in light blue.
A
Great.
B
Here we go. It says, hello, you pump in my wall. And I decided to write to you. Do we know each other?
A
I do not know what that means. What wall?
B
I mean you. I find you in my telegram And I thought I should message you. Do we know each other? I'm Frank by name.
A
Frank by name, Frank by nature. I don't know why you found me there. I don't recall talking to you. What does it say my name is?
B
Well, I'm just seeing skyline Pigeon. Can I have a photo of you? Or I should see you my photo to see if you know me.
A
I. No, I've never seen you. That I recall. Where do you live?
B
Are you sure? Well, I'm from Lublin, Poland. What about you? Can I have a photo of you? Do you play Bingo Frenzy?
A
I don't send pictures when I don't really know someone yet. My name is Linda and I live in Chicago. I might have played that game in the past. Do people talk on there?
B
Yes, people talk on there. I play that once in a while, whenever I'm less busy with work. You mean you have never played that game? Your picture is just for my eyes only. Maybe I can recognize you with you.
C
Never, never believe someone who tells you that.
A
If you don't know me by name and location, then my picture will not help you. Maybe if you tell me what you do for a living, it would help. I'm retired.
B
Oh, I see. I work as a timber contractor. And that's what my late father was doing before he pass on. I had to take over from you. What was your prefession before you get retired?
A
I was a doctor at Northwestern Hospital here in Chicago.
B
Wow, that's very lovely to hear. I have been to North Carolina once and I stay for seven months. Nice to meet you.
A
Okay, but that has nothing to do with Chicago. It's in Illinois. So what kind of forestry? I know I'm mispronounc that so. What kind of forestry happens in Poland?
B
I don't know more about the United States. In Poland, forestry mostly involved logging, replanting trees and maintaining natural areas. Poland has a lot of pine and mixed forests. Have you ever visited any large forests or nature parks before?
A
Sure. I've been all over the United States and I've seen many forests, especially in Northern California. I'm sure they're beautiful there in Poland. May I ask how old you are, Frank?
B
Of course. They are beautiful here in Poland. I will be 62 years old February 28th. And you? I still insist a photo from you. You seem very intelligent.
A
I'm 70 myself.
B
I've never been to Poland, not even any Europe countries.
A
I've been to the Canary island, which is close to Spain and off the coast of Africa. But that's It. I'll try to find a photo, but I don't have too many. Give me time.
B
Okay. Once again, nice to meet you. Like I said, can we be friends?
A
I guess it depends on whether the
C
first grader asks you.
A
You can be friends. I guess it depends on whether we find any mutual interests to talk about. What kind of things are you interested in?
B
I'm honestly not too interested in politics. I prefer more peaceful and personal conversations. But I don't keep friends due to what has happened to me in the past.
A
Oh, no.
B
I enjoy talking about life, nature, family, faith and meaningful experiences and getting to know someone personally. I also enjoy simple moments like coffee. What kind of things do you enjoy talking about most?
C
All right, stop right here. There is a hook in here that is. I think it's pretty obvious, but you know, I don't keep friends due to what has happened in the past. And he goes on to describe a bunch of other stuff and what you're supposed to do is go, what's happened in the past?
B
Yeah.
C
And he's supposed to have this sob story that gets you emotionally involved with him.
A
I'm dying to know what happened to him in the past. I mean.
C
Okay, yeah, yeah. But don't, don't. I don't think this person's going to engage with that.
A
Yeah, well, I'm Linda again and I like nature and I'm pretty familiar with wildlife and various plants and love bird watching. I'm not religious at all, so I can't relate to that stuff. I like to talk about books and.
B
What's that?
A
Oh, and world history too. Sorry, the thing's in the way. Do you have a big family?
B
I'm the only child of my late parents. My dad have a brother but I know where he's. Because he's a drug trafficking and also a drug addict. I don't know where he's with his family right now. My dad was a timber contractor. Like I told you before. He was hit in the bush.
A
No.
B
While he was cutting down timbers, my mom had an heart attack. When she heard the news, she was revived but died three years after my father death. Talking about this was make me feel sad. And talking books and world history, I don't do any of that. Lol. So I guess I'm too old for that. What about you? How many brothers and sisters do you have? How biggs is your family?
C
So he went ahead and gave you a whole sob story anyway.
B
Yeah, yeah, yeah.
A
Wow.
B
Cut it there. Yeah.
A
I was taken on a journey. I'm in I mean, no, I shouldn't be, but I'm totally in.
B
I'm. You're intrigued, right?
A
I mean, you know, he was hit in the bush.
B
He was hit in the bush. Which, for a second I thought maybe we were in Australia.
C
Right.
B
But maybe something else.
C
Right.
B
Yeah.
A
Yep.
B
All right, well, what do we. Obviously what's going on here is just your standard romance scam or getting to know you scam or cryptocurrency scam. Stage one of some kind of scam. And I think our hero in this story was doing a good job of stringing this person along and wasting their time.
C
I would have kept it.
A
Yeah. General question for us as we've read through a bunch of these in the past couple of months, are a lot of these coming from online mobile games? With the chats and mobile games, are we noticing a subtext there? Because, yeah, some of them have been from, like, Scrabble, and this one seems to have a reference to a game as well.
B
Right. That's a great point, Maria. It seems as though some of them are using the online game as the other place. Right, Right. So instead of trying to get you to go to Instagram, I'm gonna try to get you to go to Candy Crush or whatever, some game that has a chat function. Because chances are that chat function isn't going to be scrutinized.
C
Right.
A
Monitored and probably used by lonely or older people in some cases, maybe.
B
I mean, it could be as simple as, hey, go meet me at this game. And it costs five bucks to buy the game.
C
Right.
B
But I suspect it's more sophisticated than that.
C
Yeah, I would imagine as well.
B
Longer thing than that. All right, well, we will have a link to that Catch of the Day in the show notes. And once again, please send us your submissions for Catch of the Day. We always enjoy reading them. Our email is hackinghumans2k.com. Most environments trust too much and attackers know it. Threatlocker enforces default deny at execution, blocks unknown apps and limits what trusted apps can do. Stop ransomware at the source. Get your demo@threatlocker.com N2K. And that is hacking humans brought to you by N2K Cyberwire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to hackinghumans2k.com. This episode is produced by Lynn Liz Stokes. Our executive producer is Jennifer Ibin. We're mixed by Elliot Peltzman and Trey Hester. Peter Kilpe is our publisher. I'm Dave Bittner.
C
I'm Joe Kerrigan.
A
And I'm Maria Vermazes.
B
Thanks for listening.
This week’s Hacking Humans episode delves into the constantly evolving tactics of deception, influence, and social engineering prevalent in today’s cybercrime landscape. Hosted by Dave Bittner and Joe Kerrigan, with guest Maria Varmazis, the discussion explores how attackers exploit both technological vulnerabilities (like compromised IoT and residential devices) and human psychology (via phishing and social engineering). Special focus is given to recent headlines, real-world scam examples, and a thought-provoking opinion on the possible future role of AI in ending (or at least mitigating) social engineering.
[00:44 – 03:21]
"I had a really hard time with the vocalist like that. He's just—he's known for his style. It's just very distinctive." — Maria [03:00]
This section highlights the trio’s camaraderie and recurring musical in-jokes before pivoting to the serious topic of cyber threats.
[04:31 – 17:11]
"You can just think of [an IP address] as the phone number for your house on the Internet." [05:46]
"They're using a legitimate service as a smokescreen... also presumably from Russia. That's very interesting." [08:52]
"From the very get go, these things have always seemed sketchy to me." [10:03]
"If you’re not keeping its firmware up to date, which nobody does, then maybe every five years, just go buy a new one." — Dave [14:23]
[17:13 – 23:20]
"You're not getting an emergency response from me via email, no matter what." [18:06]
"It was exactly that... Text message from someone I knew. And it said like, 'Hey Dave, did you see this video?'... And anyway, they pwned me. We all learned a valuable lesson." [21:40]
[24:56 – 36:41]
"Who are we going to trust to look over our shoulder when all this stuff is happening?" — Dave [27:46] "I tend to...think back of my parents and how helpful it would have been to have some kind of full time assistant...watching their back. I love the idea of that." — Dave [30:26]
"Wouldn’t it be nice to just have a sense of your friendly neighborhood nerd just keeping an eye out for you at all times?" — Maria [32:24]
[37:09 – 44:39]
"There's a hook in here... what you're supposed to do is go, 'what's happened in the past?' and he's supposed to have this sob story that gets you emotionally involved." [41:19]
The episode is rich with banter—alternately playful, skeptical, and warmly pragmatic. The team navigates technical and behavioral facets of cybercrime with a blend of expertise, humor, and empathy, especially when discussing protections for less tech-savvy loved ones.
For links to the stories discussed, practical advice, and to submit your own tales of scam attempts, visit the show notes or email hackinghumans@n2k.com.