Loading summary
A
Hello everyone, this is Tom Uren. I'm here with another between two nerds discussion with the Gruk. G' day, Gruk, how are you?
B
G' day, Tom. I'm fine. And yourself?
A
I'm good. This week's edition is brought to you by Authentic, the open source identity provider. I have a chat with Authentic CEO Fletcher Heisler, all about the reasons why you might consider using different identity provider out on the podcast channel this week. So, Gruk, there have been a lot of military action between Iran and Israel. It's kicked off recently and there's been some. Well, I think they're pretty significant cyber actions that have been carried out.
B
I beg to differ, sir. Okay.
A
But yeah, that have been carried out by a purported hacktivist group called Predatory Sparrow, or Gonz in Persian, don't know how to pronounce that. Everyone thinks, or at least I think, that Predatory Sparrow is Israeli military intelligence or they're cyber espionage operators. So it's conducted a number of operations that have targeted Iran over, I think almost a decade now under various guises. It seems like there's a, a history and it, it pretends to be a hacktivist group. So way back in BTN number two, we spoke about Predatory Sparrow and they're interesting, or they were interesting at the time because they took a lot of steps to try and demonstrate that they were conducting responsible cyber operations. So they were doing things like minimizing.
B
Collateral damage and demonstrating it as well, Right? Yeah, they would.
A
When they disrupted Iran's fuel subsidy system, they warned emergency services beforehand. They tried to avoid actually harming people in some pretty steel plans. Spectacular. Some pretty spectacular steel furnace attacks with molten steel flowing all over the place. Now, they've claimed responsibility for two pretty significant hacks on the Iranian financial system. One, they said they deleted data from bank sepa, which is one of Iran's. It is Iran's oldest bank. When I looked the latest data I could find, said it was the fifth largest back in 2008. I don't know how significant.
B
Nowadays it's significant less for the size overall. As for the ties to the regime and the way it's been used politically, I think it's like it's much more of a legitimate target than it is necessarily the most useful banking target.
A
Yeah. So we've got. It appears slightly different views on that. So we'll talk about that. There's also an attack on a cryptocurrency exchange and there's a third potential attack that kind of could be Predatory Sparrow, but they've not claimed responsibility. So we'll talk about that as well.
B
And there's even, there's even a legitimate reason why they might not claim responsibility.
A
Yeah, but we'll explore that. So, yeah, let's start with bank sepa, if that's how you pronounce it.
B
And yeah, it's pronounced fish.
A
They've claimed responsibility. So a UK based newspaper that covers Iran reported on all sorts of disruption. So, you know, people can't get money out, ATMs don't work, you can't buy Internet, like top up your Internet. Bank systems are crashing. Now Patrick and I spoke about this and my feeling was that it's potentially very significant because the reason people worry about banking attacks. Yeah. And you've got a different view, is that it's a system. Right. And so like the 2008 financial crisis, it wasn't all banks everywhere having a problem, it was contagion caused by the collapse of a particular bank. And was that the same in 2016? A couple of times. It's a particular bank that has a problem and that spreads things clog up. It gets very difficult to get anything done. Policymakers run around panicking, huge amounts of money get spent. Now this is occurring in Iran where there's also missiles flying and blowing things up. People are leaving Tehran. Now there was a Wall Street Journal report that had some speculation about the timing. Is that right? I haven't read that one.
B
Yes. Yeah. So there's this WSJ article. Basically they point out that in Iran wages are paid on the 22nd and so there was speculation that by attacking prior to the 22nd it would disrupt people's wage payments. Essentially. I find that very thin. Basically, if you're going to disrupt payment on the 22nd, why would you attack five days early and give, you know, five days of potential recovery time? That doesn't make sense to me. You could attack on the 20th. I think that the, the timing there doesn't support it. And also I think that culturally the Iranians are used to delays in being paid their wages. So it doesn't have any sort of salience or resonance of like, oh no, now we're not getting paid, let's go to the streets.
A
I think it could potentially be significant. Predatory Sparrow has in the past demonstrated that they've understood a system really well and I guess calibrated what they do to what they want to achieve. So it seems to me at least plausible that they could have done things like totally destroy the bank, like delete backups, in which case the Timing, you know, five days, two days, doesn't matter.
B
I just. I feel like this is the least imaginative, least creative attack so far, you know, except for the. The other one that they've also done in this war.
A
Right. So I guess going back, it's very.
B
Much the, like, you know, here we are going after this steel plant. We're going to attack the CCTV and we're going to make sure that we can, like, create a video showing that we're doing this responsibly and no one's getting harmed. Like, that's interesting. Here we are going after the banks during wartime and we've. We've interrupted the banking system. Like, that's. I mean, that's so pedestrian.
A
I mean, they are, from their point of view, they're in.
B
Feel cool in the same way, but.
A
I don't think that that's in one of their, like, you know, key indentions.
B
I'm sure, I'm sure it is. I'm sure it's their top things. They're sitting there and they're like, no, it needs more pizzazz. Like, well, I think they're tearing up things going, this is. This is like, it's not creative enough. It doesn't, it doesn't inspire, you know.
A
Well, I mean, so some of them won't like it.
B
I think that that's probably one of their checklist items.
A
Well, some of the attacks that they've done, they've disrupted Iranian train systems and they had the Ayatollah's phone number, office number, as a place to call if you want to complain. Displayed on, like, terminal systems in train stations. And for the fuel subsidy attacks, they did the same things the bowsers would display. Khomeini's office.
B
You have an issue.
A
Yeah, yeah, yeah. And so in that sense, I think you were right that part of the point was to get publicity. But I think when you're in an actual shooting war where missiles are being lobbed back and forth like that, there's.
B
No time to, you know, give up on doing cool stuff just because.
A
But I think to me, that makes sense that you would drop that as a priority because just there's bigger things going on. You're not going to cut through by having the phone number on, I don't know, ATM machine or something.
B
It's just, it's. It's so uninspiring as an attack vector. Like, I, I'd expect something more interesting where they'd say, make the ATMs outside of Tehran start spitting money so that people Be inspired to leave even if you did that to the ATMs inside Tehran. Like that seems like it would be more consequential to the bank is if cash was physically removed from their ATMs. That would be a thing that impacts them and it would be good for the people because they would have money.
A
Yeah. I actually like, prefer that as an attack. It would still have serious consequences for the system, but I think it feels like there's less collateral damage.
B
Nice, right? It's a nice attack. That's the sort of thing I prefer. Right. It's. You don't have to be mean about it. You can find a way of doing clever things. If you wanted to be particularly clever about it. You could probably target ATMs and areas away from regime targets and that would encourage people to not be around when you're bombing things like factories that have missile components or whatever. It would be a way of incentivizing people to get away from areas of interest. That seems like a more exciting attack than to just wipe things. Like wiping things is what Russians do. It's just. It lacks subtlety and cleverness.
A
Yeah. I was looking at the history of bank attacks and it seems like the Russians tried several wiper attacks, and as far as I can tell, they didn't seem to amount to anything. There was no reporting of the subsequent disruption or anything like that. So this seems significant in that it was a wiper attack that actually worked. Seems to have worked, yeah.
B
I think that they probably put more. They had more time to prepare. I don't think the Russians have had months or even years possibly of working to understand the system, to figure out what they're going to need to do to develop the malware, to do the sort of attack which is going to absolutely guarantee that you're wiping out things that will impact, you know, the ATMs and the online banking and the. All of this other stuff. Like, it's. Yeah, I don't think they started last.
A
Week, you know, the bank of Bangladesh, which was hacked by North Korea. I think the reporting said that they were in there for maybe 18 months or something like that. It was quite a long time, more.
B
Than a year, and they still screwed it up. So.
A
Yeah, that's right. Attention to detail, people. And so I would expect that the timeline for this is as long as. Or longer.
B
Longer, yeah, sure.
A
I think the bank seems like it was a legitimate target in terms of understanding money flows.
B
It's right. It would have. It would have been an intelligence target.
A
Yes.
B
For who knows how long. I mean, decades maybe. Right.
A
I think it was sanctioned. The name, the number 2007 or 2008 seems to.
B
Right.
A
I mean, that's at one point.
B
So I think they've been hacked since they've been online.
A
Yes. It seems to me that the Israeli group is competent enough that they could have calibrated whatever they wanted to do.
B
Yes. Yeah, I think it was very precise. They weren't just flipping a bunch of switches and going like, this is going to probably take down the whole system, I'm guessing. Right. You know, they knew exactly which systems had to be wiped in which order and so on. So, yeah.
A
So my concern would be they went all out and wiped it out totally. I can see that there's probably a lot of different levels where they could have wiped out particular things or left enough backups to restore or something. Anyway, we don't know exactly what's happened now. Even in that. Worst case, you're disappointed in this attack because of.
B
Yeah, but what about the impact, though, Just briefly. I think what have been more interesting, at least to me, would be a targeted wiping. Right. If they'd chosen, for example, if they had erased all of the debt that the bank holds, so if they've had access for years, if they'd spent that time interfering with the backups so that the backups would be unreliable and couldn't be used to restore certain critical information, and then they wiped out all of the debt that the bank holds, I think that that would cause the bank to collapse because that's the bank's money that's gone. You leave everything else, like all the customer accounts can still be used. All the commercial banking that they do would be left alone, but they no longer hold any debt. They have no idea who owes them money. They don't know any of that stuff, I think that would be a massive disruption and it would cause the bank to collapse. And I think that would be an interesting attack.
A
Right, right. I actually think that if you're in control, you would just recapitalize the bank, which would be probably very painful for the government. But in terms of you can't let it collapse. I guess given that there's essentially a war going on, at the same time it becomes quite difficult to organize things.
B
I don't think people are going to be that bothered. And I think part of the reason for that is because. Because there's a war on. The priority that a lot of people have is getting out of Tehran, saving themselves and their families, sort of, you know, the whole, like, they will be upset because their wages aren't paid. That strikes me as on Maslow's hierarchy of needs, that's not quite at the, you know, water and food level.
A
But I mean, if they can't get their money out, that is sort of only one step away from the water and food thing. Right?
B
Sure. But again, this is like, it wouldn't be the first time that this has been delayed. Like, it's not pleasant. But my understanding is that there's sort of systems in place that they're used to. Like, okay, well, when we don't have money, here's how we still survive without it. You know, like, there's ways and means around it and then there's a sort of rally around the flag effect that happens when people get bombed. And so I think that attacking the bank, making the bank not work, probably it's going to raise support for the regime and harden feelings against the enemy who's now interfered with the ability to get money. Right. Like, I don't think people are going to blame the ayatollahs for the fact that they can't get cash. They're going to blame the people dropping missiles on them. It doesn't seem to have any of the psychological effects that some people are attributing to it.
A
Right. Yeah. So that to me seems an argument in terms of doing something very precisely calibrated that doesn't disrupt the operation of the bank, but just disrupts like, I don't know, change the IRGC accounts to 0 or negative.
B
I mean, even better, just change them to like 20 billion huge amounts of money that they can then spend that doesn't exist, cause runaway rampant inflation. On the other hand, it is fair to say that wiping is a very immediate attack, which during a wartime, you probably want, whereas attacks that take a lot longer to have an actual impact are probably less interesting or less useful. Like, if it's going to be, here's a thing we could do today that's going to pay off in six months.
A
Yeah.
B
Like, I don't think that's going to be greenlit in the same way as, you know, here's the thing we can do today that will pay off today.
A
Right. Okay. So there's another attack they claimed responsibility for on an Iranian cryptocurrency exchange called Nobitex. Nobitex. And again, the justification was the same.
B
Yeah, sanctions busting and.
A
Sanctions busting. Yep. And you know, you're supporting the regime, you're actually telling people how to avoid sanctions and get around them. And this is what Happens if you do that. And so they look, to be fair.
B
It just means that the, the Israelis got there before the North Koreans. It was a race.
A
And they took, at this point, over $90 million worth of cryptocurrency and sent it to burner addresses, addresses no one controls. And the addresses contain fu, irgc, terrorists, novatex in the address. So over half a dozen different cryptocurrencies. So they're clearly sending a message, we don't like what you're doing and you're never getting your money back, ever.
B
That's the same combination as my luggage.
A
OPSEC fail.
B
Yeah.
A
So again, it seems like you could calibrate exactly what you're doing to particular accounts if you wanted to. I don't know what they did. The exchange themselves has acknowledged that they've been hacked. If you read their messages, they're less negative about the whole incident.
B
Like, it strongly suggests that they're not actually hacktivists, that they're. Right. Like, if you were a hacktivist turning down $90 million for, you know, an ideological position, that's. That's quite hard to do, I think.
A
Yeah. So I think this raises the question to me of why bother? Like I said before that everyone believes that they're part of the Israeli ministry. Why have this hacker Persona, like, what's the permit?
B
Yeah, like, what do you accomplish? I don't have a good answer. One thing that occurs to me is it provides enough plausible deniability that Iranians can support the actions, which they wouldn't be able to do if it was directly claimed by the Israelis. Like if Mossad or the IDF issued a statement saying, you know, we have done this attack, there's no way anyone could support it. Whereas by having an attribution front, people could say, well, yeah, okay, there's speculation that it's Israel, but still, they're doing good things.
A
Yeah, yeah. In one of the attacks, the bank attack, it tweeted, posted on X, that thank you for the brave Iranians who helped us in this attack. And it posts in Farsi and English, so it's not posting in Hebrew, for example.
B
Right. To me, it seems that if there, if there is a reason, it's simply to avoid the taint of Israel just enough that people can get behind it. Right. It's a sort of face saving thing. Like it's not meant to be rock solid in any way. It's just meant to be sufficiently reliable that if someone wants to believe, they can convince themselves that, you know, and to me, that seems that does seem useful from, from an opsec perspective, if you start out with a Persona, if you decide to drop the Persona in the future, that's fine. But if you start out without a Persona, you can't sort of retroactively add one back in. Right.
A
Like it's too late, you can't take it back.
B
Right. So I think it sort of future proofs in a way, like it means that it gives them some options of what to do. They can choose to reveal or not when it becomes worthwhile.
A
So that brings us to the third potential attack, which is it's definitely an attack. Whether it was Predatory Sparrow is an open question at this point. They've not claimed responsibility, but Iranian TV was hacked, air quotes and played messages calling for regime change.
B
I'd point out that this mirrors the sort of. There's a lot of tit for tat TV hacking in the Russia, Ukraine cyber war. I think I documented like eight incidences, sort of four on each side. And generally speaking, they seem to me to have been done, barring one exception, they seem to have been done by actual activists. And that it was a very. It'd be like the Crimea, local public access TV was hacked. You know, not major stuff. It was always these little out of the way things. And then the content that was played was not custom developed. It was sort of just. We were going to play a bunch of Zelensky clips off of Facebook or here's a PowerPoint presentation that we put together. It wasn't like, it wasn't slick and it didn't have a feel of like an actual production that created a TV program to be injected. It was just a very amateurish. And I. This didn't seem that. It seems a little bit more polished at least.
A
Right, right. So one of the previous hacks, it broke into a notorious Iranian prison and it captured CCTV footage and it displayed that footage while I think it cut it together with vision of the security room in this prison as the screens were gradually changed to display the hacker symbol so that you could see the security personnel reacting to the gradual cinematic. Exactly like you would do it in a movie.
B
Yeah.
A
And so the orchestration and the planning and the production value was very high. Now, this TV footage, what I've seen is a video of a TV playing Iranian TV and it was satellite tv. So my understanding is that the bar to hijack satellite TV is not necessarily very high.
B
Right.
A
So in that sense it could be anyone. However, some of the recent hacks, Predatory Sparrow has put out short videos and they've used this quite distinctive red, fuzzy text and some of that appears in this video, but that's hardly a strong indicator.
B
Yeah, red text, that must be Israel.
A
And it could easily be, oh, we've seen this hacker group use this color text. So we'll use the same text, right?
B
Yeah, absolutely. I don't think that they have a trademark on red Farsi text and I don't think that they're enforcing it strong. So I'll say a couple of things on this one, is that it's a little bit more in line with the sort of strategic aim of things they've done in the past, which is to sort of foment resentment against the regime. So this is very directed along the same strategic lines as some of their previous attacks where they've, you know, when they went after the trains and they said, call the ayatollah to complain, and they went after the fuel and it was all timed and it, you know, call the ayatollah to come. These are very specifically anti regime things. And this seems in the same vein, which, to be fair, anti regime is. Again, it's sort of the red text. Yeah, it's not necessarily exclusive, but I think the other thing is it's a little bit the appeal to the people as opposed to destroying a bank. Destroying a bank, while in line with some of the other things they've done, like destroying the steel or going after the prison where they're directly attacking pillars of regime support, they've also tended to try and couple that with this sort of emotional, psychological angle as well, which they didn't seem to do at the bank. So maybe this is making up for it. Right. They're like 100% psychological and 100% destructive. So it's sort of combining them. You've got a nice mix of both. It feels a little bit more predatory sparrows in that it's in line with what they would do, but it's not as impressive technically as their other stuff. It sort of. It lacks that wow factor.
A
Speaking of the bank, there was a ransomware attack on it a month or two ago and there were people drawing a link between this and. I think the group was called Code breakers. And it's an attractive idea in that they published documents. I think it was a data extortion attack. But to me it seems like if you're Israel and you're preparing for the potential of a military conflict, you would just hold your fire and not.
B
Yeah, I don't think you'd show your hand. Exactly.
A
Yeah, it's Just, it's an opportunity to get caught.
B
Right. You do something silly that has no strategic impact and potentially destroys a future operation. Yeah, it doesn't make sense. It's probably very frustrating when that happened actually.
A
Predatory sparrows sitting there going, no, yeah.
B
Well that's the thing. Now code breakers is going to have Mossad after them. Like, okay, so the, like the TV thing, I think that's up in the air. It could be anyone. It doesn't have the flavor of the predatory sparrows. It does fall in line with their sort of ideological and strategic objectives. But they've also, they've been quick to claim credit. I think that that's been a big part of their thing. So the fact that they haven't, I.
A
Mean the whole history of predatory sparrow, it seems to be that they push the boundaries of what is an air quotes acceptable cyber attack and then they publish material that goes, look, look, we're actually being quite responsible, we're being very careful. And so yeah, the TV hack doesn't fall into that category of. Right, it's a TV hack, it's not a big deal, you don't need to justify.
B
Yeah, I mean again, there's been so many of them and it's, it doesn't, I don't think that there's any academic literature discussing, you know, what would happen if the TVs got hacked.
A
Whereas the systemic risk of TVs being hacked.
B
Yeah. Whereas the foundation of our financial system, you know, what if that gets hacked or what if industrial systems that are now controlled by computers, if those get hacked and get taken over remotely, that's the sort of thing that worries people or our transportation infrastructure. So yeah, like the predatory sparrows have sort of always been at the cutting edge of what's sort of acceptable. But always, as you said, like it's sort of couch presented in this way of like here's how we did this cutting edge thing in a very responsible way. Like here's how we've pushed the boundaries of what can be done while also minimizing the harm and the impact outside of specific targeting. The TV hack doesn't seem like that. It seems maybe even opportunistic, the sort of thing that any hacktivist could do. So I'm going to say that there's two solid predatory sparrows attacks. I wouldn't rule out there being future ones, but they're probably not going to be the same caliber of creative and cool that we saw pre war. It's going to be more of these sort of very practical, straightforward pedestrian boring like these are beige. Any cyber attack that can be thought of and written about in the academic literature is probably not an exciting cyber attack. That's my right. That's my position.
A
Yeah. So I guess we're both wishing for an end to the war and more exciting cyber attacks.
B
Let's stop the war and go back to the cool hacks.
A
Yep. Thanks a lot, Craig.
B
Thanks a lot, Tom.
Podcast Summary: Risky Bulletin - Episode "Between Two Nerds: The Evil Genius of Predatory Sparrow"
Release Date: June 23, 2025
Host: Tom Uren
Guest: Craig
In this episode of Risky Bulletin, host Tom Uren engages in a deep dive into the cyber operations attributed to the enigmatic hacktivist group known as Predatory Sparrow. Joined by Craig, the discussion explores the multifaceted nature of Predatory Sparrow's attacks against Iran, analyzing their strategies, effectiveness, and the implications of their actions within the broader context of cybersecurity and geopolitical tensions.
Predatory Sparrow, often speculated to be an arm of Israeli military intelligence, has been a persistent threat targeting Iranian infrastructure for nearly a decade. The group masquerades as hacktivists, executing cyber operations under various guises to destabilize Iranian systems while maintaining a facade of responsible cyber conduct.
Tom Uren opens the discussion by highlighting the group's longstanding activities:
"[...] Predatory Sparrow is Israeli military intelligence or they're cyber espionage operators."
[00:11]
Predatory Sparrow made headlines by disrupting Iran's fuel subsidy system, a critical component of the nation's economy. The group took measures to minimize collateral damage by warning emergency services in advance, showcasing a semblance of responsible cyber warfare.
Craig critiques the impact of this attack:
"It's just so uninspiring as an attack vector. [...] it lacks subtlety and cleverness."
[08:43]
One of the most significant operations attributed to Predatory Sparrow involved deleting data from Bank Sepa, Iran's oldest bank. This attack led to widespread disruptions:
"People can't get money out, ATMs don't work, you can't buy Internet, like top up your Internet. Bank systems are crashing."
[03:20]
Tom emphasizes the potential severity:
"The Russian wiper attacks ... didn't seem to amount to anything. This seems significant in that it was a wiper attack that actually worked."
[09:33]
However, Craig offers a contrasting perspective, downplaying its immediate impact:
"It's a system. [...] it's a particular bank that has a problem and it spreads things."
[04:44]
Another notable attack involved Nobitex, a major Iranian cryptocurrency exchange. Predatory Sparrow siphoned off over $90 million worth of cryptocurrency, sending funds to burner addresses containing provocative terms like "fu, IRGC, terrorists, nobitex."
Tom points out the operational security lapse:
"That's the same combination as my luggage."
[16:54]
Craig analyzes the group's motivations:
"It just means that the Israelis got there before the North Koreans. It was a race."
[16:17]
The latest suspected attack targets Iranian television broadcasts, where hackers overlaid messages calling for regime change. Unlike previous sophisticated attacks, this incident appears more amateurish, raising questions about its origin and affiliation.
Craig compares it to similar attacks in other conflicts:
"[...] there's a lot of tit for tat TV hacking in the Russia, Ukraine cyber war."
[20:11]
Tom counters the sophistication:
"It was very high [in orchestration and planning]. The TV footage is just satellite TV; it could be anyone."
[21:56]
Throughout the episode, Tom and Craig dissect the strategic intentions behind Predatory Sparrow's operations. A recurring theme is the balance between destructive capabilities and psychological impact. While attacks like the steel furnace disruptions demonstrate high operational prowess with minimal human harm, others like the Bank Sepa wipe appear more straightforward and less creatively executed.
Craig muses on the group's creativity:
"It's so uninspiring as an attack vector. [...] it lacks subtlety and cleverness."
[08:43]
Conversely, Tom acknowledges the potential precision:
"They could have calibrated what they're doing to particular accounts if you wanted to."
[11:24]
The conversation also touches upon the motivations for maintaining a hacktivist persona:
"It provides enough plausible deniability that Iranians can support the actions."
[17:37]
The duo draws parallels between Predatory Sparrow and other state-sponsored cyber operations, notably those conducted by Russia and North Korea. They highlight the differences in execution and effectiveness, with Predatory Sparrow seemingly more adept at executing impactful attacks:
Craig contrasts with Russian wiper attacks:
"The Russians tried several wiper attacks, and as far as I can tell, they didn't seem to amount to anything."
[09:33]
Tom underscores the group's dedication:
"Predatory Sparrow has in the past demonstrated that they've understood a system really well."
[06:08]
The discussion delves into the real-world implications of Predatory Sparrow's cyber operations. While some attacks cause immediate disruption, their overall strategic impact, especially during wartime, is debated.
Craig opines on the psychological effects:
"I think it's going to raise support for the regime and harden feelings against the enemy."
[13:48]
Tom reflects on the group's strategic calibration:
"They were dropping phone numbers on ATMs because bigger things are going on."
[07:59]
The consensus suggests that while Predatory Sparrow's actions are disruptive, their long-term effectiveness in achieving strategic objectives remains uncertain.
In "Between Two Nerds: The Evil Genius of Predatory Sparrow," Tom Uren and Craig offer a comprehensive examination of Predatory Sparrow's cyber operations against Iran. Through detailed analysis of specific attacks and strategic intentions, they illuminate the group's complex role in modern cyber warfare. The episode underscores the delicate balance between technological prowess and strategic impact, highlighting the evolving landscape of state-sponsored hacktivism.
As the discussion wraps up, both hosts express a desire for an end to ongoing conflicts, hoping for a return to more sophisticated and less destructive cyber engagements:
"Let's stop the war and go back to the cool hacks."
[28:24]
Notable Quotes:
Tom Uren: "Predatory Sparrow is Israeli military intelligence or they're cyber espionage operators."
[00:11]
Craig: "It's just so uninspiring as an attack vector. [...] it lacks subtlety and cleverness."
[08:43]
Tom Uren: "The Russians tried several wiper attacks, and as far as I can tell, they didn't seem to amount to anything. This seems significant in that it was a wiper attack that actually worked."
[09:33]
Craig: "It provides enough plausible deniability that Iranians can support the actions."
[17:37]
Tom Uren: "They could have calibrated what they're doing to particular accounts if you wanted to."
[11:24]
Craig: "Let's stop the war and go back to the cool hacks."
[28:24]
This episode of Risky Bulletin offers valuable insights into the shadowy realm of cyber warfare, exemplified by groups like Predatory Sparrow. For enthusiasts keen on understanding the intersection of cybersecurity and international conflict, this discussion provides a nuanced perspective on modern cyber threats.