Transcript
A (0:00)
Foreign.
B (0:04)
This is Tom Yuan. I'm here with another between two nerds discussion with Gruk. G', day, Grok. How are you?
A (0:10)
G', day, Tom. Fine, and yourself?
B (0:12)
I'm well. This week's edition is brought to you by Nebulock. I had a discussion with Nebulox CEO and founder Damien Luke out on the podcast channel where we talked about how threat actors are using AI and how Damien is using AI to counter that. So you sent me this tweet. Scattered Spider's latest tactics. Insider recruitment for network access.
A (0:36)
Not sure that's the latest tactic, because I remember Lapsus was doing that years ago.
B (0:41)
So there's this kind of a bit of a words Alad. Scattered Spider has shifted from chaotic data leaks to a more organized cybercrime model, now actively recruiting insiders for initial network access. So it's got some.
A (0:56)
I think that that's. I don't know. It's like. It hurts my head to try and untangle what they're attempting to say.
B (1:04)
So they've got this key development section in the tweet, Insider outreach, offering staff up to 25% revenue for AD access and 10% for Okta Azure AWS root credentials.
A (1:21)
Like, there's a premium for Microsoft skills, I guess.
B (1:27)
Is it a premium for Microsoft skills? Or that if you get ad access, like, that's three quarters of the job done.
A (1:34)
That's the entire job done. This.
B (1:39)
So I think this comes from telegram channels. And one of the parts in there is we are not looking for data. We have it all already. We are looking for the employee to provide us a VPN or Citrix to the network or some kind of data access, basically, like access to the network.
A (2:00)
Are there a lot of, like, help desk people just hanging out on these telegram channels, shooting the. And then it doesn't seem like a good place to advertise right there. Yeah.
B (2:10)
My interpretation was it was outreach to the community, whatever community. That telegram channel is saying, we're looking for these people. Do you know these people?
