Loading summary
A
Hey everyone and welcome along to Seriously Risky Biz. This is our podcast all about cybersecurity policy and intelligence. My name's Amberly Jack and very shortly I'll bring in our policy and intelligence editor, Tom Uren, who's been working away on the Seriously Risky Business newsletter, which you can read and subscribe to over at our website, Risky Biz. But first, I'd like to thank the William and Flora Hewlett foundation for supporting Tom's work here and also Lawfare, who syndicate his newsletter and publish it on on the law firm media website. And finally, we do have a corporate sponsor this week as well. So a big thank you to Dropzone. You can find them at dropzone D R O P Z O N E A I Tom, thank you for joining me. It's so good to see you.
B
G', day, Amberly. How are you?
A
Yeah, really good, thanks. And you've touched on a couple of reports in the newsletter this week. And the first one that I want to talk to you about is one that's been published by Dartmouths Institute for Security Technology and Society. And they've basically looked into how the US government should utilize the private sector to help with offensive cyber and boost its cyberspace dominance, which it seems that you've taken as kind of a fancy way of saying beating China.
B
Yeah. So the report is, I thought, interesting. What I like about these kinds of reports is this got a group of, I think, 30 experts, so people involved in different parts of what they call offensive cyber, and basically got them in a room and talked about the gaps and opportunities and they came up with a list of recommendations, they stepped through the gaps and opportunities. And I like these kind of reports because if you speak to a real in depth expert in something, you learn something if you ask the right questions. And so if you do that and you bring it together in a report, you can actually say stuff that is quite interesting and valuable. Now I thought the problem with this report in a way is that it assumes that we want to get to a certain place and that place is more private sector involvement in offensive cyber activities. And it defined offensive cyber very broadly as basically anything from tool development to getting access, to actually conducting operations for espionage, or even conducting operations for destructive or disruptive effects. But the starting point is yes, lawmakers want more operations, they want them faster and they want the proper private sector involved more. And I think it's correct to say that lawmakers want that, but it's very unclear exactly what they want. Like what are you hoping to achieve with that and it felt to me that the kind of vibe is it feels like China is winning because it does stuff like mass hacking of Microsoft Outlook Exchange, sorry, when there's a vulnerability and it does that over a week and they're winning. And it did that with SharePoint recently, for example. So it feels a bit like the Dr. Strangelove scene. We cannot allow a mineshaft gap.
A
But Tom, would the US government actually benefit from doing more of China style mass hacking like that?
B
Yeah, to me that's the missing piece. And so the report actually recognizes that. They say the US government needs to come up with a public offensive cyber strategy, like how do we use our private sector to do these things? And this made me think about how the Chinese system operates. And we know from various leaks the way it operates is it's a hack first sort things out data system. So they've got isoon data leaks, which was a cyber espionage contracting company. It was very clear that they were hacking and then they were trying to see does anyone want this information. And so when you've got that kind of system and you're got multiple different customers who might like all sorts of different types of information, you can just go hack a whole lot of things and maybe you'll find a customer that actually values that. So their whole. Not their whole, but a lot of their commercial sector is known to take hack materials to benefit their manufacturing, for example.
A
Yeah, right.
B
And that's just not something that happens in the us so their system is the exact opposite where the government is the customer. It comes up with very precise requirements for what it wants and then it tasks its intelligence community to go and find that intelligence. So it's a decide what you want, what's really valuable, and then you've got a single customer. Whereas the China is the opposite. Many customers, many intelligence requirements, hack first, figure it out later. And so it strikes me as really hard to figure out what you would do with a whole lot of more intelligence from China or from Russia or from wherever where it's not clear that the government cares. Like would you then have a marketplace for intelligence that just whoever could good buy in and get access? I think that's problematic. But one of the recommendations in the report is that the government start a pilot program and it authorize certain vetted private sector organizations to go after what it describes as low risk actors. And it picks out two in particular which are cryptocurrency scammers and ransomware operators. And to me that actually makes a lot of sense. There's Both, especially in the cryptocurrency space, there's a lot of scammers that are operating. It's hard to pick out a clear top scammer that you would sic, say Cyber Command or the FBI or whoever on that would make much of a difference. It's like an industry rather than a, it's an at scale industry rather than a, you know, a single key player.
A
Yeah, right.
B
And so that makes sense. If you want an at scale response, then perhaps the private sector is the place to get that. And you know, any one actor is not that important and so therefore doesn't deserve government attention. But when you add them all up, they can cause a lot of harm. So that makes sense to have a kind of distributed private sector response. And I think the same applies with ransomware. So I think we'll talk a bit more about that ecosystem later on today. But there's certain key, I guess, ransomware groups which have got a lot of market share, I guess like they, you know, they are responsible for a large percentage of the harm and it really makes sense for government operations to go after those groups. But then you've got this long tail and I think then it's the same as cryptocurrency scammers. You've got a lot of smaller actors. The government's never going to go after all of them. And so that seems like a space where the private sector could try and disrupt or somehow those groups, I don't know, dox them, hack their malware, whatever.
A
Yeah, for sure. And it sort of feels like they, you know, those, those annoying niggly crimey crypto groups and ransomware, that the private sector would not only have the capability but also kind of the will as well to go after them. I don't know.
B
Yeah, yeah. So another part of the report talks says that basically the private sector is helping in these activities already. Like the capacity exists. There's potentially a lot more that they could do. And so we're not starting from zero. It's more a case of letting them, giving them authorizations, giving them the legal authorities. It points out that there's already a large scam baiting community which will do things like hack scammers and hack their webcams. And it points out that the US legal system doesn't go after scam betas, even though some of those activities are technically illegal. So it feels like there's a, they're pushing on an open door in the sense that no one really worries if you hack a scammer, it would be just enabling them to go further, do more, hopefully do more good, prevent more harm, perhaps.
A
Yeah, for sure. The second report that you've touched on today is actually taking a bit of a look into how these smaller ransom groups and how quickly they. They are coming together. And this one kind of made me laugh because it is a report from Analyst 1's chief security strategist, John DiMaggio, and he had some really good and kind of laughable access to a ransomware operator. Devman, who seemed very happy to, on the one hand, admit that, yes, doing what he does is likely to lead to getting himself into trouble, and then, on the other hand, giving DiMaggio full access to his life story, pretty much. So tell me about this one, Tom.
B
Yeah, yeah. This felt very random in the sense that Dimegio, I've written about some of his reports before, and he, in those reports, got access to the Conti ransomware gang by setting up a fake Persona. I think he applied for a coding job despite not speaking any Russian. And after he was rejected, they just left him in the chat, and so he just sat there. In this case, however, Devman knows he's a security researcher. He knows that DiMaggio's writing down and documenting everything that's happening. And he's still, like. He talks to him. He'll. He'll ring him up. He'll talk about, you know, buying watches, luxury watches. This is, you know, what I do. He even shares passports that he's got. So, to me, the point is that there's actors in this ecosystem which will do illogical and things that don't make sense.
A
Yeah, I think just very quickly as well. Last week, you and I were kind of laughing about how, for me, as a journalist, being able to go undercover would be sort of chef's kiss. But I think I want to change that now and say having someone come to me and be more than willing to openly share all their crime secrets with me may be a little bit better.
B
I think. There's an interesting section where DiMaggio asks him, Devman. So I'll step back. So Devman, he starts off as an affiliate. He seems like he's an average, average Joe in the sense of competent but not exceptional. And he very quickly goes from being an affiliate for a couple of different ransomware gangs to, within six months, he set up his own ransomware as a service platform. And now it's never really clear what his motivation for this is. I don't know, maybe independence or something. He actually says, I'm stepping away from Crime. But it turns out he just means I'm setting up my own ransomware as a service platform. But the fact that someone who is not exceptional can do it so relatively quickly for reasons that are unclear, but just motivated by his. Like, he's a strange person, I think just indicates that the ransomware system will splinter as law enforcement pressure bites. And we've seen this in other reports, but this is like a very individual look, a very human story about someone doing this. So I find that really interesting. So he, I think one of the things he's after, it appears, is control. He's a bit of a control freak. So he sets out these codes of conduct. You know, you're not allowed to be unprofessional. It's like, you know, I'm sick of people being rude to each other, so I'm going to set up my own ransomware as a service platform where people will be nice. He even goes so far as to say that you've got to be professional with your victims. Like, they're trying to be professional. They're just trying to get through a business deal. If you are unprofessional, I'm going to take that negotiation away from you. So that's part of the code of conduct or terms of service of the ransomware platform.
A
It's always good to be nice when you're doing your ransomware.
B
Yeah, that is pretty much exactly what he says in the code of conduct. Now, at the same time, when it comes to targeting, he doesn't really care. Like, he's got limits against children and that's it. So it even says, you know, critical infrastructure can and should be targeted. It's not even can be targeted. It's, you should go do this. And there's a part which is, you know, if you've got a moral problem, well, you could do data extortion as well, but it feels like if you've got a moral problem, you shouldn't have a moral problem. Come on. So altogether, it's like this person, for reasons totally of his own, has decided to do this. Like, to me, it just reinforced that the ransomware ecosystem is going to splinter because you'll have all sorts of people who have their own individual reasons for doing things that do and do not make sense, regardless of what Western law enforcement is doing.
A
Yeah, I like the little bit about the. His explaining his sort of moral reasoning behind why targeting hospitals was a good idea as well.
B
Yeah, yeah. So he's perfectly fine with targeting hospitals. And I guess the benefit of dimaggio being openly a security researcher is he can just ask him directly, like, why are you allowing this? I think this is bad. And he basically says that in a previous negotiation, he sat in a negotiation that the Conti Ransomware group did with a hospital and the hospital was talking to its insurance company, but it didn't mute the conversation with Conti Ransomware. And so Devman was able to overhear the hospital talking to the insurance company. And he said they were talking about the ransom in terms of weighing up how much it would cost to pay versus the payouts to people who die because they haven't been able to resolve the ransomware. So very cold and calculating. And so that had an influence on him. Like, if hospitals are going to be so cold and calculating, well, we should be too. And he's also speaks about the 1999 bombing of a hospital in Belgrade. I think during the Yugoslav war, NATO bombed a hospital. Several people died. And that fed into his moral calculus, I guess. So he has reasons that relate to him that are totally individual. You know, my take home message was it's great to target the biggest and the baddest ransomware groups. Law enforcement action has been somewhat effective. I think it's suppressed the ransomware business, but there'll always be these small players popping up with, you know, their own agenda that are willing to take risks. Even though. Even though. And he acknowledges, Devman says this is, you know, a terrible thing to do. It's not going to end happily. But you know, somehow he's. He talks about his paranoia and his alcoholism, so. But still they do it.
A
Yeah. Yeah.
B
And so that leaves us, I guess, going back to the first piece, you know, what do we do about this proliferation of smaller groups? Well, it seems like a perfect problem for the private sector to have a.
A
Crack at interesting stuff. Hey, Tom, we might leave it there for today, but thank you so much for your time. And of course you can read Tom's full analysis at the Seriously Risky Business newsletter on our website, Risky Biz. But Tom, have a great week and we will catch you same time next week.
B
Thanks, Andaly. Sam.
This episode of Seriously Risky Biz dives into contemporary cybersecurity policy and intelligence, focusing on U.S. government utilization of the private sector in offensive cyber operations—with a comparative look at China’s approach—and an exploration of the evolving ransomware ecosystem, as profiled in two major reports. The hosts, Amberly Jack and policy/intelligence editor Tom Uren, unpack government strategies, industry dynamics, and the strange, often paradoxical personalities that thrive in cybercrime.
Dartmouth Institute Report Overview
Critical Observations
Tom points out a “starting assumption” in the report: more private sector involvement is desirable, but motives and goals aren’t fully clear.
“It assumes that we want to get to a certain place and that place is more private sector involvement in offensive cyber activities…”
— Tom Uren [01:18]
U.S. strategy is contrasted with China:
There are potential difficulties in trying to match China’s hacking-at-scale model:
“It strikes me as really hard to figure out what you would do with a whole lot more intelligence from China ... where it’s not clear that the government cares.”
— Tom Uren [04:13]
Policy Recommendations
The report recommends piloting programs authorizing vetted private sector teams to target “low risk actors” (e.g., cryptocurrency scammers, ransomware operators).
The logic: These attackers operate at scale, individually cause limited harm, but collectively represent significant threats—making them suitable for distributed, privately led responses.
“If you want an at scale response, perhaps the private sector is the place to get that.”
— Tom Uren [06:33]
A significant scam baiting community already operates with tacit legal tolerance, indicating the government is “pushing on an open door” to expand these efforts officially.
Profile: Analyst1 Report on ‘Devman’
Discussion shifts to an Analyst1 report by John DiMaggio profiling 'Devman’, a ransomware operator uniquely candid with security researchers.
Devman, a mid-tier, non-exceptional operator, transitions quickly from affiliate to running his own ransomware-as-a-service (RaaS) platform.
“He very quickly goes from being an affiliate for a couple of different ransomware gangs to, within six months, he set up his own ransomware as a service platform.”
— Tom Uren [11:19]
What motivates Devman is largely unclear; control seems a dominant factor, leading to unusual rules for his platform:
“He sets out these codes of conduct... You’re not allowed to be unprofessional.”
— Tom Uren [12:07]“If you are unprofessional, I’m going to take that negotiation away from you.”
— Tom Uren [12:50]
Despite 'professionalism', Devman’s only targeting “red line” is children—he explicitly encourages targeting critical infrastructure and hospitals.
“He’s perfectly fine with targeting hospitals… If hospitals are going to be so cold and calculating, well, we should be too.”
— Tom Uren [14:39]
Devman justifies this by referencing both overheard, transactional ransom negotiations by hospital staff and historical events (e.g., NATO’s 1999 hospital bombing), revealing individual and sometimes idiosyncratic moral logic.
“He has reasons that relate to him that are totally individual.”
— Tom Uren [15:28]
Ecosystem Implications
U.S. vs. China Cyber Models:
"So their system is the exact opposite where the government is the customer. ... Whereas China is the opposite. Many customers, many intelligence requirements, hack first, figure it out later."
— Tom Uren [04:48]
On ‘Devman’s’ RaaS Platform:
"I’m sick of people being rude to each other, so I’m going to set up my own ransomware as a service platform where people will be nice."
— Tom Uren [12:15]
On Targeting Hospitals:
"He sat in a negotiation that the Conti Ransomware group did with a hospital ... [the hospital] was talking about the ransom in terms of weighing-up how much it would cost to pay versus the payouts to people who die."
— Tom Uren [14:40]
On Ransomware’s Unstoppable Splintering:
"The ransomware ecosystem is going to splinter because you’ll have all sorts of people who have their own individual reasons for doing things."
— Tom Uren [13:28]
This episode highlights pressing questions about the optimal role of the private sector in America’s cyber offensive posture, contrasted with China’s market-driven hacker ecosystem, and demonstrates—through a Dr.-Strangelove-meets-true-crime profile—just how the ransomware underground continually mutates around every attempted clampdown. The interplay of policy, real-world criminal behavior, and the limits of both official and private action reveals the deeply human, messy nature of cybersecurity’s front lines.
For full analysis and more insights, the hosts direct listeners to the Seriously Risky Business newsletter at Risky Biz.