
When legit is the trick: Phishing’s sneaky new moves.
Dave Bittner: Welcome to "Only Malware in the Building." I'm your host Dave, and today we're playing everybody's favorite game, cyber feud. On my left, Selena. On my right, Keith. Contestants, get ready. We asked 100 cybersecurity professionals questions as they were yelling at their computers this week. Hands on your buzzers. Top answers on the board. Name something your computer does that makes you say, "Yep. That's malware." Selena?
Selena Larson: It suddenly gets really slow like it's thinking about every bad decision it's ever made.
Dave Bittner: Survey says [ring] number one answer. Slow performance is on the board. Keith, chance to steal. Name something else that screams malware.
Keith Mularski: Pop ups. It's got to be pop ups. So many pop ups. Pop ups asking me to update software I've never heard of.
Dave Bittner: Survey says [ring] that's a big one. Pop ups everywhere. We've also got your browser home page changes, your antivirus starts panicking, and my personal favorite, why is my web cam light on. All right. Next question. Name something malware steals.
Keith Mularski: [Ring] passwords.
Dave Bittner: Survey says [ring] top three answer.
Selena Larson: [Ring] money.
Dave Bittner: Survey says [ring] number one answer. Malware loves money, folks, almost as much as it loves bad security practices. Stick around because whether it's ransomware, spyware, or something you definitely didn't download on purpose, there's only malware in the building. And we're about to find out who invited it in. [ Music ]
Selena Larson: Hello, everyone. And I will take only malware in the building for 500, Dave. Wait. Is that not what we were doing earlier?
Dave Bittner: Wrong game, but we'll take it. And we also do not have to form our answers in the form of a question. We can just -- just go talk like normal human beings.
Selena Larson: Well, in this episode of "Only Malware in the Building" we are going to be talking about some interesting things. So we've talked on this podcast before about social engineering and how it seems like threat actors are getting more clever when it comes to crafting interesting lures, getting people to make risky decisions based off of things that they see on their computers. One of my favorites is of course quick fix, and we talked about that a few times. But today we're going to talk about social engineering plus the abuse of legitimate services. So two topics today. Device code authorization for account take over, which is really interesting leveraging the legitimate Microsoft attack flow for compromising Microsoft accounts. And then we also have abusing direct sent. So this is something that we see a lot with threat actors and essentially what it looks like is that someone in your organization or even you is emailing you and it looks real and it can be very believable. So pairing these two types of techniques with really great social engineering can be a very, very effective thing for threat actors. So yeah. I don't know. Dave, if you want to kick us off, I don't know if you have any thoughts about either one of these techniques. [ Music ]
Dave Bittner: Well, I mean I think social engineering has become a thing of its own these days, and it seems to me like there's no technical solution to social engineering. Or I guess maybe a better way to phrase that is social engineering's the easy way to get -- the best way to get around technical solutions. Right? If I can trick you in to doing something. And we're all human. So we're all -- if something we -- you know, over on the "Hacking Humans" podcast we talk about, you know, you're not dumb. You're human. And so you fall for these things. And it's interesting to me what you're talking about of chaining together some of these things to make the attacks even more powerful.
Keith Mularski: It's just using the game show analogy that we were just talking about you are the weakest link, Dave.
Dave Bittner: Well, I can vouch. That -- yes. In most cases, and certainly when it comes to the hosts of this show, I am the weakest link.
Selena Larson: You know what Dave? I was actually thinking about you earlier today. I had hummus for lunch.
Dave Bittner: Oh. All right. That's dip adjacent.
Selena Larson: Yes, and I thought, you know who would appreciate this lunch? Dave.
Dave Bittner: No. I do. I enjoy a good hummus. Was it a straight hummus or was it some sort of spicy flavored hummus?
Selena Larson: Just regular with avocado on a sandwich.
Dave Bittner: Yeah. Classic. Classic. Good for you.
Selena Larson: Keeping it easy. Keeping it easy.
Dave Bittner: That's right.
Keith Mularski: Well, we also can't have an episode without talking about dips. So this is one of our first cold opens that we didn't talk about dip so we have to throw it in there somewhere.
Dave Bittner: That's right.
Selena Larson: Has to be something that you can eat in front of the TV. And actually talking of TVs it's a really great analogy for the device code phishing because I think most people are familiar with when you, you know, get a new TV. You set it up. It's like a little -- a device code will pop on screen. So like scan this QR code to add your account to this television, for example.
Dave Bittner: Right.
Selena Larson: And it's sort of that authentication flow that threat actors are taking advantage of. And in these cases that we're seeing it is the Microsoft [inaudible 00:06:09] device authentication flow. So, you know, Microsoft 365 it will say "Hey, you know, add -- scan this code. Scan this QR code to add a new device to your account." So there will be these really interesting lures and oftentimes they're business relevant themed, something that you might be expecting anyways from your HR or your, you know, company coms. And sometimes it's a link to a QR code. Sometimes it's a QR code. But you scan it and then it kick starts the device code authentication process. And we see this both from e-crime actors as well as APT and espionage threats.
Dave Bittner: Well, help me understand here, Selena. I mean how does it begin? Am I just going through my email and I see something that perhaps is pretending to come from HR or something like that? [ Music ]
Selena Larson: Yeah. Yeah. So we've seen a variety of themes. One that I thought was pretty compelling was salary bonus, employer benefits. Things of that nature that come at the beginning of the year. Do you -- here's the pay rise, employee. Employee pay rise. And so it will look like something that was like a document that was shared or something that was shared from Microsoft. And so, you know, it's a URL you'll click on. And combination will lead to like a QR code. You scan that. And essentially it takes you through that overall process. So social engineering really plays a role here. Right? Like you have to craft a -- like a good and believable lure that makes someone think, "Okay. I should engage with this." And so you log in to an application with legitimate credentials because that's the process. So you point them to [inaudible 00:07:58] and then it will generate a token. So this is -- this is what the threat actor's actually like looking for. So it will say, "Okay. How do you -- give me this token or turn it over in some way." Or they'll email it to you. So you might click on the link, log in to legitimate service. It will show you this token and then that's what you kind of hand over to threat actor. So once this user is actually presented with the device code that's how it's -- that's the key. Right? That will unlock the account, so to speak.
Keith Mularski: I think this is really neat too because at least from reading your articles if I'm getting this correctly so you're getting this device code and it's coming from a legitimate link. Like a legitimate Microsoft URL, I guess so. So there's no suspicious link. So we've been training for phishing all these times. Don't click on suspicious links. But now this is a legitimate link. So if you check the URL it's fine. We've been saying all this time, "Make sure you use MFA." But now this is MFA because you're getting your device code. So it's kind of brilliant in the fact that it kind of just really goes against everything that we've been teaching for anti phishing all these years of don't click, check the URL, don't click on a suspicious link when now everything is legitimate all in this process. Am I correct in that?
Selena Larson: The authentication flow is legitimate, but the apps and things that they are saying "Oh, you know, grant this application," that's something that the threat actor has sort of created. And with those, you know, that whole flow does look quite legitimate. Right? Because it's using the actual device code creation technique. It's something that you do anyway like when you're trying to add legitimate accounts to your M365. Like it's something that you're like, "Okay. Like I recognize this. I've done this before." Or maybe you've added an account to your TV. You've scanned this QR code. You've logged in to, you know, these legitimate applications that you can put them on your TV. So it's this behavior that we're very used to doing in our -- both in our personal lives and professional lives too. It's like this process that we're like "Okay. Like this is how we do things now." And it's actually -- it's actually pretty clever. But so the landing pages themselves like those URLs will like when you're actually like given the device code, those URLs will look suspicious. Right? So it will be like something seems off here. But a lot of times the pages are very well designed. They're very believable. It is the like sort of the again the screen or the flow that you might be used to. So it is something that is pretty interesting. And threat actors we did used to see this occasionally with a little bit more targeted campaigns from the e-crime sphere. There's actually been red team tooling that's existed for a while for this. So it's something that has like been known, but not widely used until recently.
Keith Mularski: Well, that's when I started doing some research on -- when you shared the article for me. So, you know, you mentioned square fish in that. Like you said, that was a legitimate red team tooling. And, you know, I went and I watched a video today of kind of how, you know -- how that, you know, really worked. But then, you know, I guess what the criminal threat actors kind of took that square fish first iteration from I think it was like 2022 to square fish 2 now which was released in 2024. And so whereas that first red team tooling it was really targeted, it was more, you know, manual, it took a high skill to be able to do that, and limited volume that you could send with a fish that now square fish 2 is really that on steroids. It's scalable phishing. It's high automation, low skill. So low entry level. High volume capabilities. And just more widespread adoption on the criminal forum. So I thought that was really fascinating that really that the red teamers may have been the ones that kind of let the criminals know that, hey, this is a new way how you could phish.
Selena Larson: Yeah. I think it's really interesting because it was I mean it was around and it was something that, you know, was not widely seen, but we had seen it from like, you know, red team and targeted attacks and from the e-crime thing. And I remember last year or the year before there was a lot of talk about APT threat actors being like, "Oh, my gosh. Like look at this really unique attack chain." This thing that these espionage threat actors are using now. Oh, my gosh. It's so impactful. And I remember one of my researchers being like, "Yeah. We've seen this." He was not impressed.
Dave Bittner: In a way. Yeah.
Keith Mularski: I do have a quick question on this. When did - when did Proofpoint or when did you start seeing kind of a spike in these types of attacks? And the reason why I'm asking is that when I started doing research one of the other phishing kits that does this is called graph phish that was developed by a guy and on the Russian forum exploit IN. Just this summer he released it publicly. So he was trying to sell it and it just wasn't getting a lot of traction. And all of a sudden this July he's like, "Oh. I've developed this. I'm just going to put it out for public release. Here's the download link. Here's the password." So I'm really curious if you really started seeing this spike from July onward.
Selena Larson: Yeah. It took a little bit more, but yes. It was definitely in alignment with when that tool was released for free, just out there for everyone. I mean I think it was like a little bit more of a slower adoption, but come the fall we started seeing it like pretty regularly. And now there's like other ones too. We're seeing new phish kits emerge that use the device code authentication flow. Stick around after the break. [ Music ]
Dave Bittner: So let me ask you this. Is this a situation where having something like a password manager could help because, you know, like my password manager will if I try to log in to a site that isn't the site it's claiming to be my password manager will throw a fit. It will either not automatically fill in my credentials or it will say, "Hey. What are you doing? This is not, you know -- this -- you're filling in your Microsoft credentials, but this is not Microsoft." Is that a possible avenue of defense?
Selena Larson: Well, it is a legitimate Microsoft authentication flow. So it is like --
Dave Bittner: Because they're only after the token.
Keith Mularski: Yeah. It's passwordless.
Selena Larson: Yeah. They're not --
Dave Bittner: I see.
Selena Larson: Yeah. So they're not after your username and password. They're after that token. But from the enterprise perspective there are things that organizations can do like for all users. So honestly blocking device code phishing if possible is really the best option because you just, you know, lock this down and it just won't work. So even if, you know, they fall for the phish and get the device code and, you know, it just doesn't -- they won't -- it will block it. Right? So they won't be able to actually go through that whole authentication flow. But also using conditional access policies. So much more of an allow list approach. So these are the apps that we approve that we know to be safe. There's also things like only using it for approved users or operating systems or IT ranges. So like using like named locations where it's like, okay, we know that you can log in from here, but if we're seeing attempts from Russia this is not it. So yeah. So there's also, you know, like again you're using conditional access and those policies can really help prevent as well. And also like user training. Right? Like this is something that's increasing with increasing frequency. And making sure that people know that this is a new technique that they're using. I find that, you know, kind of talking to people and explaining when it comes from a social engineering perspective like understanding why you might fall for something or why it's effective, and not just being like "Here's a screenshot." But like here's why it's really effective. And kind of incorporating that in to user training I think is very helpful.
Dave Bittner: What's the training against this? How do you -- how do you vaccinate people against this one?
Selena Larson: So usually it's like looking for suspicious URLs. Right? But that doesn't really work because you're prompted to actually enter a device code. So that is really what it is. So it's the action. And it's like looking at the technique overall and seeing the actual device code and seeing that this is how it can be abused. So not entering those from untrusted sources. So if you just get a random email from someone at gmail.com or, you know, an email that says it's from HR that's not working, the lure itself might look and align with our suspicious triggers. Right? Like the social engineering is important there.
Keith Mularski: And it's submitting a QR code though too. Isn't that -- isn't that the --
Selena Larson: In some cases. Yeah. Yeah. So yeah. So having that -- having that general awareness of being like "This is what it's asking for." If someone asked you for your device code, say no. If someone's asking you for a username and password, say no. Like another thing that we're like keep it secret. Keep it safe.
Dave Bittner: Could you have a company policy in place, for example, that requests from folks like HR need to be verified in some other human to human way? Or is that just going to get old for HR really fast?
Selena Larson: Yeah. I mean that -- because it's just so much impersonation, I mean you should. That should already, you know, be part of your organization's user training. Like if you get an unsolicited email from someone that's pretending to be this person and it doesn't match what her email looks like, like ping her on Teams. You know? Like that. It's always this sort of like double check and verify no matter what. You get that a lot with like business email compromises too. So like a lot of look alike domains, for example, can be very very good. And, you know, if you're getting an unsolicited email from a supplier that looks basically identical to the domain just call your supplier. Like "Did you really mean to send me this?" But what also happens too is, right, when you have account take overs sometimes there are your legitimate suppliers emailing you, but it's [inaudible 00:18:31] by a threat actor. Right? So that is just like double checking when you get these unsolicited emails and things that you weren't expecting as part of your work flow. Contacting them via phone or on a chat app or some, you know -- some other way to make sure that it is actually them and they did mean to send it. That you are getting a raise. [ Music ]
Dave Bittner: I mean basically don't trust anybody anywhere any time ever again. Right?
Selena Larson: It is a theme of this podcast. Just go in to the woods.
Dave Bittner: Right. People, yes, go build a cabin in the woods where you're out of range of cellular service. Build yourself a Faraday cage where you can't get satellite service. And become a hermit and yeah. Just live a lonely life.
Keith Mularski: Dude, I'm going to do that for eight days on my cruise because there -- I'm not going to be in touch with the outside world. So no internet. So.
Dave Bittner: Uh huh. We'll see how long it takes before you or -- either you or your lovely bride spring for the expensive internet package because you just can't stand it.
Keith Mularski: No. I'm going to be good. I'm going to be good.
Selena Larson: I like to call escaping in to the woods or without internet throwing in the towel. Thoreau.
Dave Bittner: Oh. As in Thoreau. Oh. Nice.
Selena Larson: Wow. That didn't -- that failed.
Dave Bittner: Boy, that's a smart joke for this crowd.
Selena Larson: I forgot this wasn't Jeopardy.
Dave Bittner: Yeah. That's right. We're Family Feud, not Jeopardy. Family Feud, not Jeopardy. A Thoreau pun probably isn't going to get very far for you with Family Feud the way it would on Jeopardy. But we'll allow it. What else you got for us today, Selena?
Selena Larson: Oh yeah. Well, the other thing I wanted to talk about is direct send. I don't know if you guys have experienced this at all. Keith, did you have any --
Keith Mularski: No. No. I was -- I was just getting ready to pivot to direct sends because this is fascinating too.
Selena Larson: Perfect. Take us away.
Keith Mularski: No. No. I was -- let you said it, and then I'll add the color. So.
Selena Larson: So -- so Microsoft's direct send feature essentially makes phishing emails that look like they're originating from within the organization. So it's --
Dave Bittner: Thank you, Microsoft.
Selena Larson: Yeah. It's basically what it is it's a feature of Microsoft 365. It allows devices and apps to relay messages to Microsoft tenants without authentication if the recipients are inside an organization. It's simply useful for things like, you know, printers, legacy apps. It's widely, widely used. And again this is abusing legitimate services. So just like the device code phishing that's like very useful and very helpful and very important for work flows can be abused, I feel like just everything -- everything these days can be abused. And so now we have this direct send feature and threat actors have realized "Oh wait. Hold on a second. I can -- I can do this." And so we do see that it can be misused to deliver unauthenticated messages that appear as like real internal emails. So basically what the email will look like is that this is from you to you or, you know, someone within your organization to you, and it will have something that is like, oh, again sometimes a QR code. We do see that a lot where it's things like, "Oh. This is -- you have a new task or new priorities." Or like they love telling people they're getting raises at the beginning of the year or at the end of the year. So you have these sort of organization -- they would seem like they would be real within organizations, stuff that you might be expecting. HR. New voice mail. Things like that. And it will look like it's coming from them, but in reality it's a URL or it's a QR code and mostly we see it with credential phishing, credential harvesting and account take over. But it could -- the same technique could be used to deliver malware.
Keith Mularski: And this is one kind of like the bad guy's on -- is on the inside. You know, like we've been so again accustomed to see on our emails external, you know. That's just tagged right in the subject line so that you know it's coming from outside. But now this is coming through and you think, hey, well this is, you know, Dave sent it to me or Selena sent it to me. It's coming from internal. So naturally again you're thinking that this is safe. You're not seeing those red flags of it being an outside person or from the outside. So you're more than likely to be a little bit more trusting and maybe click on it, especially if the lure is HR bonus or salary increase or something like that where you're going to be a little bit more curious and trusting to click on it. So I thought this was a very unique stop clicking on this stuff. And now we're seeing the actors now really start to pivot because I think our training is being more effective. People have a little bit more awareness. So now they have to kind of shake things up. How do we appear that we're coming from internal? Or, you know, the QR codes. Or, you know, the device codes like we just talked about. How do we really kind of change up those TTPs now to become more effective?
Dave Bittner: Does this rely on someone else in your organization previously being compromised?
Selena Larson: No. So essentially what the flow looks like just as an example a threat actor will connect to a virtual host. And like RD3 and 33AR. The SMTP connections are initiated from these hosts to unsecure third party email security appliances. And then those messages are relayed through appliances to Microsoft 365 tenants belonging to those organizations. It's honestly a little confusing.
Dave Bittner: I'm confused. I don't know about you, Keith, but --
Keith Mularski: She lost me at appliance.
Dave Bittner: Yeah. When you say appliance, what do you mean?
Selena Larson: So some sort of -- whatever you're using for, you know, like your email security or whatever, the apps and services that are incorporated within your text stack. But essentially what it is is they -- what it really comes down to is threat actors are abusing the legitimate protocols that we use in printers, how printers talk to each other, for example. So you can print from the third floor when you're on the first floor. To do something very similar. But the good news is you can disable it. So you can reject direct send. You can basically use mail flow rules. So basically like you can block email from unauthenticated relay IPs. You can like look at the headers to see if that, you know, if it's legitimate. But honestly like if you're -- if you're not actively using direct send for business critical information you can just reject direct send.
Dave Bittner: Turn it off. Pull the plug.
Keith Mularski: I think a lot of the messages too from reading your article and research on it, a lot of these do go to the junk mail folder. The problem is everybody still looks at their junk mail folder and they say, "Well, this is an internal email. Let me click on it. And then let me see what's going on here." So, you know, the messages are failing. It doesn't have a great success rate. But, you know, a lot of times it's still delivered to the junk mail which people check. So.
Dave Bittner: Not me. I don't check my junk mail. No.
Selena Larson: Do you check any email, Dave? Are you email free?
Dave Bittner: I do. I mean I -- in general I loathe email. I just my -- it's just one of my least favorite parts of the day. When I think about it, I think it's time to check. And I check it a couple times a day, but when I do my body language goes, "[Sighs] I have to check my email."
Selena Larson: I'm a real sicko because I look at my email too much.
Dave Bittner: No. No.
Selena Larson: I also just look at everything. Just constant bombardment of information.
Dave Bittner: See now Keith's about to go on his trip and my wife and I are opposites when it comes to this. When we go on vacation she will keep up with her email so as to not have an avalanche when she gets back. I'm the opposite. I will ignore it the whole time I'm gone. Then when I get back I do what I call declaring email bankruptcy. Just to mark everything as read counting on the fact that if it's really important they'll email me a second time.
Selena Larson: Wow.
Keith Mularski: Do you put in your out of office message, you know, "If you want me to respond back to you, email me. I'll be back on let's say, you know the 3rd or 10th or whatever?"
Dave Bittner: Yes.
Keith Mularski: "Email me then because otherwise I'm just not going to see it."
Dave Bittner: Yes. I do. Yes. I put the work on them. I don't have time to go through 1,000 emails when I get back from vacation. I'm exhausted from vacation.
Selena Larson: Yeah. When my husband listens to this episode he's going to be like, "Selena, you need to do what Dave does. Do that."
Dave Bittner: Put the phone down.
Selena Larson: Yeah. Yeah. You remember what Dave said on the podcast, Selena?
Dave Bittner: You don't have to reply right now. You don't have to reply.
Selena Larson: Nope. Nope. [ Music ]
Dave Bittner: All right. Well, big picture solutions here. I mean the top level recommendations. What should organizations be doing to protect themselves against these things, Selena?
Selena Larson: Yeah. So when it comes to, you know, direct send obviously you can reject direct send. Definitely enforce email authentication. So SPF, DKIM, DMARC, these things that are really critical not just for direct send abuse, but within email abuse and email phishing campaigns of course in general. Using some sort of email fraud defense or email protection can be very, very helpful. But really like I feel like when it comes down to the abuse of legitimate services sometimes it's just like don't let those services be abused. You know, like when we're talking about click fix disabling PowerShell for like users that don't need it. You know, like most people don't need to just, you know, command R run PowerShell on their host. So things like that that are components, it does take a little bit of effort and you do need to say, "Is this something we can do?" Right? You know, you have to do an asset inventory. You have to understand your own business processes and what people are using for what purpose because sometimes when you just block everything it can really disrupt business group function. So, you know, like anything else in security, you do need to have a knowledge and understanding of how the business operates before you just, you know, block all IPs from China [laughs].
Dave Bittner: Right. Right.
Keith Mularski: The other thing is just like, you know, how we saw the correlation from the phish kit being released on the underground to it being actively used, again you need to have visibility in what the threat actors are doing. You need to have that threat intelligence to see what's being talked about out there in the underground and seeing the new types of tools that are going to be out there. And then because this is a great case in point where if you're following, you know, exploit IN and you know you see this new phishing kit that gets released that's doing something very unique, chances are you're going to start seeing that being adopted in the months following that. And then you can kind of get out ahead of that so that when you see that first, you know, device code phish then you're already ahead of the game. So making sure that that intelligence drives operations.
Selena Larson: Yes. That's actually a great point, and you know maybe we could just even have a podcast talking about operationalizing your intelligence because it's not [laughs] -- intelligence without actionable take aways is just information.
Dave Bittner: Yes. Right.
Selena Larson: But yeah. Looking at those patterns, I mean, Keith, I'm sure you see a ton with your job of like threat actors saying, "Look at this new thing I have." And then it just explodes.
Keith Mularski: Absolutely. Absolutely. That could be a good topic for sure.
Dave Bittner: I feel as though I'm curious what the two of you think of this. I feel as though as the threat actors grow more and more sophisticated and more specialized in their approaches that in some ways the solutions are becoming less and less satisfying. Does that make sense?
Selena Larson: Turn it off, you mean?
Dave Bittner: Well, right. Like when -- if the -- it's kind of like, "Hey, Doc. My elbow hurts when I do this." And the doctor says, "Well, don't do that." Like that's not -- you know, that's not satisfying, but yet with a lot of these things that seems to be where we are.
Selena Larson: Well, to Keith's point earlier, though, I think that's a direct result of us doing those things. Right? So like disabling macros by default. So it used to be, right, like macro enabled documents were everywhere and like it was like if macros are enabled so it was like you just had to block macros. Like don't enable macros. And then when Microsoft did that it just like completely shifted the landscape and forced all this behavioral change. Same with MFA phishing. Right? So it's like, okay, well don't not use MFA phishing. So now we have MFA phishing's the norm and so now threat actors have to adapt. So I think a lot of these things are a direct result of it -- of us doing the basics and saying that this is -- you know, this is how you -- this is how you prevent this exploitation. But the basics, the bar for the basics I think has increased. So it used to be MFA everywhere solves account take over. That's not true anymore. Now you have multiple different ways that attackers are using techniques for account take over. And so each one of those doors has to be locked. Not just the MFA door has to be locked. So I think that that's part of it, but I also think that attackers are just getting a lot more creative and are finding a lot more unlocked doors and just new ways in to organizations now that coming in from the chimney is like [laughs]. [ Music ]
Keith Mularski: Yeah. You're always going to get a reaction to what we do, you know, whether that be, you know, what we do as defenders or what we, you know -- reactions to law enforcement take downs. The bad guys aren't going to just say, "Oh. You got me. I'm going to go, you know, sell hot dogs or something." You know, they're going to continue to come up with new ways and collaborate just like we collaborate to come out with new techniques in order to make money because really at the end of the day it's about money and information that they want. And that's never going to go away.
Selena Larson: Yeah. I think there's always been this idea of basic cyber hygiene takes out a lot of the low hanging fruit for threat actors.
Keith Mularski: No doubt.
Selena Larson: And yeah. And now there's just like more hygiene required.
Dave Bittner: Well, all the threat actors are wearing drywall stilts now so they can reach more of the fruit.
Selena Larson: Yes. They are there climbing. They are climbing up. Exactly. Yeah. How many metaphors can we squeeze in to this podcast?
Dave Bittner: All of them. I have an endless list.
Selena Larson: We will be right back after this quick break. [ Music ]
Dave Bittner: Keith, enjoy your trip. I'm going to go hang out in my Unabomber shack in the woods and hide from everyone because to me that's the only thing that's going to work these days.
Selena Larson: I'm going to manifest Dave's method the next time I am on vacation.
Dave Bittner: Yeah.
Keith Mularski: I'll be thinking about you guys as I'm underneath a palm tree drinking a, you know -- a punch rum drink or something like that. So.
Dave Bittner: Enjoy yourself.
Selena Larson: Enjoy. Well, thank you both for letting me talk about things that I find very interesting. I'm always fascinated by social engineering paired with the abuse of legitimate services because it does just keep changing and threat actors are getting a lot more creative. So it's been very fun to chat about this, to learn more about this as I go as well on my research journey. To all our listeners, we hope you took something away and the next game of Jeopardy that you watch will have the answer for what is direct send. Thanks for tuning in. We'll see you next time.
Dave Bittner: See you next time.
Keith Mularski: See you next time.
Selena Larson: And that's "Only Malware in the Building" brought to you by N2K CyberWire. In a digital world where malware lurks in the shadows, we bring you the stories and strategies to stay one step ahead of the game. As you're trusty digital sleuths, we're unraveling the mysteries of cybersecurity always keeping the bad guys one step behind. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you ahead in the ever evolving world of cybersecurity. If you like the show, please share a rating and review in your favorite podcast app. This episode was produced by Liz Stokes. Mixing and sound design by Tre Hester with original music by Elliott Peltzman. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. [ Music ]



