Only Malware in the Building 5.5.26
Ep 23 | 5.5.26

Mythbehavior under investigation.

Transcript

Selena Larson: Welcome back to Only Malware in the Building, the show where -- [animated voice] where we talk about cyber.

Dave Bittner: Did your voice just -- [animated voice] go up? [Human voice] What? What is -- [animated voice] what is happening? Why do we sound like animated chipmunks? This is incredible. What did we press?

Selena Larson: [Animated voice] No, please. Don't hit any -- don't touch anything.

Dave Bittner: [Animated voice] I'm touching everything.

Keith Mularski: [Animated voice] Stop it. You might make it worse. See? I told you.

Dave Bittner: Oh, wow, Keith, you sound hilarious right now.

Keith Mularski: We sound like we narrate movie trailers now. [ Music ] 

Dave Bittner: In a world where malware takes over --

Keith Mularski: Three hosts lose all control.

Selena Larson: [Animated voice] Okay, wait. What button did we hit? I didn't touch anything.

Dave Bittner: [Animated voice] I definitely hit a button, I just don't know which one.

Selena Larson: [Animated voice] Great. We'll add that for us.

Keith Mularski: Okay. This is --

Dave Bittner: Not helping. This --

Keith Mularski: [Animated voice] So many buttons.

Selena Larson: [Animated voice] Why are none of them labeled?

Keith Mularski: Who set this up?

Dave Bittner: We did. Wait -- [ Electronic Humming ] I think I fixed it. 

Selena Larson: Hello?

Keith Mularski: Oh, thank God. 

Dave Bittner: Okay, nobody move.

Selena Larson: New rule: We label everything. 

Keith Mularski: Yeah, "Because I'm old, big labels, bright colors. 

Dave Bittner: Like, "Do not touch this one ever."

Speaker 1: Or, "This one turns you into a chipmunk."

Keith Mularski: Honestly, that one gets a star. 

Dave Bittner: No, no, no, no, no, no stars, no favorites. That's how all this happened in the first place.

Selena Larson: We are absolutely going to hit that again.

Keith Mularski: One-hundred percent.

Dave Bittner: You guys are hopeless. [ Music ] [ Typing ] [ Music ]

Selena Larson: Hello and welcome to "Only Malware in the Building." I'm Selina Larson, and today I'm very excited to talk about something that has been on the top of my mind for a while: identity. Keith, Dave, who are you?

Keith Mularski: Oh, man, I can neither confirm or deny who I am.

Dave Bittner: Yeah, that's right. The old G-Man, Mr. Undercover, Mr. Secret Agent Man. Is he really Keith Mularski? We'll never know. No one will ever know.

Keith Mularski: He could be a double agent.

Dave Bittner: Me, on the other hand, who knows? You know what? I ask myself pretty much every day, "Who the heck are you? What are you doing here, and why are you this way?" So it's a bold question to ask, Selena, and I'm not sure we want to go down that path. [ Music ]

Selena Larson: I think we should, in part because multiple cybersecurity companies have recently released threat reports looking over the last year or so of threat data, and all of them had one thing in common: that threat actors are increasingly targeting identity. Now, every time I think about this, I think about that scene in Zoolander where he's, like, staring in the mirror and is, like, who am I? I feel like this is actually what threat actors are asking themselves as they are compromising and trying to take over everybody's personal identity, so a couple of highlights that I wanted to talk about before we sort of dive into everything. The thing that sort of kicked me off on this look into identity and the landscape overall is back in February, Sophos published "Nowhere, Man: The 2026 Active Adversary Report," and they have this fantastic visual, this graph, that says, "Identity-related root causes as percentage of cases have increased every year since 2022," and 2022 was the last year that non-identity-related root causes, so things like malware or exploits, things like that, were more commonly observed than identity-related root causes. I thought that was pretty interesting, and then, of course, we have a couple of other reports that came out recently, including SpyCloud. They found that from their "2026 Identity Exposure Report," non-human identities are now a core attack surface. SpyCloud saw a 23% increase in its recaptured identity data lake, which now totals over 65 billion distinct identity records. Then finally, I wanted to highlight Red Canary's "Threat Detection Report," which they publish every year, and it's really great. If you haven't read it, I definitely recommend it. They say identity-based threats now account for more than half of our total confirmed threats, following an 850% increase in identity threat detections year over year. What do you guys think about this? This is crazy, right?

Keith Mularski: Oh, it is nuts, and like you just mentioned, you know, credentials, I know at Qintel, we collect compromised credentials, too, and I was just looking today, like, how many compromised credentials we have. It's, like, 414 billion, and that's just not just, like, you know, just, like, combo lists and malware logs and cookies. There's just so much of the compromised credentials that are out there, and we're just seeing the threat actors, you know, hey, instead of having to hack in using an exploit, hey, why don't we just kind of log in as that person? You know, I just saw in the news in the last week, I think maybe it was in even one of these reports where they were saying, "identity's the new perimeter," and then we just had the Stryker intrusion with the Iranians that was, basically, and we can dive into that, too, but just using a compromised identity, so this is definitely the new trend. [ Music ]

 

Dave Bittner: So let me ask you both this, I'm curious, to what degree do we think that the shift towards identity has come because the other ways to get in that used to be easier aren't as easy as they used to be? In other words, was there a time when identity was harder than malware, right, but now, we've got everything buttoned down pretty well against malware, so the path of least resistance has shifted to identity? Does that make any sense?

Selena Larson: Yes, I think that's correct, and we've seen, overall, a shift in the threat landscape, and I thought it was pretty interesting to note, specifically in Sophos' report where the 2022 was sort of the last time that identity was less than other initial access or types of attacks. I don't think that that's necessarily a coincidence because especially if we think about email as initial access, which is where I live in my data at Proofpoint. There was a big shift in 2022 to 2023 where macro-enabled attachments from large botnets, high-volume threat actors didn't work anymore. It used to be, like, you know, one click to enable macros could get you quite a bit of access within an organization's environment, and that's not to say that was the only access that we saw, but it was something that was pretty common and was pretty easy because people would believe that they had to enable macros in order to access documents. It was a pretty reliable attack that ended up getting closed because Microsoft locked that down. Macros were defaulted to not be able to be downloaded from the internet, so it was blocked, that attack path. I think that we see this sort of trend, right, away from this sort of easy, low-hanging fruit to identity, but then I also think that as we're even more interconnected, things like our identity can get us so much more within the enterprise, right? We have everything moving to the cloud. We have our access that can get us sensitive corporate information, access to a lot of different things that we have to use in our data all the time, and so it's a very, like, interesting exploit and avenue for threat actors. Whereas, like, malware can lead to ransomware, which was, like, encrypted data and having huge ransomware. Now, if you can steal data or steal an identity, you can make smaller amounts of money off of that type of information. [ Music ]

Keith Mularski: Yeah, and I think, you know, the identity part, too, like, Dave, what you were just saying, EDR has gotten so good now that if I could, you know, steal your session, I'm you. You know, one of the things that we're seeing out there is, you know, a lot of perpetual tokens, you know, or cookies that aren't expiring. When the threat actors get that, they can go in there. There's no token binding to, you know, where you're binding that token to that device, so it could be transferred by the threat actors to then be you. Then with the infostealers that are out there, I think in one of the reports that you mentioned, Selena, I can't remember which one it was, but they were just saying that the average device has -- that gets popped with one of these infostealers out there has 87 different stolen credentials on it. If you get on one of these, you know, hosts with an infostealer, you're getting the corporate accounts, the personal accounts, you know, the saved browser sessions, VPN keys, cloud admin tools, API keys, so you're really getting a lot. I think the threat actors on the underground, they're seeing, look, this is kind of an easy way to get on because a lot of these infostealers are kind of low weight malware, but the return on this is just enormous.

Selena Larson: I think it also kind of coincides, and I'm curious, Keith and Dave, your take on this, is it sort of coincides with the ransomware going from big game hunting and encryption to more like data theft and extortion, so that became a little bit more of a viable business model, where you saw the rise of identity being more interesting there because of the types of data that criminals can get their hands on or resell, or the different types of access that's available. Whereas it used to be, like, all the money was made in big game hunting ransomware with, like, full encryption, and now, it's, like, well, data theft and extortion is a lot more of, like, that business model. Do you think that that at all had a role in the sort of focus on identity?

Keith Mularski: I think so, but I also just think that, you know, we've been focused for all these different years on, you know, making sure that we're patching CVEs, that we're making sure that we have good malware protection, and we've been focused on that aspect for so long that we just kind of haven't focused on identity like we have those others. As with every action, there's a reaction, so with the good guys doing that and making that harder, the bad guys are just going to -- are pivoting to different areas that are a little bit easier to get in.

Dave Bittner: I wonder, too, like, how does this align or track with the push towards multifactor authentication and even pass keys, because I feel like people have gotten the message that username and password is not enough. Yet, this continues to be a place where the bad guys are having success, so is this happening in spite of the adoption of multifactor, or is this just that even with multifactor, like Keith said, they're able to steal tokens, and that's the ballgame?

Selena Larson: I mean, I think it's a little bit of both, right? So you have organizations that still aren't adopting multifactor authentication and things like generic password spraying and brute force can be fairly effective. Then you have MFA-enabled attacks that are even if organizations have multifactor authentication, they're still able to get those cookies. They're still able to become that individual, and I think that we see a lot of different phishing kits popping up, as well, from different various threat actors that are multifactor authentication phishing. That's, basically, phishing is multifactor authentication these days. In our data, I thought this was a really interesting statistic that we published recently is that 99% of organizations experienced account takeover attempts based off of our cloud threat data, and 67% experienced a successful account takeover. Of those account takeovers, 59% of those accounts had MFA enabled, so the majority of accounts did have MFA, but the kits are becoming a lot better. Threat actors are becoming a lot more creative with how they're conducting their phishing. Social engineering is becoming a lot more convincing as well. We talked about that a little bit on our podcast. I think now MFA, yeah, maybe MFA is everywhere, but so are MFA stealing credentials, credential kits. Now it's like, all right, it's time to do the next level, right, and a token, a physical token, a physical key to prevent some of that.

Dave Bittner: Well, that was going to be my next question because I remember -- oh, it was probably a couple of years ago now. I think it was research from Google where they basically said, on their own internal tests and experiments and so on and so forth, that if you had a hardware key, basically, that was the thing that was like 99.9% effective at preventing account takeover. Again, this was a couple of years ago, so I wonder, do either of you have any updated information on that? Is that still true? Is that still pretty robust in its level of protection comparatively?

Selena Larson: Well, now I think you need to draw blood [laughter] and have your DNA logged in order to access the laptop.

Dave Bittner: Been there/done that.

Selena Larson: Yeah, no, I mean, that's still the best. I mean, that's just the reality of where we are now is that, yes, a physical key, because threat actors are becoming so much more creative, and I think, too, with social engineering, their -- Proofpoint has actually published research on how you can sort of social engineer around the physical key required, basically saying, oh, this doesn't work. You have to do an MFA option that's, like, a code or something, so there are ways to kind of trick it, not necessarily by bypassing a physical key, but basically using social engineering to get somebody to use a less-secure method of logging in.

Keith Mularski: That's what we're seeing with the Scattered Spider guys. You know, they're following that up with a phone call to IT, and, you know, they're saying, well, hey, I'm having trouble logging in or my MFA is not working. Can I reset it? Just like what you were saying, Selena, if it was a token, hey, my token's not working. Hey, could I set it up? I can give you a phone right now, and we could set up a new MFA, and that's what we're seeing with the Scattered Spider group to kind of get around that. You know, the recent Ty- -- I want to -- I always want to say Typhoon, but it's Tycoon 2FA.

Selena Larson: Tycoon2FA, yes.

Keith Mularski: Yes, I was so into Salt Typhoon, so that was kind of screw me up. So, yeah. Tycoon2FA, you know, so that's, you know, one of the phishing kits, like you were just talking about, Selena. I guess we're going to kind of dive into that, since you guys played a real big part in that takedown. You know, but they're phishing and bypassing and doing a man-in-the-middle attack to defeat that MFA. That phishing kit is just sold for, you know, $120 on Telegram, so it's a low entry to kind of a sophisticated attack. [ Music ]

Selena Larson: Well, the tycoon case was really interesting. Tycoon was the biggest MFA credential phishing threat in our data and, I believe, in other people's data as well, right? Microsoft published some great research on it, as well, and was seeing millions and millions of emails attributed to the Tycoon phishing as a service platform, and it was around for quite a while, quite a few years. It was very popular with phishing, credential phishing threat actors. It was easy to use also, so it was well maintained. The person behind Tycoon was, you know, offered support, was regularly updating it, providing tools for people to be able to just buy a kit and start phishing. I think that the focus on taking down phishing is really exciting to me because we've talked about, previously on this podcast, targeting malware disruptions, things like Operation Endgame going after Lumma Stealer or Peekabot or some of the, you know, the big botnets that are responsible for a lot of ransomware, but I feel like credential phishing and phish kits get a little less love from both law enforcement, but also, sort of the general security research community. I think that that's partly because they're just not as, like, "cool" or "technical." I have air quotes. You can't see them. 

Dave Bittner: Yeah.

Selena Larson: But I think, you know, credential phishing is like, oh, that's just phishing. You know, like, I want to look at the botnets. I want to look at the wipers. I want to look at fun malware, but credential phishing using multi-factor authentication phish kits can lead to things like follow on malware deployment. If you're able to get into a corporation, you can take over someone's identity. You can steal data. You can commit fraud. You can find banking details, or you, as a threat actor, can sell that information onto a much more sophisticated threat actor that can then drop interesting malware, pivot within an environment, potentially drop ransomware. It's an opening that can provide you with a lot of different opportunities. [ Music ] We'll be right back. [ Music ]

Dave Bittner: So if this is the reality that this is how folks are getting in, does that mean we need a pivot on the inside, inside the castle moat? In other words, is, you know, everybody's talking about zero trust and micro segmentation and all those sorts of things, is that no longer optional? Is that a necessity, given that we're seeing so much success of getting in with people's credentials?

Keith Mularski: Yeah, I mean, really, at the end of the day, you know, right now, we have to, obviously, have that least privilege and all that, because if somebody's logging in as me, it looks to the defenders that it's me. The threat actor could utilize all of my privileges to pivot throughout the network, and nothing's really going to flag unless I start, you know, trying to deploy Mimi cats or something like that. You know, but, you know, if you're just kind of, just pivoting through there, it's just going to look like a regular user session without necessarily bad behavior. Again, some of the things that we've talked about here all the time with, you know, segmentation and least privilege, you know, all go into play here.

Selena Larson: Conditional access policies are also super important. Basically, you can create a sort of allow-list approach, so these are the accepted use cases for this user. It's different, you know, users, operating systems, IP ranges, name locations, things like that to make it so that you have the picture of the person who should be logging in, who should be using this identity, and if it deviates from this set identity, then it would flag, like, this is suspicious. This is something that I should be investigating. 

Dave Bittner: I guess, too, like privilege sprawl is something you got to keep an eye out for, as well, where over time somebody needs access to something, and even when they don't need it anymore, it tends to stick because who's checking up after the fact?

Keith Mularski: The number of political accounts in corporate America right now is just absolutely insane. You know, when I was at EY and we were doing attack and pen, one of the first things our guys would do is just get on to SharePoint and just start search of SharePoint for privileged accounts, and 99 out of 100 times we would find one, and, you know, within two hours, then we would have domain access. So there are absolutely too many privileged accounts out there and just really poor secret management for sure. [ Music ]

Selena Larson: Well, I did actually want to touch back on Tycoon because I did want to make sure that we gave the flowers to all the people who deserved it and also encourage people to think about credential phishing as much of a priority as information stealers, as malware, as ransomware, things like that. So also, I wanted to shout out Red Canary again, because I was at the SANS conference at the end of January. There was a woman from Red Canary who was talking about prioritization of the different threats, and they actually had identity and, like, credential phishing as a higher priority than malware in her framework that they have. I thought that that was so interesting. I think it sort of signals this shift within our community, like, within cybersecurity. That's, like, okay, we know that identity is becoming the new playing field. This is what threat actors are prioritizing more than anything, and we have all of these case studies that are coming out like saying, look how much identity is sort of taking over the landscape. You have companies that are saying, yes, we're prioritizing it this way, and now I think we have the tools that are available to us. It's just a matter of, sort of, implementing them. One of the tools I think in the toolbox that is very exciting that we have talked about on this podcast before is, of course, law enforcement disruptions or legal types of disruptions. The Tycoon disruption was a perfect example of this. It was a coordinated effort between public and private partners. Proofpoint, of course, played a role, but Microsoft, Europol, Cloudflare, Coinbase, eSentire, Health ISAC, Intel 471, Shadowserver, SpyCloud, there was a group of organizations that really sort of came together to say, look, this is a huge threat in our data. We are seeing this impacting our customers, impacting us, impacting the number of credentials that we're seeing on the dark web. What can we do about it? And so, there was this coordinated effort between public and private with law enforcement from Europol and different countries and this private sector with Microsoft and Health ISAC with a lawsuit against the creator, basically, this multi-pronged approach to do this takedown. It's not necessarily like wiping it off the board forever, and it's not to say that MFA phishing doesn't exist anymore, but it signals to the bad guys like, hey, we are taking this seriously now. Phishing isn't just phishing. Phishing is up there with the most important threats to us. I think it also signals to organizations like, hey, credential phishing is not, quote, "just credential phishing." It's something that you need to take very, very seriously because it can have these very significant impacts, and, you know, I'm kind of curious. Do you see that narrative shifting or do I just sort of live in, like, a little bubble where I think people focus more on like malware, ransomware, and credential phishing is more of a second thought? [ Music ]

Keith Mularski: I mean, I think as like an agent when I was at the FBI, you know, in Cyber Division, you kind of almost had, like, this badge. When you were, like, doing exploits or you're doing something that -- you know, you're doing cool, cool things like that, or you know, at least there was that perception of that, you know, while phishing or spam cases aren't as sexy, you know? I think everybody likes to do gee-whiz things and that's why, you know, they like the look at the zero days and things like that, but what I love about this takedown is of really just industry and law enforcement listening to the pain points that industry is seeing out there. I think that's the true public-private alliance of, you know, an industry focus group coming together saying, look, this is a problem out there. It's bad. You know, there's billions of credentials going around. You know, this this phishing kit, it's sophisticated and we need to impact this, and then for law enforcement to come together and go, yep, we agree. Now, what intelligence can you provide us? What intel can we get from you to help make our case? Then, you know, working to get that across the finish line and use, not only law enforcement techniques and powers with search warrants and things like that, but civil seizure orders like, you know, what Microsoft was doing as well. So really, it's just such a great case of doing it the right way, in my opinion. [ Music ]

Dave Bittner: Keith, from your experience in law enforcement and the times when you had a view into some of the backroom conversations that the adversaries were having, how much did someone else being taken down affect them? Like, how much were you able to mess with their heads, or did they feel impervious to it? Does a takedown make everybody else a little nervous?

Keith Mularski: Oh, it makes them paranoid. I mean, it makes them paranoid like crazy. Well, in today's world, the news cycles, what, a couple of weeks, though, so for two weeks, they just go utterly paranoid because they're wondering whether the hammer is going to drop on them and who's getting flipped? A lot of times they don't realize, you know, well, these cases take weeks and months. Even though there's a takedown, we may know about you, but we're not going to arrest you, arrest you in the next 7 to 10 days. Maybe we'll get you in two months when you travel to Thailand or something like that, but there is a lot of paranoia that goes through and talking about this person is a rat or this person's a fed, so there's a lot of distrust that goes down when these takedowns happen. [ Music ]

Dave Bittner: It's interesting to me because I feel as though it emphasizes that there is utility in talking about these takedowns and spreading the word about them. You know, like it's something -- I try to be fairly deliberate about on picking the coverage that we do over on the CyberWire, because I feel as though these takedowns, first of all, it's a win. It's good news, right, instead of the bad news you're hearing every day, but also, I want people who are either out there actively doing bad things or maybe just considering it to hear that you're not free and clear. People are actively out there looking for you, and as you say, the hammer might come down.

Keith Mularski: Absolutely, and, you know, just, like, looking at this, if I was putting my FBI hat back on and just seeing this takedown, seeing these reports that just came out about identity, some of the things that I'd be going after right now is how to make that impact on that identity space, is I'd be targeting the identity access brokers. You know, they're out there on the forums. They're selling access to certain companies. And that's where I'd be using my intelligence out there to run sources, get communications against these guys. And then, you know, that would be my next big takedown of going to Europol and, you know, once we get these guys identified, and then, now, maybe we arrest 10 of these identity access brokers, because then that's a major disruption in that space. If you can't buy that data, then they have to pivot to somewhere else.

Dave Bittner: The whole thing of cutting off the head of the snake.

Selena Larson: Yeah, absolutely, and because we think about it from the perspective of researchers or even within an organization, you only see the end result of an entire ecosystem of brokering, of tool providers, of money lending, money sourcing. There's just a lot of moving parts within an industry, and there's kind of like core services that enable a lot of this stuff. What you were saying, identity brokers is a perfect example. Identity and initial access brokers, they're the ones that are sort of facilitating a lot of other crime. They're the ones that are unlocking and opening the doors for people to go in and out, but they're kind of like the bouncers that are standing there saying, yes, you can come in; you can come in. They're kind of controlling all of that, and I think that, you know, kind of finding those individuals or those people -- on the flip side of it, like, if we're thinking like identity access, another great example would be sort of like traffic distributors. They're also kind of saying, like, yes, you can go here. You can go here. I'm allowing you to pass through this way. They're kind of like the crossing guards of web activity and like cybercriminal threats that are using their traffic. They're allowing all of this badness to sort of be moved through, and if you kind of chop off the people that are sort of providing that access, it makes it a lot harder for threat actors that are using those platforms or relying on those individuals to do their crimes because they have to kind of facilitate that themselves, right?

Keith Mularski: I love the comparison to a bouncer. I think that's going to be that's going to be the next operation name, "Operation Bouncer," [laughter] when you go after the identity access brokers, right? Yeah, great analogy. [ Music ]

Dave Bittner: How much is it true, Keith, that, you know, it makes more sense from law enforcement's point of view to go after the kingpins, rather than the, you know, the street dealers, right? '

Keith Mularski: Yeah, absolutely. I mean, at the end of the day, you want to cut off the head, right, because, you know, if the head is cut off, then the body dies or at least it's impacted, you know, with these organizations. So, you know, but then that's like the funny thing is on the underground, you know, once that attention is there, then the guys are like, I think I just want to lay in the background, but, hopefully, it's too late by then. [ Music ]

Dave Bittner: Can I invoke that which must not be named, which is crypto? [Laughter] Like, it seems to me, like, it is the -- it's the fuel, the ability to sling money around and independently of all of the fiat systems of all the nations of the world. Without that, this would be a lot harder.

Selena Larson: Yeah, a hundred percent. I gave a talk at a Sleuthcon a couple of years ago, and it was sort of like talking about the timeline of cybercrime in, you know, 2013, 2014, whenever Bitcoin was invented. I had in parentheses, "huge mistake." It's like -- [ Laughter ]

Dave Bittner: Right?

Selena Larson: I mean, yeah, you have all of this money just moving around, but the thing is, too, is like it's traceable. That's, I think, what criminals are learning or might not be aware of and will learn the hard way is that, you know, they can -- that activity can be observed on chain. If you're working and collaborating with, you know, good platforms who do know your customer, who are tracking and monitoring that, it can be very, very fruitful. Being able to sort of follow the money, so to speak, is hugely important in a lot of these resources, but, yeah, unfortunately, there are less ethical platforms for pretend money that are out there and certainly enable, if not underwrite, a lot of what's going on.

Dave Bittner: Where do you suppose we're headed here? I mean, you know, every now and then you hear somebody say we need to just totally rethink identity. We need to get rid of usernames and passwords and come up with what's next. That, to me, seems unrealistic at this point, but at the same time, we can't go on like this forever, or can we?

Keith Mularski: In the near term, we just have to take some basic precautions. You know, we need to make sure that that our tokens expire, that we don't have indefinite sessions that are out there, that the threat actors could just, you know, hijack that cookie and paste it into their browser and, you know, become you. I mean, I think we need to do that. You know, there's other some things that Microsoft has pushed out to really kind of have token protection in Microsoft 365 that will kind of prevent the replaying of stolen sessions. Then, you know, looking at token binding, as well, because I think, you know, we talk a lot about the passwords and all that, but I just -- I think that the token stealing is really just the, you know, the secret sauce out there, you know, because everybody's talking about passwords. A lot MFA does work, but it's not going to prevent against the token stealing. [ Music ]

Selena Larson: Yeah, and I think moving towards FIDO, right, the, you know, more physical key token authentication, I know that there's also some push into -- I made a joke about blood earlier. You know, you already have face identification, fingerprint identification, which, you know, opens up a whole can of privacy and potential, "What happens if that data gets leaked?" scenarios, of course. I do think, you know, that fundamentally, there's no escaping the fact that our identities are tied to who we are, and we will continue using services. We will continue using computers, requiring them for our work, and it's not that, you know, identity is ever going to go away. It makes sense why threat actors are targeting identity, because it is something that every single organization has and is fundamental to their business, because people are fundamental to their business. It's going to be a matter of how do we implement the principles of least privilege, enable proper conditional access policies, where we can provide physical tokens and make sure that we're monitoring and observing that attack path? Understanding and baselining the activity within an environment so we can observe deviations from known behavior when someone's identity is potentially compromised. I think, more than anything, it's the awareness piece for organizations to be, like, this is something that is very high priority for us that we should be paying attention to. Even within the researcher community, understanding that, look, like, identity isn't, like, just something that you can sort of shrug off or whatever, but these are critical pieces to the cybercriminal, to the hacking ecosystem. We should be paying a lot of attention to it to see how these threat actors work together, what some of these worst-case scenario compromises can be, and how can we sort of collaborate to both take them down, but also help to work to make sure organizations are protected as well as they can be to what the reality of the threat landscape is right now? [ Music ] We will be right back after this quick break. [ Music ] Well, I don't know if we have fully figured out who we are on this episode. We did not have any philosophical moments of recognition.

Keith Mularski: Next time. Next time.

Dave Bittner: Who am I?

Selena Larson: Who am I? Why are we the way we are is still the question that we will never be able to answer, but this was a lot of fun. Honestly, identity has just been something that I've thought about for so long. I'm so glad that we were able to come together and talk about it, hear from Keith about the dark web, what stuff that you're seeing and stuff like that. Dave, thank you so much for chatting to us, bringing that perspective from, like, what you're hearing from CISOs and what you're seeing in the landscape as well. This is a really fun conversation, and yeah, if any listeners have any stories of identity, how has identity impacted you or your organization, feel free to hit us up on LinkedIn. Reply to our videos. We'd love to hear. Thank you so much, and until next time, we'll see you then. And that's only malware in the building brought to you by N2K CyberWire. In a digital world where malware lurks in the shadows, we bring you the stories and strategies to stay one step ahead of the game. As your trusty digital sleuths, we're unraveling the mysteries of cybersecurity, always keeping the bad guys one step behind. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you ahead in the ever-evolving world of cybersecurity. If you like the show, please share a rating and review in your favorite podcast app. This episode was produced by Liz Stokes, mixing and sound design by Tré Hester, with original music by Elliot Peltzman. Our Executive Producer is Jennifer Eiben. Peter Kilpe is our Publisher. [ Music ] [ Typing ] [ Music ]