Only Malware in the Building 8.4.26
Ep 26 | 8.4.26

Class is in session—for cybercriminals.

Transcript

[ Music ]

Selena Larson: They finally finished the incident report.

Dave Bittner: Good. Did they identify the ransomware gangs?

Selena Larson: Every one of them.

Dave Bittner: Excellent. Who got into the network?

Selena Larson: Play.

Dave Bittner: I know they got into the network. I asked who?

Selena Larson: Play.

Dave Bittner: I don't want to play.

Selena Larson: You don't have to.

Dave Bittner: Then tell me who got in.

Selena Larson: Play.

Dave Bittner: You're doing it again.

Selena Larson: Doing what?

Dave Bittner: Telling me to play.

Selena Larson: I'm not telling you to play.

Dave Bittner: Then what are you telling me?

Selena Larson: Play got into the network.

Dave Bittner: Then say, "Play got into the network."

Selena Larson: I just did.

Dave Bittner: No, you just said, "Play."

Selena Larson: That's all I had to say. That's the name.

Dave Bittner: It's a terrible name.

Selena Larson: I didn't name them.

Dave Bittner: All right. Play got into the network. Then who encrypted the files?

Selena Larson: Maybe.

Dave Bittner: You don't know?

Selena Larson: I know.

Dave Bittner: Then tell me.

Selena Larson: Maybe.

Dave Bittner: That's what I'm asking.

Selena Larson: That's what I'm telling you.

Dave Bittner: You're guessing.

Selena Larson: I'm not guessing.

Dave Bittner: Then why do you keep saying, "Maybe?"

Selena Larson: Because Maybe encrypted the files.

Dave Bittner: You're certain?

Selena Larson: Absolutely.

Dave Bittner: Then stop saying, "Maybe." Let me write this down. Play got in. Maybe encrypted everything. Who demanded the ransom?

Selena Larson: SafePay.

Dave Bittner: There's no safe way to pay.

Selena Larson: I agree.

Dave Bittner: Then don't tell me to SafePay.

Selena Larson: I'm not telling you to SafePay.

Dave Bittner: You just did.

Selena Larson: No, SafePay sent the ransom note.

Dave Bittner: Then paying isn't safe.

Selena Larson: That's exactly right.

Dave Bittner: Then why are they called "SafePay?"

Selena Larson: Criminals aren't known for accurate branding.

Dave Bittner: Who claimed responsibility?

Selena Larson: Anonymous.

Dave Bittner: Nobody knows?

Selena Larson: Anonymous.

Dave Bittner: That's what I said?

Selena Larson: That's what I said.

Dave Bittner: Nobody knows who did it?

Selena Larson: Anonymous does.

Dave Bittner: If they're Anonymous, how do they know?

Selena Larson: Because they're Anonymous.

Dave Bittner: This business gives me a headache.

Selena Larson: Then the defenders arrived.

Dave Bittner: Finally, somebody with sensible names.

Selena Larson: Defender found Play.

Dave Bittner: Good.

Selena Larson: CrowdStrike stopped Maybe.

Dave Bittner: Excellent.

Selena Larson: Huntress tracked Anonymous.

Dave Bittner: Wonderful.

Selena Larson: Falcon spotted SafePay.

Dave Bittner: Terrific.

Selena Larson: SentinelOne blocked DragonForce.

Dave Bittner: Hold it.

Selena Larson: What's the matter now?

Dave Bittner: You mean there's another gang?

Selena Larson: DragonForce.

Dave Bittner: You never told me about DragonForce.

Selena Larson: You never asked.

Dave Bittner: I was still trying to figure out Play. Let me see if I've finally got this. Play got into the network. Maybe encrypted everything. SafePay demanded the ransom. Anonymous claimed responsibility. DragonForce showed up later. Defender found them. CrowdStrike stopped them. Huntress tracked them. Falcon spotted them. SentinelOne blocked them.

Selena Larson: Perfect.

Dave Bittner: That's the whole incident?

Selena Larson: Almost.

Dave Bittner: There's more?

Selena Larson: Then Mimikatz appeared.

Dave Bittner: Cats?

Selena Larson: Mimikatz.

Dave Bittner: Cats?

Selena Larson: Mimikatz.

Dave Bittner: First you had Play, then Maybe, then SafePay, then Anonymous, then DragonForce, now cats?

Selena Larson: Mimikatz.

Dave Bittner: You know something?

Selena Larson: What?

Dave Bittner: I miss the days when all you had to worry about was a virus.

Selena Larson: Those days are gone.

Dave Bittner: I can see that.

Selena Larson: Next week, we are doing phishing.

Dave Bittner: Good.

Selena Larson: The gangs are called Click, Reply, and Oops.

Dave Bittner: I'm staying home. [ Music ]

Selena Larson: Welcome to "Only Malware in the Building." I am your host, Selena Larson, Principal Threat Researcher at Proofpoint here with my co-host, Dave Bittner from the CyberWire. Dave, do you remember that feeling of summer being over? You're getting really excited. You're buying all your notebooks, and you're, like, "I'm going back to school."

Dave Bittner: Well, you're half right. I remember the feeling of summer being over, but I can't recall being excited to go back to school. I wished summer would go on forever.

Selena Larson: Well, maybe it's because I grew up in Arizona and I was ready to leave 1-million-degree weather for the confines of a schoolhouse, but --

Dave Bittner: Yeah, okay, fair enough.

Selena Larson: I do have fond memories of going back to school. One thing that I actually care a lot about in my role at Proofpoint and as a Threat Researcher and working with various organizations and friends and family is threat actors targeting schools. Students, whether that's K-12, university, advisors, teachers, supply chain impacting the schooling environments, and it really makes me mad when they go after them.

Dave Bittner: No, I agree. It seems like one of those things that should just be off limits, kind of like hospitals, and yet, it is not. [ Music ]

Selena Larson: It's interesting, because I know that there have been sort of like some conversations from ransomware threat actors. Should we have those targets that we won't go after? I think that hospitals are kind of higher on that list than schools for some reason, which I think is very, very interesting. As we know, when these threats target school systems, they can lead to financial losses. They can lead to impacts on the individual students themselves, whether that's psychological or financial. They can lead to their entire networks being taken down, schools disrupted, exams disrupted, kids having to work from home and having to stay home from school. Maybe they'll have a little bit of extra recess. But yeah, so today, I wanted to talk to you about -- as we go into back-to-school season, I wanted to talk to you about some of the threats that we have seen targeting all levels of education from K-12 all the way up to universities.

Dave Bittner: Yeah, let's do it. I just want to add for our listeners that Keith is off this episode, but he will be back. He had some things he had to take care of, so he could not join us today, but we look forward to having him back next time, so no worry; do not fret. Keith will return.

Selena Larson: He's taking an extended break, picking you up some dips.

Dave Bittner: There you go. I love it. I love it. [Laughter] [ Music ]

Selena Larson: Yeah, so I wanted to talk about, I think, the biggest, sort of, university -- sort of education targeted threat that we've seen recently is the May hack against Canvas, and it happened, if I'm recalling correctly, around finals time, exam time for many schools, because I had friends who were texting me that said that their kids couldn't take their tests.

Dave Bittner: Yes.

Selena Larson: They were having to reschedule them, or teachers were having to figure out how they could grade things differently. I don't know. Did you experience any impacts of this? Do you know anyone who had a falling out?

Dave Bittner: Well, I am much older than you, so I have grown children, which means that they went through the school system. It's interesting how much a central part of the school experience Canvas is. If your school system uses it -- and ours did. We're a public school system, and Canvas is kind of at the center of everything. It's how teachers assign homework. It's how test scores are reported. They do their grading directly into Canvas, so it's just kind of sitting there in the background as one of those, I don't know, key, fundamental, core tools that you don't realize you need until it's gone. In this case, my youngest son, who was just finishing up his first year of community college and they also used Canvas, and so, suddenly, you have no access to that. It wasn't as bad as, say, a high school, or a middle school, or an elementary school, where, you know, it could actually interrupt the day-to-day. I think a college is a little more flexible, but still, it's a hassle, especially when you have no idea how long it's going to take to get things back up and running.

Selena Larson: When I was in K-12, I didn't really have -- I mean, I had my computer lab, but we weren't really doing anything on our laptops or anything.

Dave Bittner: You had laptops. That's adorable. [Laughter]

Selena Larson: Well, I mean, not, like, school-assigned laptops like they have nowadays. I had -- well, I had a big bubble computer. I had the Macbook -- the big Mac, the bubble Mac.

Dave Bittner: Oh, the one that looked like a tooth, yeah.

Selena Larson: Yes, yes, yes, yes, I had that one for homework and stuff, but when I got to college, we did use sort of like an online platform, and I just remember it was, you know, not the best platform. I have to admit, I did get really excited when it would go down.

Dave Bittner: Because it meant you got the day off? [Laughter]

Selena Larson: I took some online classes, and if the software wasn't working, I would be, like, "Oh, no, I can't do geology today."

Dave Bittner: Fair enough.

Selena Larson: Yeah, taking geology online was a weird decision. I don't recommend it.

Dave Bittner: Virtual snow day.

Selena Larson: Yeah, so for those of you who might not be familiar with exactly what we're talking about, Canvas is a widely -- like Dave mentioned -- a widely used learning management system and the cybercriminal group called ShinyHunters, which was not part of our Abbott and Costello routine -- I don't know if that has a similar or legitimate word next to it, but they claimed responsibility for it. They tried to extort the company, threatened to release data. They reportedly gained access through a weakness associated with Canvas's Free for Teacher Program, which shared infrastructure with institutional Canvas environments. Some of the data that was exposed: names, email addresses, student ID numbers, messages exchanged between people that were using the platform. There wasn't, according to the company, they found no evidence that passwords, dates of birth, government identifiers, additional, sort of, financial information, or more -- I don't want to say more important information because all information is important. Some of that sensitive data wasn't necessarily impacted, but they stole information affecting roughly 275 million users across around 9,000 institutions.

Dave Bittner: Yeah, and I think maybe something worth noting here is that when you say, "not a lot of sensitive information," my understanding is something that was included, as you mentioned, was communications among teachers and communications between teachers and students. Think about you have students who have special needs. You have students who are having emotional struggles. You have students who are having discipline issues, all of those things that are very sensitive and require privacy and trust.

Selena Larson: Yeah, for sure. I mean, that stuff is really sensitive. It reminds me of, remember those ransomware actors that leaked those sensitive photos of doctor -- or plastic surgery patients?

Dave Bittner: Yes.

Selena Larson: It's just, like, just so cruel. Why would you -- because it's not -- I mean, that kind of thing isn't necessarily, like, profitable for a threat actor. Like, if you're stealing financial information and credit card data, I can -- okay, you can use it that way, but that type of information is sensitive back and forth, no one needs to see how bad my grades were in college. You know, like I'm --

Dave Bittner: [Laughter] Right.

Selena Larson: I'm begging my professors.

Dave Bittner: I mean, for the threat actors, don't you think it's sort of proving that you better not mess with us, you better pay the ransom or this, we're going to make an example out of you?

Selena Larson: For sure, and I think that that's part of the whole MO of ransomware threat actors is they want you to be scared. I think that that's something that is really important from any sort of criminal activity is that when they're targeting somebody, whether it's online or whether it's, you know, walking down the street, they give you this idea of fear, and when you're afraid, you make, maybe, different decisions than you would if you're thinking clearly. For example, paying ransom, and I think that that's something that is certainly controversial. I know you had some folks come on the CyberWire to talk about, do we pay? Do we not pay? How do we navigate that? That's, you know, part of the reason they try and make you afraid is because they want you to pay the money to prevent whatever from happening. I think it's interesting because in this particular case, it was, basically, a supply chain attack where a major infrastructure provider had these sort of follow-on consequences for all of their customers. It's like, well, how do we have to navigate that? How can we deal with the fallout in that way? Some weren't necessarily impacted that much, and some were, and then there's this discussion of the ransomware and how do we pay it to sort of try and solve these problems? I think it's an interesting case. I think it was handled really well. I think the notifications that were going out, the communications about it, it was very transparent. Certainly, a lot of those that were involved had a really hard time dealing with this. I do think it's interesting if we're talking about threats to schools and K-12 and universities, to think about all of the sort of interconnected software and services that are being used every day, whether that's kids on your laptop doing their homework or taking tests or playing trivia in school, in classrooms, you know, it's all digital now, which it hasn't been in the past.

Dave Bittner: Yeah, and also, it's worth mentioning that schools, especially public schools, aren't known for having big wheelbarrows full of cash to throw at problems like this. They are perpetually underfunded, and that includes the folks who are trying to defend them against these attackers. It makes them, I suppose, a more-ripe target because they're less likely to have robust defenses compared to, say, a bank or someone in the private sector, yet here they are with this valuable information.

Selena Larson: Well, and it also feels a little bit worse, too, because I think it's -- these are kids, right? I don't know. I don't know. Maybe in my head, I'm just like, oh, whatever, adults. Who cares?

Dave Bittner: [Laughter] Right.

Selena Larson: Your stuff is out there anyway --

Dave Bittner: They got what's coming to them, right?

Selena Larson: -- but young people, your whole future is ahead of you being impacted by such a thing. It's so interesting because I wonder -- I don't know. Dave, did any of your kids experience things like cyberattacks when they were in school? I think about how, like my sister, for example, worked in healthcare and ransomware just became this sort of like, yeah, well, we got another ransomware attack. I think she experienced, like, four different ransomware attacks at different locations when she was working in the healthcare facility. She was just -- she got to the point where she was like, ah, well, it's ransomware. I'm wondering, like, are kids these days getting their schoolwork disrupted by cybercrime? Is that something that they're just like, "Ah, well, here we go again?"

Dave Bittner: I mean, I think so. I think it's just part of their world and certainly much more than it was mine and to a lesser extent yours. I remember a lot of focus on things like cyberbullying, those kinds of things. I don't remember any actual ransomware attacks while my kids were in grade school. Again, this Canvas thing, my son was just starting college. That was really the first big one that I can recall, but I think having had kids go through school, there's nothing that is more powerful and instinct than a parent to protect their child, so imagine you're the school administrators and suddenly something out of your control has popped up that puts something about the children at jeopardy, in this case, their personal information, and parents today are just set on their children having the best possible path. If something's going to get in the way of that, they are going to bulldoze their way through it. My point is that I think there's a tremendous amount of pressure when something like this drops that it has to be taken care of quickly. That's just the nature of how -- the relationship between parents, students, and the administrations these days. That's my take. [ Music ]

Selena Larson: Do you think if we had more PTA parents running cybersecurity programs that we would have less cybercrime?

Dave Bittner: If we had more PTA parent --

Selena Larson: They will bulldoze all the criminals to the ground.

Dave Bittner: -- more volunteers? I mean, you know, that's the thing, are we at the point where we need to have bake sales to pay for a multifactor authentication?

Selena Larson: [Laughter] Oh, geez.

Dave Bittner: [Laughter] Right?

Selena Larson: Yeah, that's a sad thought. Well, on that note, actually talking of resources, we would be remiss if we didn't highlight the available resources that were out there. CISA has a great resources page for cybersecurity and K-12 education. I know the REN-ISAC has, also, some fantastic resources out there. I do think that the community, in general, knows that it is a problem, and I do think that there are resources, like, free and low-cost resources, that are available out there for various communities to, hopefully, not have to run a bake sale or MFA. It's definitely something that it's, yeah, a hard problem to solve.

Dave Bittner: Yeah, and I think around here, most of the kids -- well, the schools issue Chromebooks. I think that puts them way ahead of the game just to start because you have this device where things are not being stored locally overall. You have Google's defenses to back you up, and so I think that's a pretty good place to be out of the gate. It's not perfect. Nothing is, but it's better than when kids were lugging around Windows machines or Macs. Where everything was stored on that device, if the kid drops it in a puddle and the hard drive's gone, and there goes your whole year's worth of work, right? It's much more robust, I think, than it used to be.

Selena Larson: Yeah, that's true. I think it's getting better, and I think awareness is growing. I think there are resources that are available, so hopefully, as we go into this school year, we won't have another major ransomware attack like we have seen previously. We'll keep our fingers crossed on that, Dave.

Dave Bittner: Good luck with that. [ Music ]

Selena Larson: Stick around after the break. [ Music ] You did know, talking of cyberbullying and threats, I was recently reading an article that came out in The Guardian this week about experts warning about the rise in sadistic online exploitation of vulnerable children. I just wanted to highlight for listeners that there are some really sad cases of this happening and kids who are on online platforms, whether they're chat apps or streaming services or video games even, there's a rise in some of these types of recruitment, and yeah, it's kind of scary to me. I think this is a threat to school and to young people. I kind of wanted to throw it into our discussion because I think it's something that is definitely increasing. The National Center for Missing and Exploited Children received more than 3,000 reports of -- and I'm sorry to have to say this, but -- sadistic online exploitation worldwide in 2025, which was 125% increase the previous year.

Dave Bittner: I'm afraid to ask you to explain what that means.

Selena Larson: Yeah, it's just really terrible things. It's explicit imagery. It's really self-harm. It's just, yeah, it's a lot of things that you don't ever, ever want your kids to get roped into. Yeah, and they say that to recruit their victims, perpetrators engage with video games popular with children, such as Roblox or Minecraft. Yeah, it's definitely something that is targeting a lot of these youths, and hopefully, as more awareness is discussed about it, I hope it can be something that we can definitely nip that in the bud.

Dave Bittner: Yeah, well, I had these conversations with my kids about this sort of thing, and I would check in with them regularly about it. They were kind of matter-of-fact about it, because they were into video games and all the normal things that young kids are into. Certainly, they're living in online world these days. For my kids anyway, it was sort of like, it was a nuisance; it was no big deal. They were like, yeah, you'll be playing a video game, and some creeper will come along, but you just block them and you get on with it, which was interesting for me in a couple of ways, which was first of all, how normal it is for it to just happen, right? "Yeah, a creeper comes along." Like, what do you mean, "A creeper comes along?"

Selena Larson: Whoa.

Dave Bittner: Yeah, no. Hey, stop. Hold on, pause, tell me more, but I think that emphasizes the importance of awareness. I think it emphasizes the importance of having open conversation with your kids, making sure that they know that they can come to you for anything, knowing what the boundaries are and the guardrails and all those kinds of things. We were all young once, and we did stupid things, and it's a common thing for, certainly, folks in my generation to say, "I'm so glad we didn't have phones and cameras when we were that age, so we didn't document all the dumb things that we did when we were kids."

Selena Larson: Yeah, yeah.

Dave Bittner: I don't know about you.

Selena Larson: I actually almost wish that -- just, like, what would happen if there was just a week where everyone just put their phones away, if we just sort of, like, logged off for an extended period of time and had to interact with the real world and real human beings and our friends and family and coffee shops and libraries and the park and things? I think that we could just have like a mental digital reset where we can throw all that stuff in the garbage and taking a break and extended time away. I actually totally, I guess, kind of related, but tangent for my own mental health, I've stopped using social media as much, and I've deleted social media apps from my phone. I'd really felt myself kind of getting sucked into scrolling. It wasn't really good for me, and it wasn't good for my mental health. I made this concerted decision because even those little, like, iPhone, you can set 30-minute limits or whatever, and you just ignore those, you know? It's like, okay, well, 15 more minutes, like 50 times a day.

Dave Bittner: Right, right, so you lie to yourself and you say, "I'll just do five more minutes," and then five minutes, "Oh, I'll just do five more minutes."

Selena Larson: Just five more minutes.

Dave Bittner: Yeah, we've all been there.

Selena Larson: Right, and it's -- honestly, it's very much improved my overall experience with my phone and with the world. I think that I definitely recommend that. If people are feeling that pull, just kind of take a break, take a step away because I -- yeah, I didn't really grow up with -- certainly not Snapchat or Instagram, which is, you know, a hotbed of some of this sort of sextortion and recruitment that we see with teens as well. So yeah, I just wanted to flag that as an interesting article that I was reading about. This was in the Guardian just this week. So yeah, it's definitely something I will be sharing with people that I know who have kids.

Dave Bittner: Yeah, no, like I said, I think the most important thing is just having those lines of communication open and letting your kids know that if something bad happens, you know, they're not going to be in trouble for anything they did. That they can come to you, and you'll figure it out together. I think, also, one thing we didn't touch on was all of the stories we've been seeing about kids being, I'll say, "led astray" by chatbots, by AI chatbots and the suicides that we've seen where chatbots have evidently, allegedly, evidently, encouraged kids to harm themselves because they're so eager to please. That's tragic. I saw one just this week where someone who had -- someone was a recovering alcoholic and had slipped up and had a drink and had a relationship with the chatbot. The chatbot encouraged this person to drink every day, that this was the best path to go forward. Start your day -- like, it was giving this person the worst possible advice it could, but this person is already in a very touchy, sensitive, terrible mental headspace, and you have this bot who knows how to flatter you and make you feel good and you've developed a trusting relationship with, and it's giving you all the worst advice. That is very scary to me, not just with kids, but with everyone. I can see the good side to it. I could see it being helpful. There are plenty of people out there who are feeling lonely or isolated and maybe it's good for their mental health, but I just don't feel like we have -- we've been able to put the proper guardrails on these things yet to make sure that they're doing no harm.

Selena Larson: Yeah, 100%, 100%. I feel like every week there's just some new lawsuit about bad behavior from various AI chatbots that, unfortunately, have led people, "astray" is a good way of saying it, but yeah, it's really the families that are left to try and get some answers. It's quite sad actually. [ Music ]

Dave Bittner: The word I saw someone use this week was "hypnotic." It's sort of these devices, you were talking about the infinite scrolling, they kind of cast a spell on you, and I saw someone else describe it as, "It's online gambling with your time."

Selena Larson: Yes, wait, yeah, that's a great description.

Dave Bittner: Right?

Selena Larson: Yeah, that's really good.

Dave Bittner: Is it good, yeah?

Selena Larson: Yeah, no, I mean, well, that's like a whole other, oh, my gosh, that's a whole other podcast talking about the Connection Markets and things.

Dave Bittner: Right, well, that's another show.

Selena Larson: Yeah. We'll get there. Yes, yeah, no, I think it's definitely important to highlight that, but I don't want us to just be talking about sad things the whole time. I mean, cybercrime is sad, but there are some threat actors who are targeting universities to do something just a little bit more typical crime that we can feel a little bit better about.

Dave Bittner: Happy crime?

Selena Larson: [Laughter] I don't know about "happy crime," it's job scams.

Dave Bittner: We're talking about a Robin Hood situation here?

Selena Larson: I would love to meet a Robin Hood cybercriminal.

Dave Bittner: Oh, my gosh, you know, like, why hasn't someone wiped out all the student loans?

Selena Larson: Yes, right, yeah, where are you? Come on, guys.

Dave Bittner: Erase my mortgage, you know, my car loan, anything. [Laughter]

Selena Larson: Yes, well, like all of this, like, you know, medical debt, credit card debt --

Dave Bittner: You could do some good in the world.

Selena Larson: Yes, you can do some real good in the world. You know, every so often I see these memes -- well, not anymore because I'm not on social, but before I quit social, I would see these memes about, oh, this so-and-so guy hacked this and got rid of all this, you know, medical debt or whatever, like being shared as, like, legitimate news stories. I'd always have to tell my friends who posted it, that's not real. [ Laughter ] I appreciate that you're manifesting, but as a cybersecurity practitioner, I can tell you this is fake news.

Dave Bittner: Yeah, yeah.

Selena Larson: I do think that one thing that we see quite frequently targeting, especially universities, is job fraud and job scams. I think for a few reasons, one, students are very open to sort of part-time work. They're very open to working digitally. Sometimes if it's an international student, they might have not English as their first language. They might not like sort of pick up on some of the red flags or trying to understand how, you know, jobs work in the different locations that they're, you know, going to school in. We see a lot of threat actors that are conducting, essentially, advanced fee fraud. They'll offer somebody a job, say that they're going to send them a check, but I just need a thousand dollars to cover all the technical equipment that's required for this job, but I'm sending you a check to pay for it. Then, of course, the students are out a grand. Yeah, and I think it's interesting because we see it happening pretty frequently. It is quite -- does seem to be targeted more towards higher education, and oftentimes, they're abusing, like, legitimate brands that we'll see. Sometimes it's like, "Oh, we want you to be a social media model," things that would actually appeal, you know, to just to students. Sometimes it's more, you know, bioscience type of jobs. Sometimes it's social jobs. Sometimes it's nonprofit work, things like that, and it's definitely appealing to younger people who might not be looking for high-paid work and wouldn't necessarily be suspicious of part-time job opportunities like that.

Dave Bittner: Right, right. At the same time, they're some of the folks who are least in a position to lose that kind of money, yeah.

Selena Larson: Yep. I think back to when I was in college, if someone had come with an online job that seemed maybe a little too good to be true, I'd be like, well, maybe I'll do it. I have no money in my bank account. [ Laughter ] Let's just see where this goes, yeah.

Dave Bittner: Right, right, what's the worst that could happen?

Selena Larson: Yes, unfortunately, losing thousands of dollars, yes.

Dave Bittner: Right, and that -- how do you gain wisdom? By making mistakes.

Selena Larson: What is college, if not making as many mistakes as you can in four to six years or however long it takes you to go to college.

Dave Bittner: Yeah, but at the same time, I think it's important that we remind folks that falling victim to a scam is not a moral failing, right? You're not a bad person. You're not dumb. Everybody has something that they would fall for. Every single one of us has something that we are so interested in that if someone came to us with an offer related to that, it would short circuit all of our skeptical thinking. We'd be all in with this opportunity, and before we knew it, before we knew it was a scam, we'd be so far down the road, it would be too late. Everybody has something like that, so -- [ Music ]

Selena Larson: I think, too, especially when it comes to job scams, they're definitely not unique to universities and higher education. Those advanced fee fraud ones do tend to seem to favor that specific target market, target audience, but we have things that are things like malware or credential phishing that get a little bit more sophisticated that are targeting people that currently have jobs. They're like, "Hey, would you like to interview for this, you know, VP of sales role? Click here to access this Zoom meeting." Then it leads to the installation of malware. Remote monitoring and management tools is something that we've seen distributed quite a bit through job offers, other types of malware from various different threat actors, whether it's espionage threat actors doing types of job fraud activity -- North Korea comes to mind, for example -- or, you know, the ransomware threat actors that are leading with initial access brokers that are doing this sort of job fraud hiring types of scams, those are a little bit more sophisticated. They're a little bit more believable, and they do target people that would have more money and access to enterprise networks. That's also something to keep in mind, and especially now, as certainly within our industry, across the board, a lot of people are looking for work. I do think that threat actors are pivoting to this theme because it's working on a larger number of people. This is my theory.

Dave Bittner: I'll share one that we actually reported on today in the CyberWire, which is -- and I believe this is a North Korean operation, where they would set up a job interview, an online, like, a Zoom meeting, but they would make it so that it seemed as though your video wasn't working or your audio wasn't working. Then they would say to you, well, we're going to ask you to just run this verification tool that'll let us know what your video setup is or your audio setup. We're going to send you this file that we need you to run and that should fix things, and then we can move on with the interview. Well, of course, it's malware, and they're getting in your system to steal your stuff, but you can imagine somebody in that situation, you don't want to say no to someone who you're hoping to get a job through. You're much more likely to do what they ask you to do.

Selena Larson: Absolutely. It's a very effective social engineering technique, for sure. I think, yeah, and you know, like I mentioned, we're seeing it more often, I think from a lot of different threat actors, so I wonder if it tends to be more effective, social engineering, more than others as well.

Dave Bittner: Let me ask you this: Did you have a terrible job in college? Did you have any really bad jobs to get your way through school?

Selena Larson: Did I have any bad jobs? Well, I mean, there were some jobs that I didn't really like. [ Laughter ] I didn't fully enjoy it.

Dave Bittner: Did you wait tables? Did you do that?

Selena Larson: Oh, I was for sure -- I was a waitress. I was actually, but honestly, a waitress was my favorite job of all time.

Dave Bittner: Okay.

Selena Larson: I love being a waitress.

Dave Bittner: I could see you kill it as a waitress.

Selena Larson: I loved it. It was so fun. It was my favorite job. In fact, I am still LinkedIn friends with a woman who was one of my regulars at the job that I had in high school. Actually, I started as a hostess and then I worked at the same restaurant forever. She was my regular for, like, the entire time, six years, seven years while I was at the restaurant, and I'm still LinkedIn friends with her.

Dave Bittner: I was a singing waiter in college. Yeah, you know, those, like, lunch and dinner cruise boats that go out. You know? Yeah.

Selena Larson: Yes.

Dave Bittner: This was one of those out of the Baltimore Inner Harbor. Through college, I worked on one of those doing lunch and dinner cruises, and we put on a little show every night.

Selena Larson: Oh, my God. What was the show?

Dave Bittner: It was, like, a little musical review of Broadway tunes and some pop tunes and things like that. We had a little live band, and it was great fun for someone 19, 20 years old. It didn't get much better than that. I waited tables, got to sing some songs, and go out to sea every night, you know, for a couple hours.

Selena Larson: That sounds so fun.

Dave Bittner: [Laughter] It was a lot of fun. The contrast to that, the worst job I ever had in college was I did telephone survey interviews with elderly people.

Selena Larson: Oh, yeah, oh, oh.

Dave Bittner: It was -- they had a call center on campus. Like, somebody had gotten a grant, and I needed some money, so I went in there, and they discovered that because I was capable, even back then, of stringing two words together in a competent way, they were just jumped on me to take this job, so I did. It was an hour-long interview. You're calling people in very poor parts of the country and asking them questions about their wellbeing. It was -- it just was soul crushing.

Selena Larson: Heartbreaking, yeah.

Dave Bittner: Just, I remember it was the only time in my life when I quit a job by just not showing up again. Just one day, it was time for me to leave my dorm and walk to the job, and I just sat there, like, staring at the wall going, "I can't do it. Can't do it. Can't do it." and I didn't. Like, a week later, they called me. They were, like, "Are you coming back?" I said, "No." They said, "Okay. We figured."

Selena Larson: Yeah, yeah, it sounds like that wasn't the first time that's happened.

Dave Bittner: No, no, they got that a lot. They got that a lot.

Selena Larson: Yikes. Well, but actually what this is making me think of is we should do "Only Malware in the Building Musical Review."

Dave Bittner: Oh, I like the sound of that.

Selena Larson: We did "Hot Ones," so I think we need to make a music video.

Dave Bittner: Right, sure.

Selena Larson: I don't know if I can sing. I can do Disney voices, like the, you know, Zazu. I can do his parts where they're speaking.

Dave Bittner: Yes.

Selena Larson: You know, speak singing, I'm really good at that.

Dave Bittner: Right, a patter song, that's referred to as like "Trouble from the Music Man." You know, that's a patter song. It's kind of like the musical theater version of rap.

Selena Larson: Yes. Yes.

Dave Bittner: Musical theater came up with it first, yeah.

Selena Larson: Yeah, well, sign me up for that.

Dave Bittner: All right. Well, we'll check in with producer Liz and see, but maybe that's a good idea for a future episode.

Selena Larson: Yeah.

Dave Bittner: What could possibly go wrong?

Selena Larson: Well, yeah, nothing, actually. Look, if our "Hot Ones" episode was any idea of what it could be, I have big dreams, and I think it could work. [ Music ] Before we wrap up, I did want to highlight one more university-targeted -- interesting university-targeted threat, and it kind of ties into, actually, a broader trend that we're seeing from the espionage threat landscape. You mentioned North Korea, so speaking of espionage, a spy is going to spy, we recently published some research about a China-aligned espionage threat actor that was targeting Roundcube mail servers belonging to physics and engineering departments of U.S. and Canadian universities. So basically, it's kind of an interesting technique because it's considered a half-click exploit where there's something that's actually in the body of the email that only really requires the target to open the email in the mail client for the actor to exploit the vulnerability and achieve access to the mail servers.

Dave Bittner: You call that a "half-click exploit?"

Selena Larson: A half-click exploit, and we have some more research coming out about this type of threat in the near future, so maybe we can talk about it on a forthcoming episode --

Dave Bittner: Okay.

Selena Larson: -- but what's really interesting is, basically, you don't need to click anything. You don't need to download an attachment or click a link to get to a phishing website. It's exploiting vulnerabilities in web mail servers specifically. In this case, it was a Roundcube mail server, and they were specifically targeting, again, these universities, university departments that are potentially interested in things like physics or sciences, things like that in North America. When a threat actor is able to compromise a mail server, as you might imagine, there would be a lot of interesting, juicy information and potentially espionage-rich data on such things that could potentially be used to then pivot within an environment and gain additional access. Yeah, it's quite interesting. This overall campaign was exploiting a couple of vulnerabilities in Roundcube, but they were known. They were end-day vulnerabilities, and it was a couple of 2024 CVEs, so they were a little bit outdated. It just serves as a really, really good reminder for everyone, really, but certainly universities, K-12 education, but those who might be of interest, certainly, to espionage threat actors that are increasingly trying to exploit web mail servers to make sure those pieces of software, all your mail servers, are up to date.

Dave Bittner: Just so we're clear here, what you're saying is that this was a known vulnerability that had been patched, but people had not gotten around to installing the patch, and that's what made them vulnerable?

Selena Larson: Yeah, unfortunately, I mean, I think there's been a lot of discussion about things like Mythos and all of the AI tools that are going to make zero-day discovery so much easier for threat actors and everyone's going to be able to get their hands on 0-day. Unfortunately, the reality of what we're seeing right now is that old vulnerabilities still work. Those end-day vulnerabilities can be very, very beneficial depending on where they are in your environment, how fast you can patch them, if you remember that they're there, which is an important thing. Yeah, so in this particular case, they were exploiting -- and one of the vulnerabilities was CVE-2024-42009, and essentially, this would allow a threat actor to have JavaScript hidden within the HTML body of an email, and when that was opened, would kick off the overall attack chain.

Dave Bittner: Wow.

Selena Larson: Yeah, it's interesting, and it's an interesting trend that we're seeing from these adversaries targeting web mail servers.

Dave Bittner: I mean, is this the kind of thing, similar to how we have ad blockers in our browsers, can we install protections on our email clients to root out these things within our email?

Selena Larson: Yeah, so web mail providers are actually pretty good about staying on top of such things, and I definitely recommend patching as soon as they are up to date. Using a secure email gateway is also something that can be very beneficial as well. Having email security providers that add a little additional layer of protection, as well, but really, the most important thing is to make sure that you are maintaining your updates against such CVEs.

Dave Bittner: Yeah, yeah, yeah. All right. Well, interesting stuff. [ Music ]

Selena Larson: We will be right back after this quick break. [ Music ] Any last fond memories that you would like to share of your university time, Dave?

Dave Bittner: Oh, my goodness. You know, I enjoyed college. I went to the University of Maryland, so not far from home, a big, big, big school, and I had a really good university experience. It was not extreme. I did not join a fraternity. I did not do any of the -- it wasn't a frat house or, what's the movie --

Selena Larson: Animal House?

Dave Bittner: It wasn't Animal House. Thank you. It wasn't an Animal House situation. I had good roommates. I had good friends. I had a good time. It's funny. I was just telling my youngest son, who, as I mentioned earlier, is in his first year of college, and so he's starting off in community college. He's our practical one. He's starting off in community college, but he is planning on going to a state school after that, and so chances are, he will live on campus. The conversation we were having was, I said to him, this is the time in your life when you're going to have the opportunity to have all of the freedom and none of the responsibility, so take that. Enjoy that because that doesn't happen. Maybe when you retire, you get to be in that place if you're lucky, but don't let this slip by if you're able to get this opportunity, and I feel like that's what my college experience was like.

Selena Larson: That's great.

Dave Bittner: Yeah, I had a good time.

Selena Larson: That's so nice. I also really loved college, probably surprising nobody, but I went to Arizona State, and boy, did I embrace the no responsibility time.

Dave Bittner: Oh, I see. I see.

Selena Larson: But you know what, Dave? I was almost -- I went to school. I wanted to go to school for dance, dance education.

Dave Bittner: Selena?

Selena Larson: Yeah?

Dave Bittner: I started college as a music education major.

Selena Larson: Are we the same?

Dave Bittner: We're two sides of a coin. [ Laughter ] Shall we hold hands? Can we hold hands and sing, "We Are the World?"

Selena Larson: I love this. This is such a fun fact. I know, and so now I'm in cyber, so how did that happen? Who knows?

Dave Bittner: Same.

Selena Larson: How did we get to where we're going? You really are all over.

Dave Bittner: Well, how many creative people ended up in cyber, right? Like, a lot of the same skills the creative arts encourage, improvisation, problem solving, working together, all these things serve you well in a career in cyber, so I just feel I've been lucky.

Selena Larson: Yeah, me too, and that's a terrific note to end on. Embrace the arts as you embrace cyber.

Dave Bittner: There you go.

Selena Larson: To anyone who is going to school, going back to school, has kids going to school, or is thinking about going to school, just remember all of these little tips and tricks that we talked about. If there's anything that you need to share, you feel you need to share with friends and family, if you're an IT administrator, check out those stories that we mentioned. Yeah, best of luck, class of 20- -- what are we, 2027?

Dave Bittner: Oh, I don't want to think about it.

Selena Larson: "It's been 84 years."

Dave Bittner: Yeah, exactly, oh, I feel like that woman on the Titanic.

Selena Larson: Exactly.

Dave Bittner: All right. Be careful out there. Thanks, Selena. I'll see you next time.

Selena Larson: See you, Dave, and that's "Only Malware in the Building," brought to you by N2K CyberWire. In a digital world where malware lurks in the shadows, we bring you the stories and strategies to stay one step ahead of the game. As your trusted digital sleuths, we're unraveling the mysteries of cybersecurity, always keeping the bad guys one step behind. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you ahead in the ever-evolving world of cybersecurity. If you like the show, please share a rating and review in your favorite podcast app. This episode was produced by Liz Stokes, mixing and sound design by Tré Hester, with original music by Elliott Peltzman. Our Executive Producer is Jennifer Eiben. Peter Kilpe is our publisher. [ Music ]