Special Editions 8.30.26
Ep 104 | 8.30.26

CyberWire Daily at 10: A decade of emerging threat actors and APTs.

Transcript

Maria Varmazis: Hello and welcome to this special edition. I'm Maria Varmazis, and in today's episode, I'm speaking with host of the "CyberWire Daily," Dave Bittner. We're continuing our celebration of 10 years of the "CyberWire Daily" in our chat today. Our topic of conversation for today are 10 years of emerging threat actors and APTs. Here's our chat. [ Music ] It is my distinct pleasure once again to welcome back the host of the "CyberWire Daily," the one and only Dave Bittner. Hello, Dave.

Dave Bittner: Hello. Good to be back.

Maria Varmazis: Thank you yet again for joining me as we continue to celebrate 10 years of the "CyberWire Daily." Can you believe it?

Dave Bittner: I still cannot. No, the time has flown by.

Maria Varmazis: Every time I say it, I ask you, can you believe it?

Dave Bittner: I still can't.

Maria Varmazis: You still can't believe it.

Dave Bittner: Maybe keep trying. One of these times, you'll convince me.

Maria Varmazis: Maybe by December, and -- because then by then it'll be 11 years of the "CyberWire Daily."

Dave Bittner: Right. Yeah.

Maria Varmazis: It'll be factually correct and not believe it. Anyway, so for our 10-year anniversary chat for today, we're going to talk about advanced persistent threats or APTs and threat actor groups, and this is a subject area that I think a lot of people -- they're fans. People have fandoms for some of these groups.

Dave Bittner: Yeah, fair.

Maria Varmazis: Which -- it's -- I don't know how else to describe it. Just there's almost a parasocial relationship in some of these situations with some of these groups. That is not the case for us. We're not fans of the work that they do because they're very harmful.

Dave Bittner: No, but we do have our favorites.

Maria Varmazis: We do. It's true because we're -- instead of talking about like a technical thing, we're talking about groups of people --

Dave Bittner: Right.

Maria Varmazis: -- and their motivations. So we can get into the psychology here. It's fascinating. So why don't I start with something high-level to start us off as for a question? So as you look back on the last 10 years, what do you think about changes in the threat actor landscape? Just super high-level.

Dave Bittner: Well, I mean, I think it was about 10 years ago that this public attribution of nation-state activity became a lot more common, and the APTs became recognizable brands rather than mysterious anonymous attackers. And I think we saw that governments and vendors and researchers all became more willing to publicly attribute these campaigns, and then we also saw the emergence of coordinated public advisories and international cooperation. So, you know, I -- to me, I -- my education on this is I was getting started on the CyberWire and getting up to speed and had the good fortune of having folks around me who knew a lot more than I did and had a lot more experience with these things. How could you not love the Bears, Fancy Bear, Cozy Bear, right?

Maria Varmazis: Yeah.

Dave Bittner: There's Russian APTs. What a great way -- it's kind of like learning your nursery rhymes, you know? But they're -- the three bear, you know, they're cuddly; they're soft. How dangerous could they possibly be?

Maria Varmazis: Right. And yet --

Dave Bittner: So that was my intro to all this.

Maria Varmazis: Yeah, I'm curious, is -- there -- the two really interesting things you mentioned. One is about how attribution changed from we don't do that to, oh, yeah, we're going to attribute now. So I wanted to ask you about that, and then I -- let's get into that one first because that, to me, over the last 10 years is just a seismic change. I remember when that was considered a super no-no. You just do not attribute. And now I think there's -- correct me if I'm wrong; you would know better than I would -- but it seems like there's no hesitation to do that now. What do you think? What's your read on that?

Dave Bittner: Well, some organizations still don't do attribution. I think -- I think like Dragos, you know, the industrial control or the industrial -- the organization that helps protect industrial control systems, they kind of have it as a policy that they don't do attribution. They don't think it matters. I guess what I wonder is how much of this is marketing, right? Because when we go to the RSA conference, or you know, and we see vendors who have big, giant, superhero-looking statues of the APTs, it becomes a way to help market your defenses against them. The adversary isn't a big, blurry, fuzzy blob on the other side of the world. No, that's Fancy Bear. No, that's, you know, so now we have the Blizzards and the, you know, the -- for a while, they were -- they had names based on their countries. You know, famously, the joke around the office was if there was ever a Canadian one, it would be Apologetic Beaver.

Maria Varmazis: Yeah. Yeah, you kind of understand from the InfoSec company marketing team point of view that they're probably relieved they don't have to try and market a CVE or, you know, some script kiddie's terrible leetspeak name. Like we have Fancy Bear or whatever we can use. For them the job is easier now.

Dave Bittner: There's still plenty of that. There's no shortage of leetspeak, and, you know, you've heard me complain --

Maria Varmazis: Yes, I have.

Dave Bittner: -- more than once that no one thought that someone in the world would have to pronounce this name when they named it, and unfortunately, you know, sometimes that burden falls on me to try to figure out how to pronounce a string of letters and numbers. I often come to you because you have -- don't I? You have more experience. You're --

Maria Varmazis: I was forged in those fires. It's true.

Dave Bittner: Yes, you're much better at decoding. Like, Maria, what do you think they're going at here?

Maria Varmazis: Well --

Dave Bittner: Most of the time, you get there before I do.

Maria Varmazis: My Spidey nerd sense is, you know, tingling --

Dave Bittner: Right.

Maria Varmazis: -- with this kind of thing.

Dave Bittner: For sure.

Maria Varmazis: Yeah, I mean, a lot of the times it wasn't meant to be read out loud. That's very true. It's just, it's just the fact somebody thought of it at 3 in the morning and was like, That sounds cool. Yeah, yeah.

Dave Bittner: I was -- I was doing an interview just earlier today about this this malware group called GodDamn. That's the name of the group, GodDamn.

Maria Varmazis: We're gonna -- we're gonna get in trouble. Someone's gonna yell at us for saying that on the show.

Dave Bittner: Well, when we mention them on the daily podcast because it's a family show, we refer to them as the GoshDarn ransomware group --

Maria Varmazis: Right.

Dave Bittner: -- which, you know, doesn't give them quite the street cred that they have with their real name, but I was -- the person I was talking with today, the researcher, we both agreed that maybe it's gotten to the point where these groups are just trying to punk us because they know we have to say these names out loud, and I wonder, you know, how soon are we going to just get the most -- I don't know -- disgusting, vulgar names just because somebody, again, somebody has to say it out loud.

Maria Varmazis: Yeah, somebody is going to be at a board meeting saying, "So we got pwned by this bleepity bleep group.

Dave Bittner: Right.

Maria Varmazis: And, you know, it's just yeah.

Dave Bittner: Yeah, yeah.

Maria Varmazis: Yeah. What do you think has led to not just attribution but also this coordinated naming and shaming? I mean, is this all coming from, you know, federal governments doing a fantastic job with the private sector? Like what do you attribute to this?

Dave Bittner: I think it's a big part of it. I think there's been better intelligence-sharing over the years between -- well, amongst government organizations, but also between the government and the private sector. I also think we've got much better confidence in attribution than we ever did. We know what to look for. We know the signs of one organization or another. So, I guess the kind of table stakes when it comes to attribution has gotten much more routine. And I think more than ever, people see strategic value in exposing these adversary operations publicly. They see it, and I don't think they always felt that way. I think it was spy versus spy trade craft. I won't say there was honor among thieves, but there were things that were not spoken of because you wanted to keep your cards close to your vest, I suspect.

Maria Varmazis: Yeah, yeah. No, I could see that, and I'm wondering if you noticed a shift over the last 10 years of when stories were less about really tactical level this specific thing has happened, this is what you need to do to mitigate versus there is a set of actions that is now happening based on this nation-state group or that sponsored group, or you know, we're talking much more strategically out loud now. Have you been noticing? You've sort of touched on that. I'm just wondering if you've been noticing that becoming -- I don't know if it's the majority of what you're seeing now or just more of it. I'm just curious if you've noticed a shift.

Dave Bittner: I would -- maybe a way to categorize it is that we have definitely seen the professionalization of APT operations over the past 10 years or so, and so, you know, it's an interesting question to ask: Have the attackers become dramatically better, or have they simply become more disciplined? I would say it's a bit of both, but a lot of the innovations have been organizational rather than purely technical. They're running like a business. They have marketing teams. They, you know, there's the hardcore coders who are getting this stuff done, but there's a whole business side to this now. They're teams. They're not just individuals, even just for the commercial ransomware operators. So I think mature software development practices, we're seeing those outside -- I'm sorry, mature software development practices, we're seeing those both inside and outside of espionage operations.

Maria Varmazis: I'm wondering as you reflect on how much of what you've been covering is basically espionage operations or touches on it, is it more or less than you would have anticipated, do you think when you started this?

Dave Bittner: Well, I think when I started this, we were just at the leading edge of ransomware really becoming a thing. And as you and I have talked about, I think on one of our previous episodes, we weren't sure that ransomware was going to become a thing. I thought -- many of the people I talked to thought that crypto mining was going to be the thing, and ransomware is going to fade away. And of course, that's not what happened. Ransomware went into high gear, and we got these just huge dollar amounts going after big organizations. So, I think, in terms of espionage, the rise of, again, professionalism, the rise of can we call it mob-like organizations with ransomware, the global growth of ransomware? I don't think espionage has gone away, and there's probably more espionage than ever because it's been accelerated by all the capabilities that we now have, and let's not talk about AI yet. But I just think this whole other industry popped up alongside of it that's able to use a lot of the same tools. Certainly, some of these folks who are doing ransomware came out of the espionage community, right? No, there's no doubt about that. So they kind of go side by side. We hear stories about people who are probably working for the government, but moonlighting on the side to make some extra money, and their government handlers are looking the other way. Let them do it. Use some of the tools. Use some of the trade craft. So yeah, there's definitely some blurriness there, but I don't think -- I don't think anything's shifted away from espionage. I just think they're both happening now, probably more than ever.

Maria Varmazis: Has it surprised you that these lines have been getting so blurry? You know, over the course of these years, as you've been covering things, I'm just wondering if I spoke to you 10 years ago, I would imagine a lot of -- I would imagine things like Patch Tuesday kind of coverage would have been, yeah, that's going to be the staple of what we do versus where we are now where we're talking a lot about more geopolitics more regularly. I mean, that that feels just so much more relevant now. The sophistication on certain levels, sometimes it feels like just calling it cybersecurity feels too minimal for the scope of really what's being discussed a lot of the time. It's much broader, but it's all relevant. Has that surprised you? It surprises me.

Dave Bittner: I think in some ways, one of the things I noticed early on, and again when I was getting up to speed, this was a question I asked my mentors pretty regularly, which is why are governments, including the U.S. government, so reticent to draw lines in the sand and say you will not cross this line in the cyber domain? We just don't really do that, and the most common answer I got was they don't want to draw lines because they don't want to have lines that they can't cross. They want to be able to use these tools on the offensive side. So if we keep everything fuzzy, it's harder to blame us for something or put a bullseye on our back for having used the same tools. So there -- are there things that I think we could all agree should be off the table? Ransomware on hospitals? Yeah, we're still not there yet. I have a good old, you know, colleague who's a cybersecurity researcher who famously says that there are certain bad actors who deserve having their front door breached by a highly precise missile.

Maria Varmazis: Yeah, yeah.

Dave Bittner: But we're not there yet. There's no line where if you cross this line, you will generate kinetic response. I think that's just the state of the game now. I'm not sure what it'll take to change that because, boy, we're seeing a lot of stuff all over the world these days, aren't we, when it comes to cyber capabilities crossing over into the real world and into the kinetic world, and I don't see that changing anytime soon. I guess, I -- well, I wonder if it will take some kind of a big event. Everybody talks about cyber Pearl Harbor, you know that kind of thing or a cyber 9/11. I'm not exactly sure what that would be or could be anymore. Everybody has their own ideas, but I guess what I'm getting to is that there's a lot of benefit. There's a lot of strategic benefit and ambiguity when you're a nation state, and so maybe it's a -- just a gentleman's agreement that this is how we're gonna run things. I don't know for sure, but that's something I wonder about.

Maria Varmazis: Yeah, I also wonder how much of this maybe was just happening behind the scenes, you know, out of the public eye, and essentially just the military space that, us civilians, we just weren't privy to, and now it's just more public, and how much -- I -- this is one of those things I will probably never know the answer to. I'm not part of that world, but I do wonder about it sometimes about maybe we just didn't know what was going on. Yeah, if you had to choose -- I don't know. This may feel like an unfair question. If you -- if you had to choose an APT or a threat actor group, something from the last 10 years that stands out in your mind as either the story had a lot of legs, as we might say in the industry, or it was -- it represented a huge shift, a paradigm shift, or something like that, I'm just curious if any stand out in your mind. Because there have been a lot, and heaven knows there's been a lot of fun names out there, but I'm curious if there's just the one that that stands out.

Dave Bittner: No, I mean again, I you know I like the Bears. Just I'm attracted to them just for aesthetic reasons, you know, Cozy Bear and Fancy Bear, and I think the long-time adversarial relationship we've had with the Russians and before that the Soviets and the Russian Bears and all that, I just find that attractive. I -- whether or not we would categorize them today as being at the top of the heap, I don't know. I think The Shadow Brokers were certainly -- they made their mark. You know, we did a whole parody of them. They were so well-known at the time. They've kind of faded away. I haven't seen much from them lately, but if you had a list of who were important groups like that, they certainly made a name for themselves. I don't know. It -- I mean, it seems to me part of what's happened with the naming is even that's gotten more fuzzy because every group now, you know, Microsoft and CrowdStrike, and they all want to have their own naming system be the standard.

Maria Varmazis: Yes, it's so aggravating that it becomes a chain of names.

Dave Bittner: It really is.

Maria Varmazis: Yeah.

Dave Bittner: Right, because now we say, you know, Fancy Bear, also known as, also known as, also known as. I kind of wish that maybe -- I don't know -- CISA were in charge of -- or NIST or somebody came up with a standard naming framework that everyone could agree to. I think Microsoft tried to do that. There's some logic behind their naming system, but their, you know, their business adversaries aren't going to take on Microsoft's naming system as a standard. They're just not going to do it.

Maria Varmazis: Right, it's a poisoned well.

Dave Bittner: This is -- yeah, there's just too much marketing rolled into these things now. So what's the old saying about, you know, if you get together and create a common standard, now you've got all the old standards plus the new common ones.

Maria Varmazis: Yep. My favorite XKCD comic right there.

Dave Bittner: There you go.

Maria Varmazis: Yeah, that's the one.

Dave Bittner: Yeah, yeah.

Maria Varmazis: I have it on my fridge at home because it -- just it's relevant. I know that's extremely nerdy, but it's just -- it's so relevant to everything.

Dave Bittner: I am sure many of our listeners are furiously nodding --

Maria Varmazis: Yeah, I'm sure.

Dave Bittner: -- their heads in agreement because they have the same one.

Maria Varmazis: Who doesn't have an XKCD comic on their fridge at home --

Dave Bittner: Right.

Maria Varmazis: -- honestly, right?

Dave Bittner: Tacked up to the wall or something, right? The break room, yeah, for sure, so.

Maria Varmazis: Yeah, well, Dave, I know I've been picking your brain about this. I'll leave you with one last question, and this is the looking-ahead question. I wonder what -- where you think the next threats in -- the next APTs, the next threat actor groups, where are those going to come from? Is it going to still be nation states, or are we moving past that or evolving into something worse?

Dave Bittner: Well, I think it's probably going to be more of the same for the next few years. I think -- I think the APTs are going to adapt to new technologies, and of course, the big new technology is agentic AI, so.

Maria Varmazis: Oh, I tried not to bring it up in that.

Dave Bittner: Oh, sorry. Wow, we were so close, so close --

Maria Varmazis: So close.

Dave Bittner: -- to the last question. I ruined it. And I think that's largely a velocity issue, right? Stuff's just going to come at us faster and more consistently with more vigor. So the defenders are going to have to run at a higher speed, but I think the defenders are going to continue to do what they do. They're going to improve the collaboration. They're going to improve the visibility, and hopefully these AI systems will do a better job of blocking and tackling along the way. But I think in the end, this contest between the attackers and the defenders, it's really about continuous adaptation, rather than decisive victories. It is cat and mouse, right? And I don't think there's -- I don't think -- it's not going to end anytime soon. I think the players around the world are going to continue this blend between espionage and statecraft and doing things for profit. I mean, look at North Korea, right? They have -- they have an incentive to make money. That's different from a lot of the other nation states, so they're kind of an edge case. But there are plenty of nations out there who could use a few more bucks in their coffers, and this is a pretty easy way to come at the big rich nations of the world. I think that blending is going to continue, yeah, yeah, yeah.

Maria Varmazis: Well, anything else you want to leave the audience with, Dave, or should we close out? I think just this -- I -- this notion that while the tools are evolving, that the fundamentals of espionage, of trust, and resilience, those are the things that continue to define the landscape, and I think that's what the future holds for us. I don't think that's going to change. So will it evolve? For sure. But I think we've got a pretty good idea where we're headed now when it comes to these things. I hope. I hope. We'll see, right? Here's hoping. Well, Dave Bittner, the host of the "Cyberwire Daily," thank you, as always, for talking with me, and again, congratulations on a wonderful 10 years.

Dave Bittner: No, thank you. The pleasure is mine, as always.

Maria Varmazis: Thanks for joining me today. We'll see you next time. [ Music ]