Showing posts with label apt. Show all posts
Showing posts with label apt. Show all posts

Thursday, April 27, 2023

Advanced Persistent Teens

from here and here

So I had kind of gotten the impression that the age of children being a significant online threat was a thing of the past. With all the talk about the commercialization and professionalization of the threat landscape I thought that meant the kids in the past had grown up and professionalized while the next generation of kids did something else entirely. Apparently I was wrong. Kids are apparently still a significant part of the threat landscape.

I guess I really shouldn't be surprised, though. All the intellectual and social rewards that drew kids to it in the past are still there now, and now there's the addition of financial rewards too. There's little reason for the next generation of kids to go elsewhere when what they want is right there.

Tuesday, September 27, 2022

I'm An Advanced Persistent Threat shirt


Product Page

I can't help but think that this is not something an APT would actually wear (to paraphrase Ser Davos Seaworth, if you're a famous APT you're not doing it right), but just as there are shirts that say hacker on them that get worn by people who aren't hackers, so too with the advanced persistent threats.

Wednesday, January 19, 2022

Someone's getting fired

from here

I know infosec pros tend to preach forgiveness for security fuck-ups by your users, but I don't think the same holds true for nation-state attackers. Someone inside India's Patchwork threat group infecting themselves with a remote access trojan was a pretty serious operational security failure and it's literally their job not to fuck that kind of stuff up.

Wednesday, October 20, 2021

They each could use a taste of their own medicine

from here and here

Both Russia and China have a reputation for hacking others. It's nice to see one or both of them on the receiving end for a change

Thursday, April 29, 2021

Can't let powerline munching squirrels have all the fun

from here and here

If your critical infrastructure is disrupted or damaged it MIGHT be a nation state attacking you, or it might just be one toothy boi.

Friday, March 12, 2021

Imagine being that desperate for antivirus

from here

Do they have difficulty getting security software in China? It actually seems quite amazing that an advanced persistent threat group would have to resort to such means to get the software. Couldn't they just get it from a torrent site or something?

Wednesday, March 10, 2021

Disclosure Pitfalls

from here and here (image source, article)

The problem with informing the public of vulnerabilities is that the bad guys get included and then they do this sort of thing. It could be a long time before everyone is patched, but it certainly not a long time before everyone's a target (everyone with a vulnerable exchange server, that is).

Wednesday, February 10, 2021

I guess Cuddly Fuzzbucket sounded unprofessional

from here and here

I'm not sure how you're supposed to take an advanced persistent threat group seriously with a name like that.

Tuesday, February 9, 2021

Hanlon's Hacker

from here and here

Hanlon's Razor re-imagined for the cyber-security domain.

Tuesday, April 7, 2020

Don't bite the hand that aids you

from here

Aren't state-sponsored hackers supposed to be intelligent? Interfering with the organization trying to help bring an end to the pandemic that's afflicting your country (among many others) doesn't seem like a terribly well thought out plan.

It's almost as if they don't realize it works against their best interests, which makes me seriously question the basic premise that APTs are supposed to be smart.

We're all in rough shape right now. This isn't rocket science. Stay the fuck at home, and leave the helpers alone.