AI-Driven Ransomware Defense with Halcyon’s Jon Miller
Halcyon CEO Jon Miller explains how machine learning algorithms can be used to create the encryption keys needed to thwart ransomware attacks in the wake of the company picking up $100 million in additional funding.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with John Miller, who is CEO for Halcyon, and they just picked up another a hundred million dollars in funding, and we're talking about, well, a tool to combat ransomware, because, well, they've just captured the encryption keys in the first place.
But I'm gonna let John tell us how all that works. John, welcome to the show. Thanks for having me.
We've all been talking about ransomware forever, and it's a clearly a plague, but I think we all feel like maybe we don't have as much control over our destiny as we might think. So John, walk us through here. What are you guys doing exactly that's different than everybody else in this space, because I don't, I haven't heard anybody really talk about the fact that I can maybe get my keys back.
Uh, I, I mean, it's, it's a little more than that, but, um, I started the company, my co-founder and I were working with the, the US government on next generation offensive weapons. And, uh, the day the Colonial pipeline breach happened, we were talking to each other and we both decided that because there's no counterbalance, there's no consequence to ransomware. These people get the money, they go away with it.
Everyone knows what they're doing. Very few people face arrest or, or consequences that we thought the problem was, was really going to grow outta hand. And so our thought was, um, be the first company that's actually focused on a specific threat group in the industry.
So we were the first dedicated anti ransomware company. And so what we did is we went out and we tracked all the groups, and we looked at all their samples and came up with the idea of essentially what you need with ransomware is, um, a next generation style protection machine, right? They're figuring out how to subvert, um, the existing technology stack that's there.
These guys have, you know, hundreds of millions of dollars of resources and are operating within community, right? So we came up with the idea of building something that actually came in and kind of compliments where, like EDR and AB stop, right? Where they're all about detecting or blocking, they're not really about recovery or remediation.
And so our thought was if we build something that's focused specifically on the protection of ransomware based on what ransomware is, how does it look? What does it do, right? Um, so not only do we kind of stop ransomware after it evades or tricks the EVR, we actually monitor the EVR for when ransomware guys go to disable it.
Um, we stop the data exfiltration that comes before the lockup, right? When they're, they're taking files and shuttling them off to some shady site. Um, we protect the backups, right?
And then finally we look for that ransomware behavior where they're locking up files. And when they're locking up files, like you said, we capture the keys and, and cash 'em off. And then after enough encryptions happen that we know it's something bad, we terminate it and our agent itself can actually identify the files that were encrypted, take the keys and just encrypt them.
So it's not like a, a traditional ransomware ir. And the beautiful thing about our product is the second we detect something anywhere along the journey of pre-execution or behavioral or, or even after the fact, it immunizes not only the rest of the fleet, but all of our other customers as well. So in a worst case scenario, a successful ransomware attack at a Halcyon customer essentially is a single machine goes down for 15 minutes, a half hour, maybe it worst, a couple hours, and then it just comes back up.
Business continues on, and, and it's just one machine. It's, uh, I I like to say we're all about taking the kind of like material breach out of a ransomware attack where they can actually penetrate everything, succeed, we'll recover it, push 'em out, and make sure the business has full up time. And did I understand that correctly?
But the first time you see an attack that might be successful for a period of time, but essentially you capture that and in effect, it's a, an immunization program for everybody because now you've got that signature. Yeah. So on top of it, we have a full machine learning engine that's just been trained on ransomware.
So it's really, really good at, at detecting, uh, you know, ransomware than nobody's seen before. But absolutely, if it makes messes up, if they get farther and farther into the system, we identify it immediately, stop it, and then immunize the rest of not just our customers fleet, but all of our customers. And then on top of it, we're the only company in the industry that actually stands behind our product.
And what I mean by that is, if you're a housing on any ransomware customer and they successfully ransomware you, instead of calling your cyber insurance company and negotiating, you call us and we'll handle the full response and recovery at no charge. We will actually stand behind mitigating the risk that we're selling to customers that we're providing. And it seems like today, the only thing that we really have for recovery is, you know, we're dependent upon, uh, backup and recovery software, a lot of which might be antiquated or might be encrypted in the first place.
'cause that's the first place the bad guys are targeting, right? So they normally get, uh, active directory credentials and then after the cred credentials to go after backups. The the problem that we're seeing is even if you have perfect backups, right, and they don't tamper with them, the amount of time to restore from backups is weeks, right?
The networks weren't built to take a full rebuild coming across from backup servers to the actual endpoints. And so we needed something that was quicker, right? Instead of having to recover the whole network, if you can just keep it isolated to a single host and you don't even need backups to recover it, you win.
And then if something horrible, you know, goes down, you still have backups, you still have other options. It's all about just adding in another layer of resilience into a customer staff where if you get penetrated, they're never gonna have enough leverage to actually get you to engage with the ransomware group to pay them to talk to them. You just deal with it on your own, push them out and they'll, they'll move along.
So we, even this modern age, a hundred million dollars sounds like a lot of money. Um, what's your plan for that? What are you guys thinking about?
So we're running completely unapproached right now, as crazy as that sounds, right? The, the product is very technologically difficult to, um, for somebody else to build essential. And so what we're looking to do is, um, expand our go to market, right?
More sales guys. We're, we're only being limited in growth right now by our ability to actually go out and, and close these deals. There, there aren't a lot of customers that say no when, when you explain to them what we've done and, and they understand the, the risk that we mitigate.
Um, the other side is continuing to invest in the platform. Uh, what's really made us different is all of our features are unique, right? Um, there's no competitive, um, you know, fe feature in our, our entire product.
It was all built to be complimentary with the existing stack. And we're gonna continue to invest heavily in building new features and tracking these ransomware groups and just making sure that we're one to two steps ahead of 'em with an obstacle that's so big that they won't even try to overcome it. They'll just take another path.
What is your assessment of our adversaries these days? I seem to believe that there's ransomware as a service, and they're recruiting all kinds of people to be their agents to create, create some level of separation between them and the actual perpetrators. And at the same time, you hear tales where there are a highly set of professional services where they'll come in and they might not even launch the ransomware.
They'll just tell you they're gonna do it and here's where they're gonna do it. And, um, you know, it's almost like a consulting engage. Yeah, it's, it's interesting, right?
Where they're not doing it for separation, they're doing it for skate. They're literally franchising themselves because they're so successful, right? So it's all about those macro kind of Russian groups that are building the tools are essentially enabling this whole new economy beneath them, where you don't have to be a security person, you don't have to be a coder.
You don't have to know what any of this stuff means, as long as you understand enough about systems administration, where you can run code on other machines. That's it. You can be a hyper successful ransomware group now.
And what you'll see with groups like Scattered Spider, the guys that took down like NGM and Caesars and Change Healthcare, is that they have these super amazing systems administration skills, and then they're combining it with social engineering skills, right? So they're doing these new things like sim jacking and, uh, cell phone identity impersonation, combining that with these macro tools that they're getting from groups like Black Cat, right? And they're just outrageously successful right now, right?
So they're really opening up the economy where any of us can do this, and all it's doing is just creating more and more groups and more and more attacks, right? And the, the downside is, we, we definitely haven't gotten an upper handle on this. Like, this problem is gaining momentum instead of losing, I cannot help but wonder if the way we allocate security dollars today is somewhat unbalanced because so much of what we invest in still is defending their perimeter.
Um, and the bad guys are just coming over the top of the wall, as it were, and going right after the data. And so do we need to rethink our whole approach to cybersecurity? And this is gonna sound, um, you know, probably a, a bit off, but I, I don't think it's less, I think it's more like the answer to security has normally been an attack.
An attack gets figured out and security products get built to mitigate the attack. And it's like credit card debt, like all these attacks are backing up. It's not like any of these products no longer add value, it's just we're in this cycle of, you constantly have to be investing in what's new and what's coming out and then layer 'em together, right?
It's, uh, it's very expensive, right? Because there's no, there's no easy button for it. There's no like, oh, we rolled out MFA and everything's finally taken care.
Um, it, it's just more and more, and the scary part is it used to be really the nation state attackers that drew drove for the, you know, sophisticated next, next generation attacks. And now that power is shifting from a government being the one to figure it out to cyber criminals where their only motivation is return on investment, right? If these guys are putting effort in a zero day or a tool, they're gonna use it and they're gonna try to use it in, in many places as they can to make as much money better, right?
It's in, in my view, it's kind of like the first time in the last 25 years in information security where we're starting to have real problems. Like people are, people are dying in hospitals 'cause the hospitals are getting ransomware, right? Like, this isn't, oh, China hacked in and stole our PII data.
Nobody knows what they're gonna do with it, right? Like, these are very transparent consequences and, and we still don't seem to be getting the upper handle on do we need to have a real conversation, therefore about the cost of security? Because everybody seems to walk around and say, well, it should be 2%, 3% of the IT budget or something.
And, you know, is that just kind of a, you know, fanciful thinking as it were because the landscape keeps changing and the adversaries keep getting different tactics? Well, and they have mo more For the first time ever, we have attackers on the internet that are motivated by destruction. We've never had that.
Nobody came in and broke things to break 'em. It was always a fear that we had and we mitigated against that risk. But now the threat's actually there, right?
And, um, yeah, I mean, I mean, I think that we're gonna see security spend over the next 10, 20 years skyrocket. We're, you're getting more in, IM parity with what it costs. If you're spending $2,000 on a laptop, I think people are probably gonna end up spending $2,000 to secure that laptop over time just because the actionable threat actors, they're so many more in it, right?
And they're just growing and growing and growing. And we're gonna, you know, get to a point where, and and you see it, these big mature companies that have all of the existing technologies, they're running EDR, they're doing have MFA, they're still falling to these attacks. Have we inadvertently found ourselves, therefore, in an AI arms race?
You mentioned machine learning algorithms and clearly AI will help the good guys, but it seems like the bad guys have all the money in the world, so it won't help them just as much. When was the last time you got a phishing attack where it was all structured and broken English, right? I, I mean, seriously.
Mm-hmm. I think that that was the first thing where we really saw, you know, machine learning revolutionizing, um, an attack right on us where it became super apparent overnight where it was for 15 years, it was easy enough to pick out a phishing email because it was never in, in proper English. And now everything's perfect, right on top of it.
If you look at a lot of the kind of legacy security solutions out there, the, the first gen avs and stuff like that, um, the attackers are actually able to use all this code generation stuff, right? Coming out of all these LLMs to actually build and restructure tools, right? If it doesn't take you two weeks to build a custom piece of malware, if you can take something that you already have and use an LLM to change it in 15 minutes or an hour, um, it's just continually pushing the bar higher for what the security companies have to detach, right?
And again, you can see it, the, the successful attacks are going up, right? Like every year you look at ransomware losses and no one's like, oh, they're gonna go down. We finally got a handle on it.
So what's your best advice to folks, therefore, as that kinda look at all of this? 'cause you know, there's a proverb that says, you know, the best defense is a good offense, maybe, but, you know, how do I kinda like get after all this? I wouldn't recommend anyone taking up offense against Russian ransomware groups.
They do have ties to, you know, Russian intelligence and you might end up with consequences that are worse than you. You expect it, it's about being prepared, right? Like, like everything in our industry, um, based on who you are, where you work, what your enterprise is, understand the threats.
Ransomware groups don't go after everyone. They specialists, right? There are ransomware groups that hack healthcare.
There are ransomware groups that hack critical infrastructure. There are ransomware groups that hack the Fortune 500. So understand where you sit and there's a lot of material on halcyon AI that you can go to to, to kind of reference our, uh, ransomware maliciousness quartile that we update every quarter, where we track all the groups and what they're doing and, and who they target and what makes them special.
And then we have another feed of all the live attacks. But understand who's coming at you once you understand who the, let's say three to maybe 10 ransomware groups that are out there that target your industry and companies of your size. Spend a half a day and, and go and read the threat of the other groups that they attacked and, and look at their techniques.
And then ask yourself, am I vulnerable to those same attacks? I mean, excuse me. Use that really as, um, you know, a blueprint to figure out what your threat surface is.
How are you prepared? You know, do a gap assessment. But, um, every single day these ransomware groups get, um, exfiltrated from companies without successfully ranted.
It happens. They're, they're looking for ROI. Once a hack becomes too long and too expensive for 'em, they'll bail and go somewhere else.
And the only difference between that is, is purely preparation. Alright folks, you heard it here. Hey, if you wanna work for the good guys, maybe you should learn how to think like a bad guy at the end of the day.
Hey John, thanks for being on the show. Appreciate the time. Thanks so much.
Alright, and back to you guys in.