Evolving Ransomware Tactics and Cybersecurity Strategies | Security Boulevard Ep. 6
In Ep. 6 of the Security Boulevard Podcast, Tom Hollingsworth, Mitch Ashley, and Alan Shimel discuss how ransomware tactics are shifting. Attackers are using AI-driven phishing to breach organizations while ransom payments decline as defenses improve. Malicious packages continue to exploit software vulnerabilities, and government hacking tools add new layers of risk. The panel highlights why cybersecurity strategies must keep evolving to stay ahead of emerging threats.
Transcript
AI has been a tremendous boon in ransomware for the bad guys, because most ransomware finds its way into an organization via phishing. Welcome to Security Boulevard, the cybersecurity podcast from The Future Room Group. Our episodes explore a variety of topics within cybersecurity and all of the technologies behind it.
com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms. This week let's meet our panelists, starting with the grand old man of security himself, Alan Shimel. Alan, it's good to see you again.
Thanks, Tom. It's the first time I've been the grand old man. Better than the grand old party, I guess, but all good.
Well, I'm happy to have you back as well as my friend Mitch Ashley, who I get to hang out with this week. Mitch, how's it going? Good.
I'm, thank you for not introducing me first, but yes, it's good to be here. I lead record Mitchell's older than me. I'm more than him.
I lead the software lifecycle engineering practice here at rum. So good to be here. Thanks, Tom.
Well, and of course, I'm Tom Hollingsworth event lead for all things related to security here at Tech Field Day, and we've got a packed episode. So I wanna jump in with one of the very first reports that I saw, which was rather interesting. This is coming out of Ware, which is now part of Veeam.
They said that ransomware payments have actually fallen over the last year. Uh, last year people were paying about, on average 28% of the time, and now they're paying only about 23% of the time, which doesn't sound like a whole lot of a reduction, but it is going down, and that's probably several hundred thousand dollars that have been saved. But in the article that I read, one of the things that they said was kind of interesting was the fact that remote access compromise has actually gone up significantly as the primary attack vector.
And there's some discussion about whether or not the attackers are maybe starting to get a little bit smarter and more selective about the companies that they're targeting, instead of just kind of taking that spray and pray approach to see who's actually gonna be paying up. And maybe that means good, it means the attackers are possibly being thwarted by better controls and things like that, or possibly through cyber insurance and, and services like Ware, which kind of actively work to negotiate down those payments. But it could also mean that the ones who are kind of being targeted are in for a world of hurt if they're being more technologically, uh, competent in the way they're attacking those companies.
Alan, you had some interesting thoughts before we started on this. Uh, do, what do you think about the fact that pe the payment is going down? Oh, I, I think that, that, there's several factors at play there, right?
But I also think it's sort of the natural course of things. Let, let's hit on a couple of the things you mentioned, Tom. First of all, AI has been a tremendous boon in ransomware for the bad guys, because most ransomware finds its way into an organization via phishing, right?
And where it used to be so easy to spot a phishing email because English was a second language for most of these people, or it was just sloppy, or it, it was easy to spot phishing. AI is made phishing so much better. So whether you're going with a spray and pray kind of, you know, mass market fishing and see who it, what, you know, comes into your net versus a spearfishing for specific targeted, uh, victims, AI has really, really helped there.
But I think part of the reason it's gone down is this isn't 19 or 2019 or 2020 anymore. Organizations are now wise to what ransomware can do to them. And whether it's through the cyber insurance companies enforcing it or, or just, you know, Darwinian evolutionary tactics at play, organizations are insulating their data, or at least copies of their data so that if things do get you encrypted via ransomware, they just flush it down the toilet.
No big deal. They, they could hit the restore button pretty easily. I think another big reason is the cyber insurance companies and the comp and companies like who, who published this, you know, study have gotten better at negotiating with the criminals who are behind ransomware, right?
Hey, I gave you 25 grand last time. I, I, I actually had seen a, uh, a study on what the average ransom was, and that's gone down too. So the average amount of ransomware paying per incident has gone down, and the average amount of incidents, or the average amount of payouts per incident has gone down.
You know, I also would just point out, though, is that the, the hacker underworld is very stratified, right? And the people who do ransomware are generally not the highest people on that food chain, right? They, they're a little bit further down the chain.
And I, I think the people who've predominantly were doing that are looking at bigger and better things. They've almost gro grown bored, if you will, on, on doing that bread and butter mom and pop ransomware, because that's the other thing is who are the victims of ransomware? It's not Fortune 100 companies, it's the smaller, medium companies who don't have the resources and are gonna think twice about, Hey, do I, do I just pay the money?
Do I just pay the money and get on with my business? And so, for all of those reasons, Tom, I, I, I agree. I, I, I, I think that's what we're seeing here.
Yeah, I think those are, uh, I would agree with every, all those reasons, Alan, um, you know, we've kind of flipped the script too, right? The default was just pay it, right? We don't know what to do, pay it.
Now we've got insurance companies, our, uh, legal teams, we have companies that specialize in those negotiations, how to handle it so we can bring somebody in to handle it for us if it's significant. I think the other thing is, um, you know, you mentioned ai, Alan, also the quality of deep fakes, not just emails, but videos and, and voice and things like that. We'll see more, you know, hey, it's like banks and money.
It's where the money is, right? It's where the end users are. So find new ways using AI to, to attack those victims.
So it's, you know, as, as the landscape changes, the attackers change too. Sometimes they even shape it. So it's a continual kind of roll layer roller blade, if you'll kind of rolling down the street of, we keep moving as the technology changes.
Uh, just for my part, I think it's interesting that we've gotten to this point where we're talking about the financials of ransomware as if it was just another kind of business. That's how you know that it's gone from this, this cool, awesome thing, Alan, to kind of your point, it's like, well, we're not making the same amount of return on the investments that we're making, so we're gonna have to find new ways, or we're gonna have to hit up our, our trusted partners, if you will, for, for better returns. And I think that that means that, that the air is gonna get very rare up there because the people who have the technological capability to pull that off consistently are going to kind of consolidate.
Like we've seen these hacking collectives kind of come together and, and basically band together, like merged businesses. But I also think that that means that what comes out of those groups is going to be a little bit more difficult to deal with. Because like you said, they are the people that kind of understand that you have to kind of invest in these things, make better tools, find better exploits, protect your zero days a little bit better.
And, and in the chart that was in the article, I thought it was interesting, Alan, you mentioned that, you know, phishing has historically been one of the most popular ways to do that. Phishing is on a little bit on the decline, and they're now looking more at things like software exploits and remote access and things like that. Maybe it's getting to the point where, you know, we've gotta come up with a new wave of better phishing emails, so to speak, or, or Alan, kind of to your point, maybe we start doing those little things.
Like, I'm gonna text you this video and it's actually got some malicious stuff inside of it. Um, it'll be interesting to see kind of where people come up, uh, from there. Uh, moving on, I wanted to talk about another interesting thing that's been going on.
Uh, and Alan, you've covered this a little bit. Uh, research firm COI announced this last week, um, that NPM is being flooded with a bunch of malicious packages. This is actually something kind of weird because, uh, what's happening is, uh, an NPM can be made so that if there are any dependencies that it needs to have, it can pull those down.
I mean, that's basically, if you've ever reused a Linux package manager, you know that you kind of almost need to have that anymore. But what's happening is they're using a secondary method called Remote Dynamic dependencies, which is great, except for the fact that you can basically spoof RDD into doing things that it really shouldn't, like going out to a repository that's not even H-T-T-P-S secured and pulling down Kenny, anything on the manifest. And I thought it was interesting in the article that was listed on ours, Technica, um, the, uh, people who were doing this were able to download, I think it was like 126 packages from Manifest that were not checked at all by any security scanners because the original package listed zero dependencies, and it was basically almost like a side channel attack.
Uh, Mitch, you thought that this was an interesting story. Do you see this being a problem in the future where people are basically kind of using these, these side loading attacks to get their malicious software past the security scanners? And, and do the people who create those perimeter defenses need to come up with better ways to prevent those secondary communications channels?
Well, this is one of those edge cases. Uh, edge cases remote, uh, dynamic dependency is a fancy way for hard coding, A-A-U-R-L to go get a package for you, go get some software instead of relying on the package manager, which was, which does dependency management. So if you're gonna install this JavaScript, which is what mp M'S for, uh, into your, into your app, it brings all the dependencies for you.
That's, that's the whole value of it, not just distributing the code. So this is a rarely used thing. People don't normally do this 'cause it's like kind of hard coding something into your, into your, the package that you're creating, and now you sort of defeat the purpose, but now it has a different purpose, right?
They're hard coding this into packages so that when they run now they'll go pull down exploitive code. Um, I, I think a, it's a, it's an edge case. It's not, it's one that I think can be easily fixed.
Um, as people know that this is an attack vector, now we can put that into scanners on the package managers. We can do that, and the scanning of packages come into our own environment, things like that. So it, it's not something that's hard to detect or reproduce, it's just a rare feature.
It's kind of like, um, there's another exploit out now with the, with, um, blockchain where they're using a certain message part within the blockchain to, to load in code, which is what it's meant for. But it's, it's a way of getting code into your environment and then getting a compromise started and then move, move, uh, horizontally. I was just gonna say, you know, what do you think about this?
Because, you know, you've seen a lot of these exploit, uh, kind of vectors over the years. And, and I, I, Mitch, I kind of wanna agree with you that this is kind of an edge case because we all know what happens when you hard code URLs into things. Um, it breaks a whole bunch of stuff.
But I can also see this as kind of being one of those things that's almost so stupid. It works, Alan, what, you know, what do you think? So first of all, let's go up 500 feet second.
I think one of the biggest for security issues in general these days is the fact that so much of our software is built Frankenstein style by stitching together components. We're downloading from various archives and repositories, such as the case here. This isn't the first time NPMs had, you know, we had the worms last month.
Um, we need as an industry to come up with better defenses or better processes to make sure the software we're downloading from repos is safe, is secure, is free. And you know, this goes to the whole thing around SBOs. Theoretically, the SBO wasn't supposed to just be the label on the mattress that if you tear it off, it's a federal offense.
Do you know what I mean? The sbam was supposed to be a living breathing document or, or a program that a good sbam reader or a good security program would then be able to say, okay, I've got this component, I've got this snippet I've downloaded over here, and I see there are dependencies. I see there are calls out.
Let me check those call outs and make sure they're not malware. They're not malevolent, malevolent. So that's the idea behind, I mean, the whole idea behind bums was to kind of help with this kind of thing, right?
This is, this isn't happening sort of post deployment. You know, it's getting injected right into the software build process when we're, when we're pulling these components and these, these code snippets from from archives. And it can happen to any of the archives.
It can happen to you. It maven, it can happen to you at Artifactory. It could happen, you know, a docker, we've seen it with docker images and stuff like this.
This is the new attack vector and it's why we need to do our SBOs. It's why we need to, you know, make sure that these SBOs do go back and check these third party dependencies that we're seeing in there. You know, it, it's not good.
This is, it's not the first and this isn't going to be the last I'm afraid. Well, and it's why you see, you know, even unexpected players like Ause come out with a curated repository of rebuilding software, then on top of what they know to be a secure, uh, Linux os of course their own. But, you know, I don't know.
I don't know, Alan, it's, to me, it's kind of tilting at Windows to say, the industry needs to change this because package managers are gonna be out there forever and they're not going away. 'cause there's code that relies on 'em. You know what, what it means successive generations.
So even if we came up with something new, Well, I don't think Mitch Yeah. Who they're I think think, I think your SBOs need to, so it's, again, the SBOs shouldn't be a static document that said, I downloaded the packet manager. The SBOs should explore the connections within that packet manager, almost like running it in a sandbox.
Yeah. And I think the security scanner on the, on the package coming in should look for this, right? And if it's not looking for it now, start looking for it.
I, I think that's where we are. We're not getting rid our packet managers. We're not getting rid of, Okay, I took it.
You meant to like, rebuild these packet managers different. Well, It, look, if I was going to go start a new company today, and maybe I'll Mitch you and I'll do it again. We'll get back at this.
I, I would, I would build a repo firewall that works on any repo that does exactly that. Every piece of software, every component, every package, every script, every snippet that I download from a repo, I'm gonna, I'm gonna put it in a sandbox and run it first. I'm gonna check all its dependencies and I'll certify it before I pass it through Every model, every agent, right?
Add those to that mix. I, I love that idea, Alan. I wanna be an investor.
Uh, I just need you to do me a favor. Do you have a module that will convince my DevOps people to stop going and downloading random packages that, oh, this is just the thing I need. And I know it's not on the allow list, but it's just the thing.
I need this one time, My notes not the newest one, but there's some functionality I need. That's why I'm getting the one that's three years old versus the one that is six months old. You know, it, that's human nature.
But if we could put that firewall up there, I don't know. I mean, maybe I'm tilting it windmills as Mitch says, but I, I thought we would have seen that product already, And maybe we will. That, that, that's the interesting thing about having these conversations is as soon as somebody breathes it into the, the atmosphere, someone's gonna come up with that idea.
And if you do, make sure you shout out the Security Boulevard podcast, because we, we'd love to take credit for that. Absolutely. Alright, we got one more story that was kind of interesting.
Um, and it involves the law, specifically the law that decided that there was an Australian man who was working for a US defense contractor who, um, broke it. And by breaking it, uh, he attempted to sell, uh, protected hacking tools to, uh, parties in Russia. Uh, this man, Peter Williams, uh, pleaded guilty to, uh, taking tools that were developed by the company that he worked for and selling them, uh, to Russia, even though they were specifically marked to only be sold to the US federal government and close allies.
Uh, he worked for a company called L three Harris. I think that's the holding company that he, he worked for a company that worked for them. Uh, but it kind of goes back to some of the things we've talked about over the last few weeks about states and just how they're coming up with these tools.
Uh, you know, we've seen leaks, uh, after all of the stuff that happened about 10 years ago. Um, we've seen the development of those tools by governments that then basically offer them to sale for anybody who's willing to pay. Um, Pegasus being, I think probably the, the most egregious example of that.
But now we just have flat out companies that are developing this, and then an insider was like, Hey, um, you got $30 million in your pocket, I'll let you have it. Uh, do I, I've said this a number of times on a number of different podcasts, uh, about other security things. But the way to prevent this from happening is to just never develop the software in the first place, because we all know what it was gonna be used for.
And the fact that you are basically, for lack of a better term, shooting the cop with their own gun is kind of embarrassing because we, we know that the rules say that you are only supposed to sell this to the US government. And we know that everyone always follows all of the rules and never breaks any of them, especially in security, right? You know, this is a great opportunity for why not, um, sort of turn the table.
Let's, let's have give this guy tools that already been compromised by us, so when the Russians get it or whoever gets it, now we're in their network, right? They're, they thought we're getting tools to break into our stuff. Look counter espionage.
You know, How, how do you know we didn't do that? I know. That's the first thing I thought of, of like, this would be a great counter Espina just being honest.
Well, I, it's been done before. Oh. Oh, it has, and it has backfired.
Alan, I, I think I brought this up last week. Uh, but there was actually, uh, something that happened, uh, a couple years ago where the, uh, US government very heavily convinced, uh, I believe it was Juniper Networks to install a very special version of ECC, uh, encryption software on their routers. And it was one that was known to have been able to be easily compromised.
And those routers were being sold to the Chinese government, and the Chinese government found out about it and basically reversed the hack to be able to hack back through them. And we're doing some things they probably shouldn't have. Did that lead to Salt Typhoon?
I don't know for sure, but like, this is the thing, and, and the, we, we've, I've had this argument with people a lot about the, uh, UK government's, uh, request to Apple to include, uh, basically a legal intercept backdoor and iMessage. And, and they're like, well, we'll never share it with anybody. And I'm sure Apple's response was that, you know of.
Because the moment we build that backdoor into the system, whether it's for egalitarian purposes or not, it's always gonna be compromised. And all it takes at that point is enough cloud computing resources and a smart enough ai, and you're gonna be able to, to figure out how to do that. And now you have effects of Kingdom.
I believe in the case of Apple, there is a backdoor. Apple just didn't want to give it to the UK government. Apple does have the ability to do it.
The UK gover and they didn't trust end government with it and more power to Apple for them. But, you know, look, in another world, in the past life, Mitchell and I did a security company. We did a, a lot of work with the sec def team and, and the DOD and some of the agencies.
And I will tell you that they do put out software that they know is compromisable so that they can then observe whether it's the Chinese or the Russians or whoever, so that they can then observe them coming in, see where they go within that network and, and, and they try to keep 'em in, you know, relatively benign parts, but they feel better that I have that visibility into doing that, then they are running wild. And I have no idea. So there is a part of our national cyber defense that says, yes, we know these people are here, there within the network, but we, we've got them contained and, and it's so we could watch them.
Now, that being said, look, this is shade, this instant case here, Tom Shades of Edward Snowden, right? Whether it's purely for money, which may be the case here or not, we don't know for sure. Or is he upset with the present US administration?
Is he, uh, been radicalized there? There's a lot of reasons why people, you know, turn against their own governments and so forth, money just being one, one of them. Um, and, and it, and it could be combination of money and something else too.
The real issue is we're not gonna stop making these tools, but we've gotta do a better job of, of, you know, certifying the people who are working with it, making sure if money's the motivating factor, you know, are they high debt? Are they, you know, what, what's going on there? Um, number two, we've gotta keep better controls over who can actually access to exfil exfiltrate the software, right?
And, and that is something we work on too. I've seen a lot of sort of next gen AI power DLPI thought DLP was dead a long time ago, but I've seen a, a renaissance of, of AI empowered DLP to stop exfiltration of programs and so forth like that. But, you know, look, we're always gonna have new John Le Clare ma novels.
It's probably a good story behind this one. Well, a great butcher Uncle Ben from Star, from, um, Spider-Man, you know, with great power comes a long line of people who will try to hack that great path. Well, I think it's funny that you bring up the fact that we need to have better controls over it.
Um, I think maybe the military contractors need to take a lesson from the cloud providers. You need to have a license to run this stuff, and you need to be in a specific location to operate it. And if you don't meet those criteria, you can't run it.
Because I, I, Tom I've dealt with military contractors, they make the cloud providers look like children, And yet these tools keep getting shipped out it, Because what happens is a guy like this goes into the office, he logs in, you know, to log into these systems, you need a card with a chip and you log in and you're there. But for however he figured it out, they're able to exfiltrate it. He might have exfiltrated into a u SB jive probably because they're all, we, we got a call once from the Pentagon.
Can we, can we run a, we had a network access control, uh, product that Mitch helped design or bled the design, and they wanted us to be able to test was the, can we make sure the USB port was disabled on laptops? We said, yeah, we could probably write that test, but why would you wanna disable the US SB port? This is why you wanted to disabled the u SB port.
That was 20 years ago and that was 20 years ago. So imagine today, Todd, Oh, uh, my friend Edward Lecky has a solution to that. He just super glues all the USB ports on his laptop shut.
Well, You did do that too, but again, it's there for a reason, right? And L three Harris look, L three is a huge, you know, we used to call 'em the Beltway Bandits. L three Harris L three is a huge beltway bandit, and they bought the Harris Corp, which was based down here in Florida and is also huge.
DOD satellite, uh, you know, contractor. So these aren't rinky dinks. These, these are, you know, major level folks who believe me, know what they're doing.
But you know, who knows what lurks in the hearts of men. Tom, only the shadow knows, Or, well, I know what lurks in the hearts of most of these people is crippling debt. That's usually why they do the things that they do.
They do. Except, you know, Snowden, you know, it wasn't where with Snowden, he, he really felt like he was just, you know, a justice warrior or whatever you wanna call it. Yeah.
He was an ideologue, which is actually really rare. 'cause when you look back at, at more what we consider famous spies like Robert Hassan and folks like that, usually it was a pure, a pretty pure motivation. Yeah.
But I would, I would positive that the ideologues are more dangerous. Oh yeah. They are true believers.
They, they, they really do believe. Well, I, I believe that it's about time for us to wrap up this episode. Uh, and we are very, very busy people.
Uh, there's a lot of things going on. Alan, what are you doing, uh, this week, next week that people can check out? Yeah, actually I'm going to be in Atlanta for CNCF Cube Con, cloud Native Con.
I'll be there for all week next week and then come home for Thanksgiving and then head to Vegas for, uh, uh, uh, AWS reinvent, come home from that. And then I think I'm off to Israel for Cyber Week, which is a lot of fun for those who are into cyber. There's no shortage of Israeli based cyber companies to talk to.
See, I told you Alan was busy. Uh, Mitch, what about you? What do you got going on?
Well, this week, um, you know, I'm headed to San Jose to join the Networking Field Day. So check us out on text, wrong tv, YouTube, all the channels, all the properties. They'll be streaming live from there.
And then I'll be joining Alan as one of the attendees at, uh, Kon the following week. After the week after that, I'll be at OpenText World, then with a little bit of Thanksgiving day Turkey. And then I'll be in re at reinvent as well.
So I'm not going to to cyber week, but gonna reinvent. That's good to hear. Well, I'm gonna actually be hanging out with Mitch this week at Networking Field Day.
I mean, it is my baby after all. Uh, we got great presentations like, uh, Mitch said, check them out at Techstrong TV and also tech field day com for the schedule lineup and people who are gonna be there. And then the next week, while these guys are hanging out at CubeCon with Alistair Cook, I'm actually gonna be hanging out with Stephen Foskett in New York City at Commvault Shift.
Uh, just got registered today, so there's gonna be some great security content there. Uh, I'll probably be live blogging, live, uh, social mediaing, uh, live tweeting, teeing, scooting, whatever we're calling it now. Um, and so check out that for more.
Uh, but also don't forget to tune in and, uh, check out all the back episodes of the podcast that we've recorded over the last month or so, uh, because we really do enjoy you listening to not only this episode, but all of the other ones as well. If you enjoyed this rousing conversation, please go over to YouTube, uh, subscribe, make sure you've got the notification icon so that you know when you, these episodes are being published. If you wanna check this out in a your favorite podcast application, that's a great way to kind of have it automatically download in the background before you get on the plane so you can listen to us.
When you're enjoying a ginger ale at 37,000 feet. We would appreciate if you'd leave us a rating and a review in any of those places, because that does help the show grow. People definitely wanna see what we're all about and what they enjoy about our conversations.
com and the Futureum Group. com. You can check out the Textron TV website or that cool new Techstrong TV app that we've got available on Apple tv, Roku, and pretty much any smart TV out there.
We'd love for you to check it out and see the back catalog of all the things that we've got going on. Make sure you're following Security Boulevard on X, Twitter, and LinkedIn. Just look for security BLVD and there's tons more content out there to enjoy.
Thank you very much for tuning in. We'll see everybody next week.