mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
The Quiet Conflict
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of the mnemonic security podcast, we take a closer look at a tension that remains invisible to most of us, yet is very real: the quiet conflict unfolding within our critical infrastructure.
This topic gave us the perfect excuse to once again invite one of our favorite guests, for the fourth time, Joe Slowik. Joe brings over 15 years of experience in cyber threat intelligence (CTI), detection engineering, and incident response, with expertise in industrial control systems (ICS), operational technology (OT), and critical infrastructure environments. He currently serves as Director of Cybersecurity Alerting Strategy at Dataminr.
In his conversation with Robby, Joe explores the threats posed by Volt Typhoon, a state-sponsored Chinese cyber operation known for targeting critical infrastructure, primarily in the United States. They discuss the origins and activities of the group, recent operations, and Joe also shares his research into what this group has the potential to achieve based on their current operations and proven capabilities.
The discussion also covers Joe’s broader research into China’s cyber eco-system and how it has evolved, including the country’s extensive network of research institutions, companies, and lesser known contractors. Joe also shares his observations about current trends in the OT industry, insights into his upcoming areas of research within OT, and his perspective on where the field is heading.
From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.
Robby PeraltaOne of the luxuries we've enjoyed over the past decades is that nation-state operators haven't wanted to break things. They've wanted to know things. Intellectual property from corporations, political and military secrets. Knowledge is power. But where classic espionage ends with stolen data, the group we're talking about today wants something far more dangerous. Access. Advanced persistent access, if you will, and the kind that has turned critical infrastructure in the United States into a chessboard. And although it's the United States and China facing off in this game, the others are watching. And Europe, better be paying attention. Joe Slowik, welcome back to the podcast.
Joe SlowikAlways happy to be here.
Robby PeraltaI don't know how many times it's been, but it's this is like three or four, I think. Three or four, yeah, exactly. Looking forward to seeing you here at the ICS conference, the annual Denmark party of ours.
Joe SlowikJust a couple of weeks away.
Robby PeraltaI couldn't wait to see you though.
Joe SlowikYeah, exactly.
Robby PeraltaBut unfortunately, we're here to talk about something a little less fun. That's Volt Typhoon. Yeah. My first question to you, why now? Because if I remember correctly, that happened that started being a thing a couple years ago. So what prompted you to uh dive into that now?
Joe SlowikSo it first surfaced publicly around spring of 2023 and has since been overtaken by other typhoons, specifically Salt Typhoon, because we have to keep to these naming conventions, right? Um but as part of that, Volt Typhoon has not gone away. There was an interesting article or an interesting quote that was captured by the record uh a few months ago where someone made the comment that, like, oh, Volt Typhoon, we defeated them or they didn't succeed, which was kind of taken out of broader context because if you talk to people that actively track that threat actor or are concerned with that threat actor, while they haven't been in the news much, they have certainly not gone away and in fact are doing some rather concerning things these days. Uh, unfortunately, the problem with Volt Typhoon is that not a whole lot of information regarding their operations and current status is public. So I've been working on this research through a couple of different companies at this point, and um finally had an opportunity to provide a reasonably complete overview of everything that is publicly available and publicly known about this group for background and understanding purposes, and to take that understanding along with an understanding of previous critical infrastructure targeting incidents of what could this group conceivably do if they wanted to go active based upon their operations to date, their capabilities, both identified and assessed and similar. So, really to provide uh something that people can point to where it's like, hey, this is the problem set outside of scary secret spaces or whatever, uh, for awareness for other audiences and the things we need to be worried about from a defensive standpoint and uh to make investments in resilience and similar with respect to that threat actor.
Robby PeraltaA Chinese-based group of threat actors that are um pre-positioning for an event with Taiwan.
Joe SlowikThat's that right, yeah. Covers it. Yeah, that's a good thumbnail sketch. Uh, what's interesting about Volt Typhoon is that unlike a lot of other People's Republic of China related threat actors, like even Salt Typhoon has been linked to a couple of different contractors essentially working for the Ministry of State Security. And we've seen similar links to either the Ministry of State Security or the People's Liberation Army for other entities. Nothing like that has ever really been put forth for Volt Typhoon. So Volt Typhoon really is, at the end of the day, just sort of a behavioral construct with no public identification of precisely who they are, who they report to, or where they reside in the nexus of government and commercial entities in PRC performing offensive cyber operations.
Robby PeraltaSo the salt typhoon is kind of that third actor. No, bolt typhoon is that sort of third actor that it just goes to work at eight, leaves at five, and even if you kick them out, they're gonna come back to the same target no matter what you do.
Joe SlowikThey are very much linked to what could be referred to as a low and slow approach, and but also an opportunistic approach to infiltrating critical infrastructure entities with an emphasis on developing and maintaining access for the long term, uh, which is one of the concerning things about them is that because of their almost extreme reliance on subverting network trust and network control, it is a pain to evict them uh if and when they get in.
Robby PeraltaIs it so that they've been just targeting critical infrastructure that is close to military bases, or is it, you know, energy companies that are just serving big cities, or is it just anything that could be important to the United States?
Joe SlowikSo that's an interesting element that has been developing and sort of changing over the last year, year and a half or so, is that historically volt typhoon operations were linked to critical infrastructure associated with the projection of military power in the Pacific region. So thinking about electric utilities and guam on the island of Guam supporting U.S. military installations, which is basically the entire damn island of Guam. Um uh, or ports and similar control systems for that would allow for shipping military equipment from California, etc., oh across the Pacific to support Taiwan in some fashion. However, there was a really odd uh event that was made public um, oh goodness, February of this year, where there was a Vol Typhoon intrusion in a municipal power and water company, Littleton Electric Light and and Water. I I forget I'm the exact precise name is escaping me, but small town in Massachusetts, basically. And there's if you stretch it a little bit, it's like there's some interesting transmission links that flow through there, but honestly, there's nothing remotely interesting about that place. Like it's not really close to Boston, it's not really close to anything that you would assess to be for a strategic purpose. Right. So it's almost like Vol Typhoon has combined very targeted, very uh concerning operations with more opportunistic items, which leads to to preview what I'll talk about at Cyber WarCon, that there's a divergence in Vol Typhoon or what Vol Typhoon may be preparing for. On the one hand, very targeted, very specific interruptions that you could link with, say, you know, military force projection or to hold military capabilities at risk. And then on the other hand, more indiscriminate, widespread compromise of critical infrastructure for the sake of potentially just causing chaos, like what we see occurring in Ukraine through Russian operations, through the indiscriminate disruption of civilian critical infrastructure.
Robby PeraltaYeah, interesting. So not just towards the mainland United States, it's also in other countries that the US has relationships with.
Joe SlowikThat's less clear, uh, especially in public information. Um there are indications, and certainly Volt Typhoon is a concern for other entities operating in the Pacific, and you could think of some pretty obvious ones like Taiwan itself, Japan, Australia, etc. Philippines. As far as publicly identified and disclosed intrusions, none exist, but I would argue that very much an entity that should be of interest, if only for understanding how that entity is operated, because that playbook could very easily be replicated in critical infrastructure in other areas within the region as well, even if there's not a immediate uh immediately identified intrusions, or it could just be that they're already in these places and no one's spotted them yet, which is a little more concerning.
Robby PeraltaYeah, those another what question I would ask you. Is this just a China versus US thing? But it's kind of obvious, even though there's no we can't really speculate, but it would make sense that anybody that's deeply enveloped with the United States military is an obvious target for these sort of things for for that reason.
Joe SlowikSo this is an interesting point because on the one hand, I would say, like for a European audience, you probably don't need to be as concerned specifically about volt typhoon operations. However, I would argue that everyone needs to be concerned about volt typhoon-like operations, if that makes sense. So looking at the wider threat landscape, other PRC entities, maybe not necessarily focused on critical infrastructure disruption, but on uh, you know, classic areas of intellectual property and theft and espionage, certainly, you know, the same playbook that Volt Typhoon has followed for IT-based intrusions, uh, I would expect to see similar activities related to other threat groups associated with the PRC. And it's not like others aren't paying attention to how effective these operations have been in terms of both their ability to get into environments and then to linger there for an extended period of time.
Robby PeraltaYeah. And is this called what is this defined as? Is it soft power? Is a hard power like that? It's a threat without being a very it's a threat that's given diplomatically, I guess you could say.
Joe SlowikMaybe, but it almost blends the two because it goes beyond what we've seen with traditional cyber operations being of a more espionage information gathering bent to something that you know US officials have been very blunt and very direct in public statements and saying this group is not interested in stealing secrets, this is not an espionage-focused entity. The actions this group is taking instead are tightly and clearly linked with preparing for disruptive actions. So getting into more of the harder applications of power or at least enabling them in the future.
Robby PeraltaSo more into the technical aspects of it. So using or infiltrating home routers and using them as like proxies, is that the same group? Can you just go into detail a little bit how that looks?
Joe SlowikThat's a tricky one because Volt Typhoon has been closely related to using networks of compromised subverted devices like home networking equipment, IoT devices and similar that have been collected into proxy networks, also referred to as operational relay boxes, ORBs, to be.
Robby PeraltaExactly. Or I guess they're both the initial access broker and the keep it going, keep access broker.
Joe SlowikThe access team.
Robby PeraltaThe access team. So once they have that access, uh lol bins. You wrote lol bass in your report. What's the difference between those two? I'm assuming the same thing, but
Joe Slowikit's essentially the same thing. Uh living off the land binaries and scripts instead of living off the land uh binaries. So it just extends lol bin to scripting objects because Vol Typhoon has been a heavy user of things like PowerShell and similar in their operations as well. So it's technically more accurate, but for all intents and purposes, it's the same thing.
Robby PeraltaYeah, but it's basically just using stuff that's already on the system that they're hopping onto.
Joe SlowikYep. And you know, looking at Volt Typhoon's actions and doing things like capturing credentials, getting access to domain controllers and similar systems within the Windows environment, and using built-in tools that are used legitimately to manage these devices, like NTDS util, VSS admin, and similar to interact with the devices in a way that is notionally allowed and aligns with what you would expect an administrator to do, but obviously not in a way that anyone wants um this actor to do at any one time to do things like grab all credentials across the Windows domain, for example.
Robby PeraltaYeah. So this for somebody like you is not novel anymore because it's been they've been doing it for two years, at least. Uh, and these techniques I'm sure been using for a long time. Uh, but I guess the trouble or the challenge for defenders is number one, getting that knowledge that you have, and that's not it's hard to teach that to some to all of the entities that need to understand that and apply it. Is that what the challenge is? Or is there more to it?
Joe SlowikUh there's certainly more to it because there's an understanding aspect of things, and there's also a resource and visibility aspect to matters as well. So there's this industry tendency to say, oh, lull bin, lull bass use or whatever. It's so hard to detect. It's actually really easy to detect. The problem is being able to differentiate between legitimate applications of these tools versus illegitimate applications. Where Volt Typhoon is particularly interesting is not just in trying to leverage the same tools that system administrators and similar use, but being going one level deeper or one step further in trying to blend in by doing things like grabbing Windows event log information to identify not just what accounts are remotely authenticating to devices, but when and what time windows they're doing so, and trying to align with when you would expect users to legitimately operate instead of classic tripwire. It's like, why did Bill log into the system at two o'clock in the morning local time? That doesn't seem right. Um, in you know, similar sorts of outliers. So, and this is a concept that I teach very often that when it comes to these sorts of items, it's not just about developing detections and alerts that can identify them, but that identify these activities with enough context around them that you can differentiate between a known a good instance of these applications or these sorts of techniques versus a suspicious or outright malicious use of these techniques uh by an external adversary. I'm thinking of the word baselining. Baselining is definitely an area that comes up frequently, and it's an area that a Volt Typhoon appears to be a uh cognizant of for the reasons I mentioned earlier that they do appear in intrusions to attempt to identify what that baseline looks like and to align with it reasonably effectively.
Robby PeraltaYeah, so they have a 24 SOC uh SOC, they have a 24-7 operation as well, I guess. They can afford that. Have you seen that?
Joe SlowikHigh-end reactors operate on the time sc on the time zones of their victims. Yeah. Has been the case for 20 years.
Robby PeraltaReally? Have you seen, because I'm assuming that there are, since you do so much training, I know that there's entities out there that have heard what you said and have applied what you've uh taught them. How have in those cases the ones that have actually understood the problems, done something about it, kicked them out, they get back in, how like how do they change or how have they morphed over time, or at least the past two years of activity you've seen?
Joe SlowikThat's a very interesting question because and this is one area that I'm hoping to spark a little bit more discussion on, because there hasn't been much published in the public realm on how Volt Typhoon operations have changed. The most detailed accounting of Volt Typhoon operations is a joint cybersecurity advisory that was put out by uh CISA in the US along with multiple uh domestic and international partners. It's about 40 pages long uh PDF that goes into describing a lot of what that group has done. And I'm sure a lot of it is still reasonably current and accurate because these techniques still fundamentally work. But what we're missing is how this group has adapted and changed in light of public disclosure uh in the 2023-2024 timeframe. And I know some entities are benefiting from non-public reporting with respect to Volt Typhoon operations, and there's a lot of folks that are tracking Volt Typhoon operations, but when it comes to not just the organizations that have the stature or the financial wherewithal to purchase a boutique threat intelligence feed or to have direct access to CISA or other government sort of sources of intelligence, and we start talking about the Littletons of the world, what do they look for? How do they prepare their environment? Because we've seen Volt Typhoon extend their reach beyond just very obvious headline entities that are very much on the radar of officials and similar to these opportunistic targets that you know, if we go towards the scenario of widespread disruption to inflict civilian pain, how are we best supporting those entities? And are they even aware of what they need to do to combat this entity?
Robby PeraltaI would guess the thought process behind not saying everything to everybody is just that, oh, then the bad guys change. But I mean, they'll know if you know.
Joe SlowikOr they'll have a understanding that certain things have been disclosed, but also just because it's been disclosed that, oh, the you know, the mechanisms used by Volt Typhoon to uh like I was describing earlier to compromise domain controllers to leak active directory credentials, they still work, they're still effective. Um, you know, we can put detections in place in order to try to identify that activity, but it's still difficult for most organizations to effectively apply them in a way that minimizes noise for responders. So it's an interesting tension, um, the dilemma between intelligence disclosure, like get information out to as many hands as possible so that we can enable people to respond, understand, and defend against these activities versus hold withholding that information or keeping it close hold only very specific circles to maintain that information and its validity. And there is a definite balance that needs to be struck between the two. It is not an either-or proposition. I think, given the potentially widespread nature of Vault Typhoon operations, at least within North America and North American-related interests, that we are in a position where wider disclosure is merited as opposed to withholding information given how opportunistic this group has been in targeting not just the electric sector, but potentially the water and wastewater sector, and even potentially moving into the oil and gas sector uh over the last year as well.
Robby PeraltaThere's certain political powers in the US that don't really want it that to be uh talked about right now, maybe.
Joe SlowikSo it's at the time that we're speaking, it's the 21st of October or whatever. No one's working right now anyway because the government shut down.
Robby PeraltaThat's another story. They're working, but they're not getting paid, right?
Joe SlowikUh this is true. Yeah. Some people are working, but those people aren't getting paid.
Robby PeraltaWhat a world we live in right now. Um I want to talk now more about uh the ecosystem for like salt typhoon. I read the other day that there's uh almost just as many Chinese cybersecurity companies as there are Western or something like that. So can you say something about their ecosystem, how that's evolved over since you've been tracking them?
Joe SlowikSo thinking about things like the domestic PRC vulnerability and exploit development marketplace is vast. Uh, and includes incentives, political and legal incentives, to keep that information either close hold within PRC circles or for initial discussion. Disclosure to PRC authorities instead of disclosure to the actual companies. So thinking back, you know, for folks who remember the Log4J incident, that was initially identified by PRC researchers, and they got in trouble for it because they disclosed it to the Apache Foundation or whoever controls that code. I'm throwing a blink right now. The proper part when they were right. When they were supposed to initially disclose that to the PRC government, and then after a cooldown period, can then pass that on to uh whoever the actual vendor or maintainer is, which is a very interesting relationship thinking about things like vulnerability equities and the ability to weaponize some of these items potentially. I mean, it's notionally for like, oh, so before there's public disclosure, that we can patch our own networks and orient our own defenses. But I think everyone kind of realized that like there's a real good opportunity to make sure that there's a no one but us uh concept of being able to exploit and take advantage of that before widespread disclosure, patch development, and patch deployment. So that's one area, including the development of PRC analogs to Pwn to Own and similar sorts of activities. But then also, I think what people are waking up to is this vast network of research institutions, companies, and contractors that underpin uh domestic and foreign intelligence and law enforcement operations within the PRC ecosystem. Uh companies that no one outside of those who are closely tracking these sorts of things has ever heard of before, but you know, a very large network of very capable organizations uh involved in this activity. Uh it was interesting. There was an uh article, an interview with the directors of the Dutch military and um civilian intelligence agencies in Volksgrant that came out late last week, earlier this week, I can't remember exactly when. Uh, and you know, the Dutch intelligence agencies are pretty good in the cyber realm and have done some interesting stuff over the years. And there was a comment made that was quickly walked back about from the, I believe, the director of the Dutch military intelligence agency of basically saying at this point, like the Chinese cyber ecosystem is about as good uh and certainly larger than the US uh cyber ecosystem when it comes to things like hacking and offensive operations. Whereas I think most, you know, historically you'd have seen like, oh, US, UK, Israel, Russia, China, or some similar sort of ranking. But uh the People's Republic of China has invested heavily, has the talent, has the capabilities that I don't think anyone should be sleeping on on them or thinking there's some sort of qualitative advantage that uh Western organizations have vis-a-vis PRC cyber operations anymore.
Robby PeraltaYeah. Anyone that knows what they're talking about doesn't adopt them anymore. That's for that's for damn sure. Uh while you were talking about the like the competitions pon't own, but for the governments, and I just thought of F5 right now. Like that that could be a great example of that, right?
Joe SlowikWell, it's also an interesting example because the nature of that intrusion, uh, as reported by Bloomberg uh a few days ago, the F5 network was breached as early as 2023 and only discovered in August of this year. And during that time, threat actors had access to source code, development work, and similar related to devices and software like the F5 big IP load balancers and similar, which are typically high availability, um, high-significance devices that are external facing and thus externally accessible. So that's interesting for a number of reasons, whether you're thinking about potential supply chain concerns, which have largely been uh dismissed so far, although that always gives me a kind of uneasy feeling that when someone has access to source code, it's like, oh, what did they do? But definitely in the terms of being able to, you know, you think about vulnerability development and fuzzing that you're typically dealing with compiled software and similar and just like throwing things at it to see when it bounces or you know when something bad happens. But if you could review what people have actually written, just do a code review. Uh, I mean it's not easy, but it's easier than trying to reverse engineer uh what has been put out there in order to find logic flaws and similar and to have access to that for a couple of years is concerning.
Robby PeraltaSomebody told me once that they have teams of people that are dedicated to vendors and just breaking that and doing things. Yeah, you think that's a thing as well?
Joe SlowikUnless we hit um Yeah. You know, you think about large, complex, well-resourced organizations that are dedicated to things like exploit and capability development for state-sponsored, state-controlled threats or contractors providing that service. Here's your Microsoft shop, here's your Cisco shop, here's your F5 shop, etc.
Robby PeraltaWow. It's kind of like the good guys, but just the the bad guys. That's a crazy to think about. Uh what is going on in the OT industry besides like nation states up between US versus China? Is there anything else that's you just think that is interesting that has nothing to do with Vault and South Typhoon and all these typhoons?
Joe SlowikSo an area of research I want to pick up next aligns with this, that there is a expanding gray space or non-state space that is starting to become concerning. Typically, people refer to these groups as hacktivists and their relationships to or the degree of sponsorship by state entities or whatever is either pretty obvious or questionable depending upon what group you're talking about, thinking about like Z Pentest or Infrastructure Destruction Squad and similar to name a couple. Um historically, I've considered these to be more computer network annoyance than computer network attack entities, like oh, they're going to deface a web page or DDoS you or something similar, which has implications behind it. It's not something just completely write off, but generally speaking, not the biggest threat in the world. However, these groups are becoming a little more concerning, both in terms of reach and in terms of at least claimed capability development. And given that there remains a long tail of internet accessible or weakly protected OT equipment, especially in sectors like water and wastewater, um, but also extending into some items in electric manufacturing, um, key areas like agriculture and similar, that there's a non-trivial space for these entities which do not have and will not develop the capabilities like a pipe dream in controller or a Stuxnet or a crash override anytime soon. But there's enough for them to be dangerous for civilian infrastructure. So it's easy for I think certain thought leaders, a term that I tend to use pejoratively, um, to say that the OT threat is overhyped. And I'll admit, like to a certain extent, it is kind of overhyped in certain respects. But overhyped doesn't mean non-existent. And there really are entities out there that are probing in critical infrastructure that have capabilities to take advantage of weakly protected or uh externally exposed assets to potentially cause real harm. And I think this is where both sides, you know, I'm gonna both sides this argument, uh, can do better. That on the one hand, screaming from the rooftops that the sky is falling and you know the end is nigh isn't helping anyone, um, which some entities do to an extent, which is unfortunate. But the reaction, the overreaction to that of saying, like, oh, this is all bunk and we don't need to worry about this or it's non-existent, isn't doing any anyone any favors either. And as with many things in life, the reality lies somewhere between those extremes. That whether we're talking about the vault typhoons, the sandworms, or similar of the world, or talking about the infrastructure destruction squads and similar, that people are actively poking about this, and there's sufficient publicly available information uh documenting some of this activity. And then there is even more information that is not public for one reason or another that goes into depth for how these threats are operating. So, yeah, the truth is out there, but it's accessibility uh to all isn't necessarily there. But there's also this sense that would you really expect it's not just a US government thing, but a Dutch, a Norwegian, a German, a Japanese government thing, like lots of states and lots of authorities are emphasizing risk to critical infrastructure. I don't think they're all simultaneously wrong to do so. So there is almost certainly some fire uh underneath the smoke that we're seeing, and just the fact that we cannot completely glimpse it doesn't mean that it's not there.
Robby PeraltaYeah. So you that was like hacktivism, but what about financially motivated crime or threat actors? Do they dabble in this space or are they just kind of scared of it?
Joe SlowikSo if you went back five or six years, people, including myself to a certain extent, would have said ransomware operators aren't going to touch critical infrastructure because the risks are too great, and that's how you get law enforcement to kick down your door. Well, um, we've seen opportunistic exploitation of things like municipalities and similar that own and operate critical infrastructure environments, largely at an IT level, not actually getting into production networks, but it still has implications for uh operations in that industrial level. So there certainly are financially motivated things that are impacting critical infrastructure, but outside of the hacktivist space, we haven't seen anything, or I'm not aware of too many things that have directly and specifically gone after, you know, we're going to try to disrupt industrial operations or similar. However, we've seen maybe not in electric, water, power, et cetera, uh, but certainly in manufacturing, still dealing with the fallout from what happened at Jaguar Land Rover in the United Kingdom. So financially motivated entities are definitely more than willing to operate in spaces that result in physical disruption, even if it's indirect in nature, uh, and having an understanding of what those dependencies look like and the ability to maintain operations in the face of having more accessible assets and networks compromised and disrupted is a critical item. Um, so I look at the financial side of things as still being very opportunistic in nature. You know, you think about the scattered spiders of the world, like we're gonna go after airlines, and now we're gonna go after insurance companies, and you know, oh, we just happen to have credentials or you know, we were able to fish or whatever this organization, so we're gonna go after them. Uh, but it's definitely an area that organizations need to be aware of and planning for because we've seen the severe impacts that can result uh from this sort of an interruption.
Robby PeraltaAnd just speaking about your scattered spider and their techniques are totally different than what you would expect from somebody like Wolf Typhoon, correct? So it's it's a large array of things. No, really, okay.
Joe SlowikNot necessarily. So initial access, yes. So set scattered spider is uh historically very well noted for their social engineering capabilities. But once they're in networks, they've leveraged the information gathered through social engineering, like credential information, multi-factor authentication tokens, and similar, to then operate in ways that are very similar to how Volt Typhoon operates. So we've seen this convergence by multiple different types of threat actors towards this living off the land, leveraging built-in system tools, mimicking administrator actions and similar to burrow into networks without deploying much in the way of any sort of custom tooling, or even in many cases, what we would expect of you know, uses of pen tester tools like Mimicats and Cobalt Strike and similar.
Robby PeraltaAm I right to assume that the initial access part of the kill chain is a lot bigger than the works for MITRE, obviously know this, but like the ones are in that must be thinner than the initial access, correct? So it's only that many things you can do.
Joe SlowikNot necessarily. Uh there's still quite a degree of diversity around behaviors, but it's interesting in looking at what behaviors are actually implemented by threat actors. Uh if you map out at least public disclosure of mapped attack techniques to adversaries, that you see a very definite clustering around the same set of common uh methodologies like exploiting public applications or credential use to get in. And then once in a network, extensive use of things like cmd.exe, PowerShell and such for command execution, uh, and a lower degree of some more esoteric techniques, which are still in use, just not commonly, because most adversaries don't need to go that far uh in order to be effective.
Robby PeraltaAnd I would assume all that heat mapping or the where all the activity is concentrated around, those are like the cheapest and most effective, and like the the lowest hanging fruits, I guess.
Joe SlowikYep. Adversaries aren't incentivized to do the most fancy or complex attack, they're just incentivized to do what works.
Robby PeraltaThey have a budget as well, I guess. Like we all do. So is there anything about the conference that you're looking forward to?
Joe SlowikYeah, it's as usual a packed agenda for ISC Copenhagen. So looking forward to the talks to the extent I'm able to attend them. What I find interesting this year is the event features a lot of hands-on material, including a workshop that I'll teach on analyzing network objects. So I'm really curious to see how the event shifts in terms of uh having a lot of practitioner-focused items or hands-on items to develop, teach, and upskill the community. So it'll be interesting to see how that works out because it if I'm remember the agenda correctly, on the second and third day, there's a lot of workshop material. So it'll be real interesting to see the reception and how that helps build community and build capability across the sectors that are attending.
Robby PeraltaAnd last question do you uh the next one to two years, 2027 is two years away now. Do you think the OT space is gonna like explode the next couple of years due to geopolitical matters?
Joe SlowikSo 2027 is an auspicious date to pick because depending on who you talk to, there is a artificial, well, not really artificial, but a semi-publicly designated timeframe that the People's Republic of China, if you look at statements of some officials, has set a deadline of being able to invade the island of Taiwan by 2027. Whether that means something is going to happen in 2027, I don't think so, but the possibility is certainly there. And then we still have ongoing things like Russian operations, not just in Ukraine, but throughout Europe these days, disruption, sabotage, and similar are very real sorts of things. It's been quiet-ish in terms of headline events in the OT space, like another Triton crash override or similar. We're due, I think, and there's enough going on right now that we will see another headline event in the near future. Uh, of course, people have been saying that since Stuxnet was disclosed almost 15 years ago at this point, and we still only have you know less than 10 incidents that we can point to that are really you know high level uh in nature. But you know, whether that's because we just haven't seen them, they haven't detected them, or they don't exist is an open debate. But I'm thinking the time is getting close and there's enough stuff going on that we'll either finally learn of something that's taken place or it'll be pretty obvious. Although you could argue that we've already seen some things like the steel mill incident that happened in Iran, that famous sparrow took credit for, uh, that they launched an attack that destroyed a steel uh mill complex. No tech real technical details on it, unfortunately. I don't suspect the Iranian government is going to publish a nice white paper summarizing the event anytime soon, but or refuted for that matter, but you know, there are things that have been going on around the margins, and I think it's just a matter of time before we see something pop up that gets a little bit more attention and we have a little bit more information to share on these sorts of incidents.
Robby PeraltaIt would be back to what we're talking about earlier with the ecosystem in China. It'd be naive to think that there aren't highly specialized OT pen testing groups of people operating. Or is it naive to think that they wouldn't be working together with their friends, Russia, for example?
Joe SlowikI don't know. That's an interesting question. And this came up not from a China-Russia nexus, but from a Russia-Iran nexus around the Triton event of like, oh, you know, would these be work entities be working together and sharing information and such? These are fairly complicated uh capabilities that also have a certain level of uh almost like an expiration date around them that if used can lead to disclosure. Once disclosed, can then lead to the negation of those capabilities. I think relationships where those such information gets shared to any significant extent are very rare in existence. And while it might be possible, and we've certainly seen collaboration from Russia with other entities to help fuel its efforts in the invasion and uh bombardment of Ukraine, whether it's you know missiles and artillery shells and similar, and giving up things like more advanced technology in exchange. I don't know. I I I don't see it as being likely, but I certainly think it's more plausible now than I would have argued a couple of years ago. It's expensive to share.
Robby PeraltaBut sometimes you can call in the favor, but you can't call in the favor all the time.
Joe SlowikRight.
Robby PeraltaWell, Mr. Slowik, uh, as always, thank you for your time. Thanks. And I'm looking forward to continuing the conversation in uh in a bar in Copenhagen.
Joe SlowikSounds like a plan to me. See you then. Thanks. Okay, sounds good Robby.
Robby PeraltaWell, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.no. Thank you for listening. We'll see you next time.