Newsletters

Written content from the Risky Business Media team

China's AI-Enabled APT Operations Are Getting Interesting

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

A new report describes how a Chinese cyberespionage outfit is using AI to beef up its malware arsenal. If this is a sign of things to come, clustering threat actor behaviour together for attribution purposes is about to get a lot harder.

The Bitdefender report, released last week, describes seven remote access tool (RAT) families. All seven were created by a single cyberespionage actor Bitdefender called SilkParasite and five were previously undocumented. The report authors have medium confidence that SilkParasite is, ahem, a "China-nexus actor" targeting governments across Central Asia including Uzbekistan, Turkmenistan and Kazakhstan. 

Back in November we wrote about what looked like an experiment to see how AI-assisted hacking could support China's Ministry of State Security. The approach those threat actors took at the time was to build an attack framework and let Claude do the hacking. It was error-prone and noisy, but sometimes successful.

Risky Bulletin: Russia starts blocking DoH and DoT

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Russian internet users started reporting issues with connecting to DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) servers, suggesting the government might have cracked down on the two protocols.

Both DoH and DoT are privacy-centric versions of the DNS protocol that hide a user's DNS queries and intended destination from ISPs and other threat actors on the wire.

Both protocols have seen increased usage in Russia. They are typically used together with a VPN client as a way to bypass the Kremlin's ever-increasing and overbearing internet censorship, and access Western websites.

Risky Bulletin: Expired cards can be used for new transactions

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A team of academics from the University of Massachusetts Amherst have developed an attack that can revive old expired contactless cards to perform new (illegal) transactions.

The attack exploits the fact that NFC card data is not fully encrypted when making a payment and some parameters can be modified without breaking the card's digital hash/signature.

The researchers created a rig that intercepts transaction data through an NFC Man-in-the-Middle attack, updates the expiration date, and relays the modified payment to a Point-of-Sale (POS) terminal.

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A team of American academics have found source code overlaps between the products of a Chinese tech company and the country's Great Firewall traffic filtering and censorship system.

According to research presented at this year's USENIX security conference, the Chinese government is using the Geedge Networks Tiangou Secure Gateway (TSG) device as one of the Great Firewall's three known traffic filtering capabilities.

Researchers linked Geedge's device to the Great Firewall after more than 100,000 files leaked from Geedge's network last year.

Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The US government’s plan to enlist private sector hackers to target cybercriminals is controversial, but it addresses a real problem and is surprisingly measured.  

Last week, a presidential memo directed the Department of Homeland Security to establish a program authorising private companies to conduct cyber operations against so-called "Cyber-Enabled Transnational Crime Organisations" or CE-TCOs. The memo sets out the broad shape of the arrangement and a classified annex further details the logistics. 

The huge policy shift here is that private companies will be authorised to conduct cyber operations that were previously restricted to state entities. This includes what the memo calls "cyber surveillance" (intelligence gathering operations) and "cyber effects" operations, (intended to manipulate or to cause disruption).

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.

The agency says the cameras contain a backdoor mechanism that grants shell and network access to the devices via an SMS message received from a list of hardcoded Russian phone numbers.

The NBU started an investigation into the devices after the country's opposition accused the government of buying the cameras from Russia and after multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The European Telecommunication Standards Institute has released 17 cybersecurity standards that vendors will have to follow to sell products in the EU when the EU Cyber Resilience Act enters into effect in December of 2027.

The standards cover 17 core technologies for major product categories such as:

The standards describe a list of minimum security features each product category must implement to be CRA-compliant.

Risky Bulletin: White House lets private companies carry out offensive cyber ops

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In a presidential memo this week, the White House has directed the Department of Homeland Security to establish a program through which private sector companies can carry out offensive cyber operations on behalf of the US government against cybercrime organizations.

The new program will run under the DHS National Coordination Center (DHS NCC) and under oversight of both the Department of Justice and the Department of Homeland Security.

Private companies will be able to apply and receive specific tasks from the two agencies on what and who they can hack—to prevent rogue behavior from the private sector.

Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The cybercriminal ecosystem is increasingly focussing on data theft and extortion rather than locking up victims' files. That criminals have stumbled across a new lucrative business model is a bittersweet win in the fight against disruptive, encrypting ransomware. Data theft extortion isn't great, but it doesn't leave widespread chaos in its wake like ransomware can.

Silent Ransom, aka Luna Moth, is one group currently making big bucks from data theft extortion. Last week The Cyber Risk Insurer reported two law firms had paid substantial ransoms to the group this year: Goodwin Procter and WilmerHale, which paid USD$10 million and $USD18 million respectively. 

Silent Ransom has been targeting law firms since 2023. It historically used phishing and convinced victims to install legitimate remote access software which was then used to steal sensitive data. In the last year, however, they've brazenly sent people to compromise systems in person by posing as IT support staff.

Risky Bulletin: Russian hackers adopt the fake job interview tactics

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

One of Russia's elite military hacker groups is targeting system administrators and IT professionals in Ukraine using fake job interviews as a malware delivery vector.

Ukraine's CERT says the campaign began in May and is ongoing.

The attacks have been linked to UAC-0145, a sub-group of Sandworm, a veteran cyber unit inside Russia's GRU military intelligence agency.