Risky Business Weekly (804): Phrack's DPRK hacker is probably a Chinese APT guy

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Australia expels Iranian ambassador
  • Hackers sabotage Iranian shipping satcoms
  • APT hacker got doxxed in Phrack. Kind of. They’re probably Chinese, not DPRK?
  • Trail of Bits uses image-downscaling to sneak prompts into Google Gemini
  • The Com’s King Bob gets ten years in the slammer
  • It’s a day that ends in -y, so of course there’s a new Citrix Netscaler RCE being used in the wild.

This week’s episode is brought to you by Corelight. Chief Strategy Officer Greg Bell talks through how they’ve been implementing AI for sifting through your network data. A model-context-protocol server that can rummage in all those packet logs for you while you keep investigating? Yes please.

Show Notes:

Embassy staff flee Canberra in dead of night | news.com.au — Australia’s leading news site for latest headlines https://www.news.com.au/national/iran-ambassador-expelled-fromaustralia-anthony-albanese-accuses-nation-of-directing-antisemitic-attacks/news-story/9f552080e7aa76f06f15ce3271bc6862

Swedish security service says Iran uses criminal networks in Sweden | Reuters https://www.reuters.com/world/swedish-security-service-says-iran-uses-criminal-networks-sweden-2024-05-30/

Risky Bulletin: Hackers sabotage Iranian ships at sea, again - Risky Business Media https://risky.biz/risky-bulletin-hackers-sabotage-iranian-ships-at-sea-again/

Microsoft scales back Chinese access to cyber early warning system | Reuters https://www.reuters.com/sustainability/boards-policy-regulation/microsoft-scales-back-chinese-access-cyber-early-warning-system-2025-08-20/

Microsoft Didn’t Disclose Key Details to U.S. Officials of China-Based Engineers, Record Shows — ProPublica https://www.propublica.org/article/microsoft-china-defense-department-cloud-computing-security

.:: Phrack Magazine ::. https://phrack.org/issues/72/7_md#article

Uncovering the Chinese Proxy Service Used in APT Campaigns https://spur.us/how-spur-uncovered-a- chinese-proxy-and-vpn-service-used-in-an-apt-campaign/

Weaponizing image scaling against production AI systems -The Trail of Bits Blog https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/

FBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations | Cybersecurity Dive https://www.cybersecuritydive.com/news/russia-hacking-cisco-switches-fbi-warning/758206/

CrowdStrike warns of uptick in Silk Typhoon attacks this summer | CyberScoop https://cyberscoop.com/crowdstrike-silk-typhoon-murky-panda-china-espionage/

Kevin Beaumont: “There’s a bunch of new Netscal…” - Cyberplace https://cyberplace.social/@GossiTheDog/115095063936712306

US charges Oregon man in vast botnet-for-hire operation | Cybersecurity Dive https://www.cybersecuritydive.com/news/us-charges-oregon-man-botnet-for-hire/758293/

South Korea arrests suspected Chinese hacker accused of targeting BTS singer and other celebrities | The Record from Recorded Future News https://therecord.media/south-korea-arrests-hacker-accused-of-targeting-celebrities-bts

SIM-Swapper, Scattered Spider Hacker Gets 10 Years – Krebs on Security https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/

Chinese national who sabotaged Ohio company’s systems handed four-year jail stint | The Record from Recorded Future News https://therecord.media/chinese-national-sentenced-prison

Nevada state offices close after wide-ranging ‘network security incident’ | Reuters https://www.reuters.com/world/us/nevada-state-offices-close-after-wide-ranging-network-security-incident-2025-08-26/

DSLRoot, Proxies, and the Threat of ‘Legal Botnets’ – Krebs on Security https://krebsonsecurity.com/2025/08/dslroot-proxies-and-the-threat-of-legal-botnets/

Russia weighs Google Meet ban as part of foreign tech crackdown | The Record from Recorded Future News https://therecord.media/russia-google-meet-ban-crackdown

Kremlin-Mandated Messaging App Max Is Designed To Spy On Users https://www.forbes.com/sites/thomasbrewster/2025/08/26/kremlin-whatsapp-rival-is-designed-to-spy-on-users/

Иеромонах РПЦ Макарий призвал помолиться за мессенджер MAX https://glavny.tv/last-news/russia/ieromonah-rpts-makariy-prizval-pomolitsya-za-messendzher-max/