Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

Yeah, I mean, it could.

Darknet Diaries
174: Pacific Rim

And that was one of the reasons that I was brought in basically on day zero of this happening.

Darknet Diaries
174: Pacific Rim

The company realized that they had a potential public relations nightmare on their hands, and they needed to communicate as openly and as forthrightly as possible everything that they knew and everything that they were doing to fix it.

Darknet Diaries
174: Pacific Rim

And credit goes to the people in leadership at the company who decided that

Darknet Diaries
174: Pacific Rim

possibly against the conventional wisdom at the time, that they were going to go public with everything we knew about this attack.

Darknet Diaries
174: Pacific Rim

It was not a common thing at that time.

Darknet Diaries
174: Pacific Rim

But as I said, I've worked for a long time in this kind of role where I do investigations and then publish about them to the public to warn people about bad things that are happening on the internet.

Darknet Diaries
174: Pacific Rim

It's been my experience that the more information that you get out, the better protected people are.

Darknet Diaries
174: Pacific Rim

And that being radically transparent benefits everyone.

Darknet Diaries
174: Pacific Rim

It helps the customers who are affected.

Darknet Diaries
174: Pacific Rim

It also warns the public that like, hey, this is something that you need to be aware of in the future.

Darknet Diaries
174: Pacific Rim

And it might also put the threat actors on notice that, hey, we're watching you and we're taking action to stop you.

Darknet Diaries
174: Pacific Rim

Yeah, so there's a lot of interest within the company.

Darknet Diaries
174: Pacific Rim

Well, we know that there's these firewalls that have been registered to people who have non-corporate or non-enterprise level email addresses, like free webmail addresses.

Darknet Diaries
174: Pacific Rim

The firewalls are checking in all from Chengdu.

Darknet Diaries
174: Pacific Rim

We know their serial numbers, so we know the exact count of the number of firewalls that are being used in these places.

Darknet Diaries
174: Pacific Rim

And we could see from some of the log telemetry that the threat actors are running commands that are testing how these exploits are going to work.

Darknet Diaries
174: Pacific Rim

But we don't have the exploit code itself.

Darknet Diaries
174: Pacific Rim

So the security team decides they're going to build something that they just call the implant, or sometimes they call it the kernel implant.

Darknet Diaries
174: Pacific Rim

And it's a small elf binary that gets distributed only to the machines