Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Jack Rhysider

๐Ÿ‘ค Speaker
534 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
135: The D.R. Incident

And that would be a form of ransomware, wouldn't it be? No, this was just a hypothetical. I have no idea if Putin has any relations with the Dominican Republic. At some point, do you contact the president and say, hey, we've got a really big deal. It's not just your normal malware, but this is a geopolitical problem.

Darknet Diaries
135: The D.R. Incident

And that would be a form of ransomware, wouldn't it be? No, this was just a hypothetical. I have no idea if Putin has any relations with the Dominican Republic. At some point, do you contact the president and say, hey, we've got a really big deal. It's not just your normal malware, but this is a geopolitical problem.

Darknet Diaries
135: The D.R. Incident

Of course, attribution is very hard when it comes to cyber attacks. It's incredibly easy to hide in the shadows on the internet. So even though there are some things that point to this being Russia and dark caracol, How confident can you really be? Especially when you're on the phone briefing the president. Maybe someone else just got a hold of the Bandook malware or Conti ransomware.

Darknet Diaries
135: The D.R. Incident

Of course, attribution is very hard when it comes to cyber attacks. It's incredibly easy to hide in the shadows on the internet. So even though there are some things that point to this being Russia and dark caracol, How confident can you really be? Especially when you're on the phone briefing the president. Maybe someone else just got a hold of the Bandook malware or Conti ransomware.

Darknet Diaries
135: The D.R. Incident

Maybe someone wants you to think that it was those threat actors attacking you just to throw you off the scent. Because we've seen threat actors put in fake clues to do just that before. For this situation, there were a lot more questions than there were answers. If Dark Caracol is Lebanese-based, why would they be working with Russia or Conti?

Darknet Diaries
135: The D.R. Incident

Maybe someone wants you to think that it was those threat actors attacking you just to throw you off the scent. Because we've seen threat actors put in fake clues to do just that before. For this situation, there were a lot more questions than there were answers. If Dark Caracol is Lebanese-based, why would they be working with Russia or Conti?

Darknet Diaries
135: The D.R. Incident

Was this financially motivated or politically motivated? This attribution wasn't exactly clear, and neither are the motives.

Darknet Diaries
135: The D.R. Incident

Was this financially motivated or politically motivated? This attribution wasn't exactly clear, and neither are the motives.

Darknet Diaries
135: The D.R. Incident

Does Lebanon and Dominican Republic have any relations?

Darknet Diaries
135: The D.R. Incident

Does Lebanon and Dominican Republic have any relations?

Darknet Diaries
135: The D.R. Incident

Hold on. How can the president of the Dominican Republic be from Lebanon? Let me look this up. Okay. His grandfather was born in Lebanon and moved to the Dominican Republic in the 1800s. It was not clear to me, at least, if he's still tied to Lebanon in any way, shape, or form. I mean, I couldn't even find out if he can speak Lebanese, you know?

Darknet Diaries
135: The D.R. Incident

Hold on. How can the president of the Dominican Republic be from Lebanon? Let me look this up. Okay. His grandfather was born in Lebanon and moved to the Dominican Republic in the 1800s. It was not clear to me, at least, if he's still tied to Lebanon in any way, shape, or form. I mean, I couldn't even find out if he can speak Lebanese, you know?

Darknet Diaries
135: The D.R. Incident

But it seems like only weeks after he was elected as president is when this attack happened. So maybe this has something to do with Lebanon sending a message to the president. My mind is spinning here, and I don't want to make any wild assumptions.

Darknet Diaries
135: The D.R. Incident

But it seems like only weeks after he was elected as president is when this attack happened. So maybe this has something to do with Lebanon sending a message to the president. My mind is spinning here, and I don't want to make any wild assumptions.

Darknet Diaries
135: The D.R. Incident

At the very least, I'm reminded of how Costa Rica's president declared war on Conti, and now I can see that that's not so far-fetched of an idea anymore.

Darknet Diaries
135: The D.R. Incident

At the very least, I'm reminded of how Costa Rica's president declared war on Conti, and now I can see that that's not so far-fetched of an idea anymore.

Darknet Diaries
135: The D.R. Incident

At this point, Omar had a very good understanding of this campaign and malware, and he even reverse-engineered some of the malware, inspected it for clues, and looked at their command and control servers, and had a full map of where the infections were and how they were moving around the network.

Darknet Diaries
135: The D.R. Incident

At this point, Omar had a very good understanding of this campaign and malware, and he even reverse-engineered some of the malware, inspected it for clues, and looked at their command and control servers, and had a full map of where the infections were and how they were moving around the network.

Darknet Diaries
135: The D.R. Incident

On top of that, vendors started to improve their systems, issuing patches and updates and better ways to detect this. So he got together with all the teams inside the agencies that were infected and explained the remediation process. Step by step, he walked them through how to remove this and stop this from happening again. And he also called the ISP to have them block certain domains.

Darknet Diaries
135: The D.R. Incident

On top of that, vendors started to improve their systems, issuing patches and updates and better ways to detect this. So he got together with all the teams inside the agencies that were infected and explained the remediation process. Step by step, he walked them through how to remove this and stop this from happening again. And he also called the ISP to have them block certain domains.