WEBVTT

1
00:00:00.100 --> 00:00:09.020
It starts with a Telegram account, and it's, the Telegram account has been taken over by the threat actors. It used to belong to, like, a real person, like you.

2
00:00:09.640 --> 00:00:18.500
When you get on the call, their scam version of Zoom will basically tell you that your audio device, it can't hear you, your audio device isn't working, you need to do something.

3
00:00:18.840 --> 00:00:24.810
And then the threat actor will also be in Telegram being like, "I can't hear you. Like, I see you, but I can't hear you. What's going on?"

4
00:00:25.140 --> 00:00:34.020
They then prompt you to download an AppleScript usually, which just completely wrecks your computer with, like, the deepest malware. They're very helpful. These scammers are very helpful.

5
00:00:34.180 --> 00:00:36.220
They'll help you troubleshoot your issue.

6
00:00:36.250 --> 00:00:47.780
[chuckles] And they helped, they helped me troubleshoot a little bit pretty well because I ha- I, the, uh, my Mac's permissions were set up in such a way that the original link did not automatically download the malware, so I had to run the script through Terminal.

7
00:00:47.810 --> 00:00:56.750
Oh, yeah. I feel more on in retrospect 'cause that should've been, you know, the alarm bell- Yes... going off. But everything else up to that point, like, I have a chat history with this person. Mm-hmm.

8
00:00:57.089 --> 00:01:06.000
It's a friend and a former colleague. There was the video of him. The video was weird because it's not like, it's o- obviously not a live feed, and you mentioned that they're not deepfakes.

9
00:01:06.040 --> 00:01:14.740
They're actually recorded videos, which is also really freaking, freaking terrifying. And the whole thing had a weird feel about it, but I was up super early.

10
00:01:14.780 --> 00:01:18.510
I was also taking care of my daughter at the time, and so- Yeah...

11
00:01:18.510 --> 00:01:27.780
I just, there were so many inputs I wasn't thinking about, and it just goes to show how freaking crazy some of these phishing attacks have become, and this one is by far the most sophisticated I've ever seen.

12
00:01:27.960 --> 00:01:33.000
[tense music] Welcome back to the Blockspace Pod brought to you by CleanSpark.

13
00:01:33.340 --> 00:01:46.080
The North Korean hacking syndicate Lazarus Group has stolen more than three hundred million dollars in crypto in the last year alone using a highly sophisticated phishing attack that targets users' Telegram accounts.

14
00:01:46.520 --> 00:01:57.600
I was personally victimized by this phishing attack in December. I didn't lose any coins as a result, but I did lose access to my nearly ten-year-old Telegram account as a result.

15
00:01:57.740 --> 00:02:07.380
To diagnose this problem and explain how users can shield themselves against it, I wanted to have on Taylor Monahan, today's guest, who is a security lead at MetaMask.

16
00:02:07.920 --> 00:02:26.560
Taylor has been not just spearheading efforts to track down how many users have been affected and map out a web of those infections, but also to target the hackers themselves and try to frustrate their attempts by stealing their payloads and kind of DDoSing them by trolling them over Zoom calls.

17
00:02:26.940 --> 00:02:47.200
If you've heard about this attack, if you've been a victim to it, I highly recommend listening to this podcast because Taylor gets into the nitty-gritty of just how this phishing attack works, what the malware does, and why it's so hard to find on Mac devices, and also how they know that this is probably North Korean actors behind this attack.

18
00:02:47.380 --> 00:03:02.920
You're listening to the Blockspace Pod. Enjoy the episode, y'all. [upbeat music] Taylor Monahan, welcome to the Blockspace Pod. How you doing? Good, good. How are you? Uh, I've been better.

19
00:03:03.240 --> 00:03:08.630
[laughs] Luckily, I didn't have my life savings stolen 'cause I use hardware wallets for mostly everything. Mm.

20
00:03:08.680 --> 00:03:18.820
I did have Telegram a- attacked and compromised, and you actually pointed out before we hopped on that you noticed that because we have a chat history going back to at least twenty nineteen when I was at Bitcoin Magazine.

21
00:03:18.920 --> 00:03:27.450
Um, for those who don't know, Taylor was a fantastic resource for the QuadrigaCX hack, or not hack, rather... Well, we still don't really know what happened. We don't know.

22
00:03:27.480 --> 00:03:29.580
[chuckles] But with the exit scam at QuadrigaCX.

23
00:03:30.280 --> 00:03:42.860
But anyway, so I, I've actually was a victim of this phishing attack, and I didn't realize how widespread it was until we started DM'ing, and I started looking at how much documentation you've done for it.

24
00:03:42.940 --> 00:03:53.120
So before we get into the details, can you give our listeners a breakdown of exactly what this attack is and how it works? Yeah, absolutely.

25
00:03:53.780 --> 00:04:00.890
And so obviously, like, we're gonna focus on, like, one very narrow sort of most interesting sector, but, like, this is...

26
00:04:01.420 --> 00:04:13.820
The attack in general is, like, has many flavors, and so if you are aware of this [chuckles] and stay aware of it, you'll protect yourself from, like, a huge number of scams and attack vectors.

27
00:04:13.920 --> 00:04:19.060
Um, and so the first thing to know is that it starts with either

28
00:04:20.060 --> 00:04:33.540
a Telegram account or a LinkedIn or a Twitter, usually Telegram these days, and it's, the Telegram account has been taken over by the threat actors, and it used to belong to, like, a real person, like you.

29
00:04:33.560 --> 00:04:43.700
[chuckles] Uh, and you use the Telegram account to have conversations with people. Um, we found that they really like, for people who go to conferences, this is, like, a common experience.

30
00:04:43.760 --> 00:04:54.580
You meet someone at the conference for a minute, you have, like, a great conversation, and then you'll exchange Telegram handles, but you'll DM each other initially with, like, with, like, a selfie or like a, "Hey, what's up?

31
00:04:54.620 --> 00:04:55.750
We should catch up later."

32
00:04:56.420 --> 00:05:14.000
When they get their hands on, like, one of those accounts, they go to town because that type of person has, like, hundreds, thousands of these messages, and they'll just go through, and they'll re-up the conversation as if they were that person.

33
00:05:14.680 --> 00:05:22.620
So that's step one is they, they get the, they get the account, this legitimate account that already has connections and followers and, and, and message history.

34
00:05:22.680 --> 00:05:37.660
Step two is that they will just mass DM everyone in, like, everyone, everyone. Right now, their favorite, like, message to send is something about, like, Happy New Year, and so they're like, "Happy New Year.

35
00:05:37.820 --> 00:05:48.940
Let's catch up." During, like, other parts of the year, they'll usually, like, just be more generic, but it's generally something like, "We haven't spoken in a long time. I hope you're doing well. Let's catch up."

36
00:05:49.240 --> 00:06:03.340
Super casual. They're not pushy. They don't write essays. They just drop a little ping, and then if you respond to that, they will then, like, share a Calendly link or ask you for your calendar and set up a call.

37
00:06:04.220 --> 00:06:16.700
And so-That interaction is like a very normal interaction, and it's very hard for people to detect that this is a scam because it's literally the legit Calendly legit interaction with an account that you have messages through with.

38
00:06:16.900 --> 00:06:23.720
Okay, then the third part is the call itself, and the call itself is, is super sneaky.

39
00:06:24.820 --> 00:06:39.840
One thing that they also do, which is like it just, it blows my mind, but it's like very effective at disarming people, they will often reschedule the calls or delay the calls just like a normal person does.

40
00:06:39.880 --> 00:06:50.800
And it's the most off-putting thing because even if you're like, "I don't know, this might be s- a scam," this, this person like they'll like wait a week to get on the call and then they'll push it last minute.

41
00:06:50.820 --> 00:06:57.840
They'll be like, "Hey, sorry, can we meet in 30 minutes?" Or can be like tomorrow. Yeah, it'll be like, "Oh, my really busy friend or colleague is having a day," and they have to put it off.

42
00:06:57.920 --> 00:07:05.689
It's, that's, that is a pretty disarming tactic. It's super weird, and I've, I've... it's really particular to these threat actors.

43
00:07:06.220 --> 00:07:17.660
I don't know if they are actually just really busy and they like [laughs] fuck up the time zones. That's like [laughs] uh, or if they've like figured out that this is a disarming tactic.

44
00:07:17.680 --> 00:07:31.420
But it is super disconcerting because, again, this is all set up for the call. When you get on the call, it is, so it looks like Zoom. Sometimes it looks like Teams. Supposedly there's Google ones out there.

45
00:07:31.560 --> 00:07:40.870
I've never seen them, but at some point they'll have a Google one. It looks exactly like Zoom or Teams or Google. They use like the website, the code, the CSS, the JS.

46
00:07:40.920 --> 00:07:43.940
Like they, it's a clone, and it's pretty well executed.

47
00:07:44.180 --> 00:07:56.900
The second disarming thing about these guys is that they actually have videos of the person that you are about to talk to, and that video is actually playing in this fake Zoom, Teams, Google, whatever, in this thing.

48
00:07:57.360 --> 00:08:11.220
And so when you join the call, you see yourself, your Chrome browser will like ask for your thing, and you will see the person that you're about to meet on the call and like sometimes like a colleague or a partner or another person in the ecosystem will also be there.

49
00:08:12.300 --> 00:08:23.540
However, unlike, well, I say unlike a normal call, but actually having technical shit happen and not being able to join a call like right off the bat is a very common experience.

50
00:08:23.940 --> 00:08:34.259
Like super com- like when we were starting this podcast, in fact, we're sitting here like doing, trying to figure out the audio shit, trying to figure out the thing. Why isn't it local, right? Super common.

51
00:08:34.400 --> 00:08:43.330
And so their scam version of Zoom will basically tell you that your audio device, it can't hear you, your audio device isn't working, you need to do something.

52
00:08:43.360 --> 00:08:54.760
And then the threat actor will also be in Telegram being like, "I can't hear you." Like, "I see you, but I can't hear you. What's going on?" And they then prompt you to, there's, it like forks.

53
00:08:54.940 --> 00:09:02.660
So if you're on a Mac, it'll download an AppleScript usually, and then you ru- you click it, and it runs in this program called AppleScript.

54
00:09:03.289 --> 00:09:10.780
Uh, and that basically goes and it gets another payload, which gets another payload, which just completely wrecks your computer with like the deepest malware.

55
00:09:11.540 --> 00:09:22.640
If you're on Windows, they typically will do a little pop-up, and you have to copy-paste this code, and they tell you to run it in like PowerShell or Terminal or Run or whatever the Windows version is.

56
00:09:23.220 --> 00:09:35.800
But it all looks like, it looks like it's pinging the normal Zoom. It looks like, I don't know, like it's not that far out of the realm of possibility. It's not downloading a PDF. It's not downloading an EXE.

57
00:09:36.540 --> 00:09:50.900
So even the people that are aware of scams and aware that like I shouldn't install an EXE on my computer from a random person often don't necessarily, like aren't immune to this one, right?

58
00:09:51.480 --> 00:10:01.340
And because you sort of have these different things hitting you, because the, the information's been displayed very well, like it's not super janky. You have people pinging you in Telegram. They're very helpful.

59
00:10:01.480 --> 00:10:04.480
These scammers are very helpful. They'll help you troubleshoot your issue.

60
00:10:04.730 --> 00:10:17.170
Um- Yeah, they he- they helped me troubleshoot a little bit pretty well because I, I, the, uh, my Mac's permissions were set up in such a way that the original link did not automatically download the malware, and so I had to run the script through Terminal.

61
00:10:17.170 --> 00:10:27.170
Oh, yeah. I feel horon in retrospect 'cause that should've been, you know, the alarm bell- Yes... going off. But everything else up to that point, it's like I have a chat history with this person. Mm-hmm.

62
00:10:27.380 --> 00:10:36.700
It's a friend and a former colleague. There was the video of him. The video was weird because it's not like, it's o- obviously not a live feed. And you mentioned that they're not deepfakes.

63
00:10:36.740 --> 00:10:46.200
They're actually recorded videos, which is also really freaking, freaking terrifying. And the whole thing had a weird feel about it, but I was up super early.

64
00:10:46.400 --> 00:10:53.230
I was also taking care of my daughter at the time, and so I just, there were so many inputs I wasn't thinking about. Yeah.

65
00:10:53.410 --> 00:11:03.080
And going back to the, the cleverness of this, one thing I'll say, maybe we chalk this up to workload to where they just finally got to mine after the backlog of all the other compromised computers.

66
00:11:03.560 --> 00:11:15.640
But I ran multiple malware scans. Nothing came up for multiple different softwares and like paid ones, right? Nothing came up. Mm-hmm. I thought I was fine. Two weeks later, Telegram's gone. So- Yeah...

67
00:11:15.700 --> 00:11:24.870
if you had one of these meetings and you think you're okay, uh, as you pointed out in your thread, turn your Wi-Fi off, immediately wipe that computer. Yeah.

68
00:11:24.940 --> 00:11:36.570
Don't use it for anything related to hotkeys or, or anything sensitive. Don't use it. And- Yeah, don't use it... the other thing I would say is this is where 2FA matters so much, especially like- It, yeah...

69
00:11:36.600 --> 00:11:46.440
Google Authenticator. I had 2FA on everything sensitive, and I think that probably ended up saving my ass on a lot of stuff i- in the long run. Yeah. But- Yeah, yeah.

70
00:11:46.480 --> 00:11:58.560
The phones, so like for me personally, like I use my iPad and my iPhone, like I use them way more than my computer for random semi-risky interactions.

71
00:11:58.600 --> 00:12:08.620
This is especially true since I had my daughter because as you point out, there is like normal crypto stress, brain being full things. You have so many inputs.

72
00:12:09.380 --> 00:12:18.152
When you add the in real life child to the mix-Like, I just realized, like, there's no way that I'm, like, mentally capable of detecting bad things.

73
00:12:18.371 --> 00:12:31.192
[laughs] Like, if my daughter starts crying or, like, breaks something, or, like, wants Goldfish, like, that is going to take priority over my scam detection. [laughs] And so I definitely, like, I recommend...

74
00:12:31.732 --> 00:12:41.132
The way that your, your, like, iOS and, like, your iPhone or iPad, the way that it's set up architecturally, it's just way more sandboxed, which is why- Mm... you don't see these, like, total...

75
00:12:41.172 --> 00:12:48.292
You basically have to be, like, yeah. There's, uh, only a few people on earth that got, like, malware, malware for, like, phones.

76
00:12:48.312 --> 00:13:01.382
But then also, like, you know, having your 2FA codes on your phone or even, like, as an external, like a YubiKey, both of those will help significantly mitigate the damage, even if your computer gets wrecked. Yeah.

77
00:13:01.602 --> 00:13:08.392
Uh, it was a lifesaver for me. A few-- There are a few good hygiene things that I've picked up over the last, you know, nine, nine years or so.

78
00:13:08.472 --> 00:13:19.432
I will say it was the, the first time I've gotten got, so to speak, and it just goes to show how freaking crazy far some of these phishing attacks have come, and this one is by far the most sophisticated I've ever seen.

79
00:13:19.712 --> 00:13:34.592
[upbeat music] We are CleanSpark, America's Bitcoin miner, a publicly traded company with the largest operating hash rate, powered entirely by self-operated infrastructure across four states.

80
00:13:36.472 --> 00:13:47.852
This is our proof of work. We are setting the standard for what's next. Learn more about the intersection of energy and Bitcoin at cleanspark.com.

81
00:13:49.112 --> 00:13:58.402
You said as of December 12th, there were, there's, like, roughly or just over three hundred million dollars stolen through this scam. How are you arriving at that number?

82
00:13:58.572 --> 00:14:04.412
And if you had to give an estimate since then, since it's so widespread, what would you put it at? Yeah.

83
00:14:04.632 --> 00:14:14.272
So okay, so the three hundred million dollar number, that is, let's call it, that's the total for this sub-cluster, this, like, one particular threat group.

84
00:14:14.732 --> 00:14:24.332
That's the total that I've tracked of these threat actors, it, that they've stolen in, like, the last year-ish. It's, like, the very end. I think it's, like, the very end of '20.

85
00:14:24.432 --> 00:14:37.622
It was basically a, a full calendar year, so, like, December 2024 to wh- December 2025. The reason I know this number [laughs] is because I'm insane. No, the reason I know this number is because they have...

86
00:14:37.782 --> 00:14:46.772
It's such a particular MO, and it's very hard to stop. Most other threats we are able to get our arms around in some way, shape, or form.

87
00:14:47.172 --> 00:15:02.172
Like, for example, with-- there's, there's very similar, like, Zoom, Teams fake call malware. They're relatively easy to do any number of things to, to, like, stop their spread. These guys are

88
00:15:03.612 --> 00:15:12.872
very dedicated and very annoying. I hate them very much, and I would like them to stop. But you have to stay on top of them, and you have to stay on top of their...

89
00:15:13.452 --> 00:15:23.712
Like, because they're constantly pivoting on, like, the, the prior victims. If you lose the trail, so to speak, you lo- like, kinda lose eyes on them completely.

90
00:15:24.142 --> 00:15:41.052
And so the reason I stay on top and I track the theft so carefully is because what we're ultimately doing is we're taking this intelligence, and we're taking the information, we're pivoting off of it, and then we're doing, we're whacking them behind the scenes in a huge number of ways to try to stop the losses as much as we possibly can.

91
00:15:41.682 --> 00:15:52.062
And sometimes we're successful, but right now we're having some trouble. [laughs] So I wanna put a pin in, in the h-how you're, h-how, how you're countering this. Mm.

92
00:15:52.312 --> 00:15:59.452
And when you say you, y-like, you and team, like, other cybersecurity researchers, you and the team at MetaMask, like, is it- Yeah. Okay. Um- Yeah.

93
00:15:59.572 --> 00:16:10.581
So MetaMask, we do a lot, and then there's also, like, a huge number of independent associated security people, crypto security people, Web2 security people. We all, yeah, we all work together.

94
00:16:11.172 --> 00:16:18.312
So, so for the three hundred million figure, and I know you said you're insane 'cause you are keeping track of this. [laughs] Obvious persistence for sure.

95
00:16:18.992 --> 00:16:28.472
I-is that from you just reaching out to people and keeping track of that trail and then basically taking in information as it comes of, like, "Oh, I lost this much. I lost this much."

96
00:16:28.532 --> 00:16:36.032
Is that you using internal data from what you've seen at MetaMask? And on that last note, to be clear, this affects the wallet, but you only have- Yeah... eyes on that.

97
00:16:36.132 --> 00:16:48.432
What, what-- Is this cobbled together with both of those? How are you arriving at that number specifically? Yeah. So it's, contrary to popular belief, MetaMask has very little useful data for these sorts of things.

98
00:16:48.552 --> 00:16:57.511
[laughs] So it does not unfortunately come from some magical internal data pile that ConsenSys has, unfortunately. It does come...

99
00:16:57.612 --> 00:17:09.722
So there are certain cases where, like, they're, the, the victims are MetaMask users, and therefore they come on their, like, they come on my radar in that way originally. But most of it is... So it's a combination.

100
00:17:09.792 --> 00:17:21.812
So we have people reporting, like, they just got hacked and stuff, and, like, people do this in public, people do this in, like, semi-private ways. It's also from the on-chain tracing side of things.

101
00:17:22.232 --> 00:17:35.372
One of the other reasons that we actually do track these thefts pretty carefully is that they tend to commingle in their laundry, and if you don't have all the inputs, it is very hard to demix the outputs.

102
00:17:35.772 --> 00:17:55.572
So for example, if I have, say, $1,000, right, and I'm trying to launder it, and I put in $1,000, if the person who's trying to find me is looking for $1,000 on the other side, if I withdraw $10,000, the person following me is gonna have a hard time 'cause it's like they didn't see the other $9,000 go in.

103
00:17:55.612 --> 00:18:07.602
They're just looking for $1,000. And so when we, when we actually have a good eyes on the inputs, we're better at tracing and then we're better at, at doing all the other things that we do with the on-chain activity.

104
00:18:07.632 --> 00:18:15.312
Most of the stories, though, are, like, are, like, people reporting, people tweeting about it, me having conversations with people.

105
00:18:15.972 --> 00:18:23.632
It's, like you said, like, it's a disarming-Tactic, and it's very unsettling, and a lot of times people don't know what hit them.

106
00:18:23.672 --> 00:18:34.872
And I would say at this point I've sort of like been around annoying people long enough and helping people long enough that if you are the victim of one of these, like there's a,

107
00:18:35.912 --> 00:18:43.242
a somewhat good chance that someone will recommend that you talk to me, right? [laughs] Like, they're like, "Oh, Taylor does it. I don't know what to tell you, but just go talk to Taylor."

108
00:18:43.752 --> 00:18:50.312
So a lot of, a lot of the Is that I have today are like, are those sorts of things, or yeah, prior victims reaching out.

109
00:18:51.092 --> 00:19:02.812
So basically you'll have people reach out, then you can have, you have the transaction data from their wallet, and you're able to trace that to where all of this money is pooling, and then from there you can kind of like back engineer maybe where the other flows are coming from.

110
00:19:03.552 --> 00:19:11.892
Um- Yeah. And so- And then you'll- And then we'll go talk to them. Yeah. Yeah. Yeah. So- And on and on and on. How, how do we know that this is somehow tied to North Korea?

111
00:19:11.972 --> 00:19:23.372
Now, for those who don't know, North Korea is behind some of the largest hacks. In fact, I think the largest exchange hack, Bybit, right? Like 1.5 billion, that was the largest- Largest hack, hack ever. Yeah.

112
00:19:23.432 --> 00:19:26.672
There were no- Yeah, I mean- Like, forever. [laughs] They, they...

113
00:19:26.792 --> 00:19:35.952
A North Korean group, specifically the Lazarus Group, and I don't know if that's who this is or if it's an offshoot, it's kinda maybe all the same, 'cause these, these are as ostensibly state actors, but- Mm-hmm...

114
00:19:35.972 --> 00:19:47.472
North Korean Lazarus Group has been notorious, you know, depending on who you ask, they've, they've filched as much as like six billion over the last few years, the last five, six, seven years.

115
00:19:47.912 --> 00:19:57.222
I mean, I remember reporting on stories back in like 2018 of them doing stuff. Yeah. And they're still doing it. So- Yep... is that because we know their wallets, and so we can track them?

116
00:19:57.332 --> 00:20:08.562
What other information or footprints are they, are we, are they leaving so that we know the usual suspects? Mm-hmm. So there's a couple, like, different ways that we... So it's called, like, attribution.

117
00:20:08.972 --> 00:20:20.412
There's a couple different ways that we attribute activity to Lazarus. One is sort of the peculiar tactics and methods that Lazarus and no one else uses.

118
00:20:21.112 --> 00:20:32.212
So for example, if like, [laughs] if they commingle their funds on chain, or if they do something super weird, you know, it's usually, like, you're like, "Oh, okay, so the same person has control of that wallet."

119
00:20:32.842 --> 00:20:40.922
There's, like, some exceptions to some of these things, but that's like one really strong indicator, right? If two sets of stolen funds converge in the same place,

120
00:20:42.052 --> 00:20:51.161
whoever received that money is either the same person or it's like a service that the two different people are using. If you can rule out the latter, then it, it basically leaves the former.

121
00:20:51.492 --> 00:21:01.092
The other thing is that we do actually have a huge amount of intel and indicators, like hard data. Unfortunately not from MetaMask or ConsenSys. We have no data.

122
00:21:01.412 --> 00:21:12.412
[laughs] But everyone else has loads of data, even though it's the blockchain. On a fairly regular basis, just like normal people, their VPNs fail, and then you just see their North Korean IP.

123
00:21:12.692 --> 00:21:19.922
And that's always a weird one. [laughs] So it's not even the sexiest answer. It's just, oh, the hackers don't have the best digital hygiene either sometimes, right? Like, you know.

124
00:21:20.032 --> 00:21:21.972
Yeah, like sometimes their VPN doesn't work.

125
00:21:22.032 --> 00:21:30.962
Or sometimes, like, they probably get frustrated with their VPN, and they like go to switch location and, you know, the packets get through and- It, it reminds me of my, my mom used to read all- [laughs]...

126
00:21:30.962 --> 00:21:41.132
the pulpy, like, people magazines, and Stars would have a segment called Stars, They're Just Like Us. It's like, hackers, they're just like us. They're just like us. They are. Their VPN fails sometimes.

127
00:21:41.612 --> 00:21:50.132
[laughs] They have to take kids to school before they try to screw you out of your life savings, right? [laughs] These things happen, okay? They're just like us. Yeah.

128
00:21:50.172 --> 00:22:02.392
And there's also, like, a huge amount of other things. I personally am not, like, a, a deep malware expert, but I work very closely with a lot of people who do, like, very amazing malware analysis and stuff.

129
00:22:03.272 --> 00:22:15.872
Malware is like, is, it's code, it's software, it's things that individual humans write. They have, like, they have certain patterns, they have certain MOs, they have certain mechanisms that they like.

130
00:22:15.932 --> 00:22:25.812
If you're watching it over time, you can see the code and the malware evolve. You can also just see them using the exact same malware, like, over and over again. That's a whole world I don't really understand.

131
00:22:25.872 --> 00:22:40.172
But these specific guys are... They're, they're specifically they write Mac malware that is very, uh, good, I guess, in terms of malware. It's very impressive. It's very sophisticated.

132
00:22:40.232 --> 00:22:47.342
The way that it's been described by, like, the malware people is that it's basically, like, native Mac malware, rather than,

133
00:22:48.262 --> 00:22:57.792
like, a cross-platform thing or thing that, that a threat actor built specifically for, like, Windows, and then was like, "Oh, we gotta make it work on Mac. Let's port it over."

134
00:22:57.852 --> 00:23:01.852
This is, like, something that's sort of been built from the ground up for Macs.

135
00:23:02.372 --> 00:23:14.452
They als- it also will wreck you on all the other platforms, but, like, I guess the Mac, the Mac versions that are written in, like, Rust and Swift are the ones that are the most impressive and sophisticated.

136
00:23:14.832 --> 00:23:23.162
I think it's interesting because it makes sense if you're gonna try to steal crypto. A huge portion of this industry has always been on Macs.

137
00:23:23.712 --> 00:23:31.922
So, like, I don't know, it makes, it makes sense to me why they did that, but I still think it's like, I don't know, it's not- Yeah, it's, it's- It feels weird, yeah...

138
00:23:32.032 --> 00:23:44.092
smart for a number of reasons, and I don't know anything [laughs] about malware or- [laughs]... that part of cybersecurity, obviously. But it makes me wonder, you know, I wasn't able to find it.

139
00:23:44.392 --> 00:23:55.072
Like, I swept my computer- Mm-hmm... like I said, multiple times with different softwares. A- and, and not just the freemium ones, right? Like actual paid, paid anti-malware, and it didn't find anything.

140
00:23:55.452 --> 00:24:03.112
But my buddy- Yeah... who I ended up getting infected by, had Windows, and he had to run a few sweeps, but he ended up catching it. Yeah.

141
00:24:03.132 --> 00:24:09.712
I wonder if what you're saying about this being native speaks to that, that it was easier to hide in plain sight or something on a Mac.

142
00:24:10.472 --> 00:24:17.262
But it was terrifying to me because I thought I was clean, and then like I said, two weeks later, oh- Yeah, and then they got, they were telling- Telegram. You know?

143
00:24:17.292 --> 00:24:23.352
There's a couple different ways to, like, detect malware, the, like, the mechanisms that they use to, like, figure out if it's malware or not.

144
00:24:23.932 --> 00:24:36.385
One of the ways that they do so is, like, basically your malware-Searcher thing has like a, a massive list of like strings and hashes that match known malware.

145
00:24:36.396 --> 00:24:44.056
But if like a threat actor like steps outside that very specific little box, then it's like not malware 'cause it's not detected.

146
00:24:44.436 --> 00:24:55.996
More advanced like malware protection will actually look for like sort of like live patterns or like abnormal things that like should never happen around like persistence and like where...

147
00:24:56.036 --> 00:25:06.776
how, how do they get the, the malware to like restart every single time, and they'll flag those. But now like you're basically getting into like EDR territory, which is like CrowdStrike, right?

148
00:25:06.816 --> 00:25:16.036
Like these are like more... They're-- I mean, you could run CrowdStrike on your computer to, as an individual, it doesn't matter, but like it's just a sort of- Could you just like unpack EDR?

149
00:25:16.456 --> 00:25:26.765
EDR is endpoint detection and response. So you have like antivirus software, that's like the, the thing that we're all super familiar with. If you're like running a big company,

150
00:25:27.876 --> 00:25:33.195
you'll have what's called EDR, and EDR is... it's endpoint detectin- detection and response.

151
00:25:33.876 --> 00:25:43.816
It's, the way that it's sold is for like sort of this live monitoring and detection and then response, and so like CrowdStrike is like the big, the big one.

152
00:25:44.136 --> 00:26:03.196
At the end of the day though, it is just software, but the mechanisms by which they detect malicious things is more like basically instead of like checking into the database to see if it's malware, it's detecting against various patterns that are just known to be bad, and then if something does that, they'll flag on it.

153
00:26:03.656 --> 00:26:14.076
And because of that, it's why it's sort of a more tailored towards like enterprises and companies because they have a lower threshold, like a thr- a lower tolerance.

154
00:26:14.696 --> 00:26:21.496
But as an individual, especially in crypto, like you could run this on your machine at all times. It will protect you very, very well.

155
00:26:22.116 --> 00:26:35.656
Um, and if you have any amount of knowledge about like computers and systems and what you're doing on your computer, you'll be able to know whether something is like a true positive or a p- a potential false positive with like no effort at all.

156
00:26:35.716 --> 00:26:37.796
So yeah.

157
00:26:37.836 --> 00:26:58.256
S- so getting in a little bit more to what this malware does specifically, I was under the ignorant impression that they're just going after Telegrams and trying to get as many people in the web as possible, which doesn't make any sense if you just think about it from just intuitively, it's like, well, what good is the Telegram if you can't get anything else into the computer?

158
00:26:58.756 --> 00:27:05.696
Um, so the Telegram is just the syringe, so to speak, to transmit this, right? Or maybe the cough to transmit the virus. Yeah.

159
00:27:05.756 --> 00:27:17.285
But the malware itself, y- it's a, it sounds like a complete Trojan horse where they have access to everything on your computer. What wallet types are most vulnerable to this? Obviously, if you have- Mm-hmm...

160
00:27:17.285 --> 00:27:27.116
like your private keys in plain text on your computer, those are gone. But- Yeah... w- which wallet types are most vulnerable or are they all just kind of equally vulnerable to this?

161
00:27:27.256 --> 00:27:35.876
Uh, basically to ask it another way, how do they get access to your funds once this is on your computer? Yeah. So there's a couple things the malware does.

162
00:27:35.916 --> 00:27:47.285
So once you run the script, as I said like before, like you run the script, and then it does its thing, and then it goes and gets more things and downloads things and it exfiltrates things, and all this stuff happens.

163
00:27:47.376 --> 00:27:57.535
Ultimately, what it's doing though, like what the malware is doing is, is twofold. The first thing it's doing is it's hunting through your entire computer for anything that they want.

164
00:27:58.136 --> 00:28:10.056
And generally speaking with these guys, they... Well, the number one goal is to get crypto. They want your crypto. They want your wallets. They want your money. That's how, that's their entire job.

165
00:28:10.096 --> 00:28:20.216
That's what their entire life revolves around. Like if they don't steal any crypto, they like get sent to like the Google log, and it's really bad. [laughs] So like that's their goal, end of conversation.

166
00:28:20.276 --> 00:28:31.116
However, in order to achieve that goal, they do a whole bunch of different things. And so yes, they will take any secrets that are on your device, so your keys, your passwords, they'll take those.

167
00:28:31.756 --> 00:28:44.296
Any place that you store passwords, private keys, seed phrases, they'll take like the whole thing. So your like Chrome storage that has your password saved, they'll, they'll take the whole thing.

168
00:28:44.876 --> 00:28:54.796
They will hunt, it'll hunt for wallets that are browser extension wallets and also like, like desktop wallets, I guess we call them, right? Like the thing, like the actual desktop wallets.

169
00:28:55.516 --> 00:29:06.796
Any place that those store the private keys sort of like under the hood, they'll take all of that. So there's two types of wallets that are like somewhat better at protecting you.

170
00:29:06.836 --> 00:29:18.936
The first is obviously hardware wallets, right? Because those, there's no key on your device to actually take the hardware. Like the key is completely separate, and so they cannot just steal the key.

171
00:29:18.976 --> 00:29:30.736
Unless you're like so many people and you've also saved your hardware wallet key on your device, then like, then they take that, [laughs] just FYI. Don't store- Which like don't ever do that, guys.

172
00:29:30.776 --> 00:29:39.656
That just- Guys, don't... completely neutralizes the purpose of having the hardware wallet. But you cannot imagine the times where people come in, they go, "My Trezor got hacked, my Ledger got hacked."

173
00:29:39.676 --> 00:29:47.106
Which by the way, this is like a good indicator that the... like I'm like, "Okay. Hey, have you had any calls lately?" And the answer's like, "Actually." And I'm like, "Okay."

174
00:29:47.956 --> 00:29:55.756
And then I'm like, "Have you signed any transactions with your hardware wallet lately?" And if they say no, then I tell them to go search their computer because they left, they stored their seed on it.

175
00:29:56.156 --> 00:30:05.846
And then every single time they say, "No, no, no, no, no," and then they come back a day later and they're like, "So I guess I had an upload." Whomp, whomp, whomp. [laughs] Right.

176
00:30:05.996 --> 00:30:13.366
I don't wanna make fl- like 'cause it's, it's, it's an awful thing, but as long as your keys aren't on your computer, the hardware wallet I assume would be safe unless they were- Right...

177
00:30:13.376 --> 00:30:23.286
trying to engineer some sort of address swap like mid- Yeah, well... Yeah, well that's- Which that's not even possible, right? Oh, no. It's, they're very clever. They're very good. This is why, [laughs]

178
00:30:23.656 --> 00:30:24.956
this is why they steal so much money.

179
00:30:25.416 --> 00:30:37.751
But generally speaking, if you have a hardware wallet and you have notTaking a photo of it, put it in Apple Notes, in Keychain, whatever, then your har-hardware wallet is, is safe, at least for now, right?

180
00:30:37.792 --> 00:30:42.352
Like, they cannot take the seed and steal all your money. The other type of wallet that is, like,

181
00:30:43.712 --> 00:30:58.042
slightly better than, like, your regular daily driver wallets is any wallet that has, like, let's call it, like, strong encryption at rest. However, it requires you to not ever use that wallet.

182
00:30:59.202 --> 00:31:10.672
[laughs] So if you're-- basically, if you're storing your keys in an encrypted form on your computer and you never use the keys ever, then they have to do more work to get those keys. However, keep in mind,

183
00:31:11.602 --> 00:31:20.112
they've not-- they haven't just taken, like, the wallet data from your computer, they've also taken every single password, every single secret, every single everything.

184
00:31:20.832 --> 00:31:33.572
And if you are using that wallet, so you're unlocking it and relocking it, it's, like, trivial for them to get the password or to get, like, the unencrypted state of the thing.

185
00:31:34.172 --> 00:31:36.732
So basically, don't have your keys on your computer. Use a hardware wallet.

186
00:31:37.372 --> 00:31:54.612
Okay, so then the other thing, though, that this malware can do is besides just go hunt through your entire computer for all the places that they know secrets exist, is they can just drop more code onto your computer at any time that they want, and that code can be whatever they want.

187
00:31:55.412 --> 00:32:06.112
And this is like now we're getting into, like, Bybit territory, right? Like those-- this is how these hacks happen is like they-- the first step is that they gain the initial access. They'll go through everything.

188
00:32:06.202 --> 00:32:15.812
They'll read your documentation. They'll figure out who you are. They figure out what access you have. Then they figure out how to get the money, where is the money. And if they're blocked by that

189
00:32:16.792 --> 00:32:26.222
because it's on a server somewhere or because it's a hardware wallet, then they build you some-- [laughs] then they build, they build, they write some code to get around that.

190
00:32:26.852 --> 00:32:41.312
In this case, the most common way that they, that they end up, like, ruining you, even though your keys aren't on your device, is that they will drop a custom, a malicious version of your wallet that you use.

191
00:32:41.842 --> 00:32:51.652
So if you use MetaMask, they have many versions of malicious versions of MetaMask. If you use Atomic, they have Atomics. If you use Phanta...

192
00:32:51.662 --> 00:33:04.112
Rabby, Ledger Live, I've seen-- basically, yeah, whatever you're using to sign with your hardware wallet, they'll replace your software wallet on disk, and the software wallet on disk will basically be exactly the same

193
00:33:05.212 --> 00:33:29.272
except there will be like ten lines of code that are hooked in there that anytime you go to sign a, a transaction, like let's say you wanna send money, let's say you wanna like swap, whatever it is, it doesn't matter what you try to do, no matter what, your wallet is gonna rewrite that transaction and so that the transaction that gets sent to your hardware wallet for signing is going to be the transaction that they wrote for you.

194
00:33:29.952 --> 00:33:43.892
And they've been doing this since-- the first time I became aware of it was in twenty-twenty, was with a malicious version of MetaMask for the-- it was the Nexus Mutual Hugh Karp hack. And nobody believed him.

195
00:33:44.612 --> 00:33:54.312
[laughs] No one-- and people were like, "No, you just, you kept your, you kept your ledger on your device. What the hell?" And then they did an investigation. They found, they found the malicious version of MetaMask.

196
00:33:54.352 --> 00:33:58.472
They diffed the code, and you could see it was like twenty lines of code.

197
00:33:58.492 --> 00:34:21.332
But basically, in that case, they had identified that he had a huge amount of Nexus Mutual tokens, and so the next transaction that he went to sign on his ledger, he thought he was sending like a hundred USDC, but the transaction that actually went to his ledger device was for basically all of his NXM tokens, and then those were sent to the threat actor's wallet, and they were gone.

198
00:34:21.832 --> 00:34:34.672
So a question with this, would you be able to spot this if you were verifying the address on your ledger? 'Cause the hardware wallets reproduce the, uh, recipient address locally onto the- Yeah...

199
00:34:34.682 --> 00:34:46.872
offline, you know- So-... hardware wallet, right? So- Mm-hmm... can they spoof that too? Or- They cannot. So- You really gotta be paying attention. This is why- That's [laughs] the issue. Yeah.

200
00:34:47.312 --> 00:34:56.482
I mean- And- Not to like... It's terrible 'cause like I, I got hacked, so I'm not like-- don't wanna like, you know, throw rocks when I live in a, in a house full of glass. But

201
00:34:57.672 --> 00:35:04.492
it just goes back to the fact that you really need to make sure that you're really disciplined with your hygiene on these things because- Yeah...

202
00:35:04.572 --> 00:35:14.492
if you follow more steps than not, you might be able to catch it before it happens. But most people just don't think about it, you know? Yeah. And it- Hardware wallet's secure. I do this all the time. My computer's safe.

203
00:35:14.592 --> 00:35:23.812
You know, you get complacent. Yeah, exactly. And with hardware wallets, it's especially tough. So when we're talking about like straight Bitcoin transfers, I think it's like

204
00:35:24.912 --> 00:35:35.592
there's a better chance that you're gonna detect it because you can like-- in 100% of cases, you're gonna be able to look and, and see the address that you're sending and see if it matches.

205
00:35:35.632 --> 00:35:44.732
You do need to be careful, like, in terms of actually checking the characters because they can do like-- it's quite easy to like basically get a lookalike address.

206
00:35:44.772 --> 00:35:53.502
But, you know, if you check every character, th-they can't do that. So yes. Once you're in Ethereum land and Solana land,

207
00:35:54.472 --> 00:36:01.742
the information that's shown on your device is not necessarily-- like, it doesn't necessarily mean anything.

208
00:36:02.282 --> 00:36:12.232
[laughs] And even if it does mean something, there's just like s- you have to have such a deep level of understanding. So for example, with the NXM hack, right?

209
00:36:12.272 --> 00:36:26.292
Back in twenty-twenty before-- we have-- we've-- caveat, we've improved a lot since then. However, it's still like a fundamental issue. So he was trying to send a bazillion NXM tokens. The address that was on...

210
00:36:26.312 --> 00:36:36.212
Or sorry, he was, he was trying to send a, a small amount of tokens. He ended up sending the full amount.On his hardware wallet, if he had verified very carefully,

211
00:36:37.192 --> 00:36:56.632
and if he had checked the to address, the to address would not necessarily have been different because when you're sending a token on Ethereum, the to address is actually the token contract because you're, you're basically communicating with the token contract and instructing it to send your tokens, and then in the data field is the address that you wanna send to.

212
00:36:56.792 --> 00:37:08.932
Um, and so sometimes on your ledger, at least it used to be like this, the to address on your ledger is just the token contract address. So it'd be like the Tether token contract address or the NXM one or whatever.

213
00:37:08.952 --> 00:37:18.552
And then the, the parameters that had the real data that you had to check were later and more obfuscated, and it's less likely that you look at them.

214
00:37:18.592 --> 00:37:28.372
The second part is like even if you, like, verify an address or whatever, you then also have to check the amount, and this can sometimes be a poor experience in both Ethereum and Bitcoin.

215
00:37:29.532 --> 00:37:38.352
If they're showing the amount in, like, Satoshis, you're, you're, like, trying to map in your head, you're like, "Let me move the decimals over." No one thinks in Satoshis, [laughs] you know? Yeah.

216
00:37:38.902 --> 00:37:39.362
It's really hard to do.

217
00:37:39.362 --> 00:37:50.032
And so it's-- There's just, like, all these little caveats, and obviously, like, the more complex the interaction is, if you're trying to swap, if you're doing a multisig signature, there's all these ways that it can just be...

218
00:37:50.052 --> 00:37:52.532
It's just not as straightforward to verify. Yeah.

219
00:37:52.572 --> 00:38:04.672
There's t- like- [laughs] And sorry, it sounds like account-based models like Ethereum and Solana, there's just more moving parts that, that you might miss when you're doing this versus UTXO, um- Yeah.

220
00:38:04.712 --> 00:38:17.932
Well, and it's just, like, the types of things that you're doing. Like, I mean, people are-- They're like s- you're like r- like reorienting a position for this nested staked asset or whatever.

221
00:38:17.972 --> 00:38:28.392
It doesn't-- There's no interface right now that's, like, showing you what's actually going to happen, right? Let-- And then, like, expecting your little ledger screen is like...

222
00:38:28.452 --> 00:38:37.452
I mean, hold on, I have my ledger right here. I'll show you. There ain't no way that this little fucking screen is gonna show you anything, guys. It cannot.

223
00:38:37.512 --> 00:38:49.652
[laughs] And, like, the newer ones have bigger screens, but not that much bigger, and it's not... You know, it's just... Yeah, it's, it's tough. So again, this is why I, I stay on my iOS when I'm signing these days.

224
00:38:49.692 --> 00:38:56.472
It's a pain in the butt. The wallets are not the greatest. I yell at MetaMask all, all the time. [laughs] "Guys, what are we doing?"

225
00:38:57.152 --> 00:39:05.542
But it's because, yeah, it's because I, I just don't, I don't have faith that I'm gonna check everything. [laughs] So- Well, it's like if- It's expensive, yeah...

226
00:39:05.542 --> 00:39:16.422
if, if you have someone who, who leads cybersecurity at a, a premier browser wallet is saying that, then everyone should take notice. [laughs] I have one, one more question on the

227
00:39:17.492 --> 00:39:27.812
swaps that they do for the browser wallets and software wallets 'cause I think that's really important for maybe some people listening who might have been affected by this or just to keep their ears up if they feel like they ran into this problem.

228
00:39:28.812 --> 00:39:36.372
Yeah. If they're swapping your MetaMask, so you said there's like 10, 10, 20 lines of code that basically backdoor it for any sort of shenanigans.

229
00:39:37.032 --> 00:39:47.742
Are they literally just replicate-- Like, are they taking your private key, altering MetaMask, and then just, like, re-uploading it with the malicious code? Are they creating a perfect clone that shows your balance?

230
00:39:48.272 --> 00:39:55.942
How do they- Right, so-... make sure that it look-- Like, functionally, under the hood, it's not your wall- Like, how-- Do you see what I'm saying? Yeah.

231
00:39:55.952 --> 00:40:01.552
It's like how do you actually replicate all of the parameters of your wallet while also- So-... making sure that they can screw you with it?

232
00:40:02.532 --> 00:40:19.452
It's wild because both MetaMask and Google Chrome have, have done a huge number of things to try to prevent this from being possible because it's code. It should-- If you change the code, things should break.

233
00:40:20.132 --> 00:40:31.712
Google specifically because they have sort of like more access to your device and stuff, Google has really worked hard at this. And so if you go right now and you manipulate your-- Just, like, pick a random...

234
00:40:31.972 --> 00:40:42.772
Well, I don't recommend doing this, but you can if you really want. Go pick a random Chrome extension. Go to, like, the underlying file folder on your computer, manipulate it, change a line of code. It'll actually...

235
00:40:42.812 --> 00:40:51.572
Like, Chrome will actually kick you out. Like, it'll stop the extension. It won't let you use the extension. It'll, like, it'll, like, basically, like, internally explode and be like, "Ah."

236
00:40:51.652 --> 00:41:01.242
However, every s- every single thing that, like, MetaMask does or Chrome does to try to prevent them from doing this,

237
00:41:02.182 --> 00:41:13.152
there's usually, like, a way around because ultimately they have root access to the device, and ultimately, like, the detection has to come from somewhere. The verification has to come-- Like, there has to be...

238
00:41:13.172 --> 00:41:22.272
You have to, you have to do something to detect it. And so they have a, a constantly evolving toolbox of ways that they get around this.

239
00:41:22.392 --> 00:41:31.372
But ultimately what they do, they're touching, like, the minimal amount of files on your computer, and so they... And they know the wallet.

240
00:41:32.112 --> 00:41:38.452
Like, this was, like, sort of how I got originally obsessed with them, was, like, back in, in 2020 when I was like, "Whoa."

241
00:41:39.172 --> 00:41:48.082
There's not that many people who've, like, gone through the MetaMask code base, and it's not, it is not a pleasant code base. [laughs] Ask any of our engineers, [laughs]

242
00:41:48.112 --> 00:41:55.512
literally any of them, they will tell you a whole, a whole bunch of really gruesome details about why it's a bitch to do anything to MetaMask.

243
00:41:55.572 --> 00:42:09.072
Anyone like me- I mean, it's got, it's got hundreds of coins and tokens at this point, right? Like, it's just got to be- Yeah... an absolute mess underneath. And, and it's a, it's a t- It was-- It's almost a decade old.

244
00:42:09.652 --> 00:42:20.772
We haven't done, like, a full rewrite ever. So we got attacked, we got... [laughs] It's not... Yeah. But anyway, so they, they do, they do-- They sort of touch the minimal amount of things.

245
00:42:20.812 --> 00:42:26.592
So it's not like they're dropping, like, a, a full, like, the whole thing, so to speak.

246
00:42:27.112 --> 00:42:36.432
They'll figure out the one little thing that they need to, like, hook into, and then they'll do that, and if they have to evade Chrome or MetaMask or anyone's detection, they'll do that.

247
00:42:36.992 --> 00:42:50.864
But essentially-It's hard to explain, but like essentially like in all cases, wallets have to interface with like the ledger or the Trezor, and so there's always pieces of the code base that are always gonna be hooking out and hooking back in.

248
00:42:51.564 --> 00:43:01.224
So they can either hook into the code base in the wallet itself, that section of the code that hooks in and out, it's usually like a transaction control or whatever.

249
00:43:01.684 --> 00:43:12.994
Since they have root access to your device, they can also try to like hook into the hook, the, the transport layer, right? So- Because they can... They-- It's code. Every... Your entire- Yeah... computer is code.

250
00:43:14.024 --> 00:43:24.024
So it sounds like this, the swapping thing, is mostly for them trying to get hardware wallet funds, but if you have any hot funds- Yeah... on your MetaMask then they're just gonna take them. Al- Yeah.

251
00:43:24.104 --> 00:43:33.644
Although th-this leads to my next question. M-my... I mean, granted, I have like a poppers on my MetaMask 'cause I don't keep anything hot u-unless I'm just using it for,

252
00:43:34.784 --> 00:43:43.704
you know, trading or just like, just to sign transactions or something like that, right? Like I, I- Yeah... I never keep anything more than $1,000 on a hot wallet on my computer.

253
00:43:44.204 --> 00:43:49.664
But they, they didn't end up sweeping anything and, and you had some theories as to why that might have been. Can you- Yeah...

254
00:43:49.724 --> 00:44:01.104
render those for the people who are like, "Oh, well, like I was compromised, but my MetaMask is fine. Like, they haven't taken anything." Kind of why, why might they be waiting or why might they just pass it over? Yeah.

255
00:44:01.264 --> 00:44:08.584
So it ki- it also goes back to like your Telegram point, like what are they, what's the, what is their point or like what are they doing here?

256
00:44:08.644 --> 00:44:22.604
So I think it's, it's useful to understand that why like Lazarus, North Korea, DPRK, like why they're fundamentally different threat actors than basically any other threat actor, threat group on Earth, is that they are

257
00:44:23.544 --> 00:44:29.964
like financially motivated, meaning that they like want money, but they're also like state-sponsored, state-backed.

258
00:44:29.984 --> 00:44:36.224
They're actually like working for their government in the same way that like the FBI works for the US government, right?

259
00:44:37.154 --> 00:44:49.224
The key difference obviously is the FBI is working for the US government, and the US government is then working for its citizens, for the taxpayers and people, right? North Korea, not so much.

260
00:44:49.604 --> 00:45:02.204
[chuckles] It's just the regime, kind out for themselves, everything is for themselves. There's a lot of propaganda saying that it's for like the people, it is not. It's just for themselves. It's kinda like a job, right?

261
00:45:03.184 --> 00:45:12.704
Except like most communist states, it's, it's very weird for the Western mind to imagine a job where you don't actually get rewarded whatsoever for anything.

262
00:45:12.804 --> 00:45:30.244
[chuckles] And so because of this financial motive, combined with this very odd thing where these hackers are working for a third party/their boss/the state, whatever, what ends up happening is things like this where like they don't s- they don't steal the money.

263
00:45:30.364 --> 00:45:35.984
Like what the heck? The only sense that I have is that for low dollar values,

264
00:45:36.924 --> 00:45:47.644
there's no upside for them because even though they're hackers, they're not hacking for themselves, they're hacking for the state, for the regime, for their bosses. They don't keep any of that money, zero dollars.

265
00:45:48.504 --> 00:46:04.964
What they get from it is like sort of a fulfillment towards their quota, which may put them in a better position in life or more likely avoids a detrimental position in their life, meaning that like they don't

266
00:46:06.064 --> 00:46:16.664
go to the gulag or any number of other negative things that can happen, right? So if you think about it, if you, if they get on your device and your $500, there's no upside to taking it.

267
00:46:17.444 --> 00:46:30.264
The downside, even though it's a very low downside, like the p- the possible downside is that you realize the wallet is hacked, you realize your computer is hacked, and then you're gonna clean up better or something, and then they...

268
00:46:31.064 --> 00:46:37.744
That like sorta closes the door, so to speak, because if you don't realize how fully you've been compromised, you might keep using the wallet.

269
00:46:38.144 --> 00:46:44.164
You might just like forget in like a year and put a huge amount of money in that wallet for some reason, and they, they'd rather

270
00:46:45.264 --> 00:46:56.394
leave that door open, especially because, again, the $500 isn't gonna change anything about anything. That makes a lot of sense to me. You're, you're... It's an opportunity cost risk. Yeah.

271
00:46:56.424 --> 00:47:09.624
And I also really in, in a twisted way, I kind of like this corporate KPI- Mm-hmm... perspective on it where it's like- It's crazy... well, you know, Do Kwon got 200 million. [chuckles] You know?

272
00:47:09.804 --> 00:47:15.794
And so, you know, Lee, you really need to bump up those numbers, buddy. You've only gotten 10,000 this week. Yeah.

273
00:47:15.794 --> 00:47:22.444
And that would make sense to me in the sense that if you're looking at this from a carrot and a stick perspective, you want to bring in the biggest haul.

274
00:47:22.964 --> 00:47:38.224
So if you get some poor schmuck who's only got like a 500 bucks of USDT or 500 bucks of Ethereum, you're gonna wanna wait for that honeypot to fill up a little bit more before you mess with it because otherwise you could be spending your time going after a whale rather than a guppy, right?

275
00:47:38.314 --> 00:47:41.894
And so- Yeah... ultimately it just might not be worth it. And you pointed out in your,

276
00:47:42.904 --> 00:47:55.234
in your investigations and some of your reporting on this on, on Twitter or X, that they're really going after founders, they're really going after- Yeah... people who lead some of these, these DeFi or crypto projects.

277
00:47:55.764 --> 00:48:01.174
Their real targets are the big swingers in the community. Big.

278
00:48:01.184 --> 00:48:11.484
And if they get someone like me, if I have a lot on my MetaMask, that's great, but otherwise they're going to use me as a transmission vector to try to get to other people as well, right? So- Exactly.

279
00:48:11.524 --> 00:48:17.564
And that's like to, you know, like when we were talking about the malware, what does the malware do? What does it take? So the malware does a huge...

280
00:48:17.744 --> 00:48:27.664
Like it, it takes all these secrets, it does all this stuff, it, it leaves the backdoor open, right? But it, it's kind of interesting because one of the things the malware does specifically is it takes...

281
00:48:27.944 --> 00:48:32.444
It has like an entire little section of the code base that's purely dedicated to your Telegram,

282
00:48:33.464 --> 00:48:42.564
and this has evolved over time, and it seems to be like in direct response to their realization that like crypto founders' Telegram is like the thing that everyone uses.

283
00:48:42.604 --> 00:48:53.444
Telegram also just has a weirdP- like operating structure, like where the, where the actual messages and session cookies are is quite odd. And so they have this whole custom thing to take the Telegram.

284
00:48:53.524 --> 00:49:03.984
I was a bit surprised by this because, like really how valuable is the Telegram account? And I think that it turns out it's actually way more valuable than you might imagine.

285
00:49:04.184 --> 00:49:08.244
And so I think that they sort of look at you, like when they're identifying...

286
00:49:08.344 --> 00:49:16.144
Like when, when they like land you as a victim, they're like identifying like, "Okay, the one path is like we're gonna, this is like the dude that has the crypto."

287
00:49:16.844 --> 00:49:28.424
And if you're not the dude, you're not rich man, you're not the dude with the crypto, they like reposition you as like the dude who knows the dude with the crypto, and thus like...

288
00:49:28.464 --> 00:49:36.424
And that's why there's like sections of this malware that are basically like, "Okay, how do we, how do we make this guy valuable even though he's poor?" [laughs] Sorry.

289
00:49:37.104 --> 00:49:50.364
Like I laugh at this shit, but like that's the best, that's the best I figure. But yeah. And the other thing is that personally, I think I undervalued the Telegram mechanism. It is insanely disarming.

290
00:49:51.044 --> 00:49:59.824
And because they've managed to like grab the raw session keys out of the Telegram, even if you like change your password or add 2FA,

291
00:50:00.864 --> 00:50:09.144
it doesn't, it actually doesn't matter because they'll just, they'll get in with the session cookie. I think that that's just like an insanely valuable thing for them.

292
00:50:09.164 --> 00:50:13.334
But you also said like it had, it had been a couple weeks, right? Like you had the- Yeah, it had... Yeah.

293
00:50:13.344 --> 00:50:26.574
I, it had been a couple weeks, and I think, you know, to your point about opportunity costs, if you, if you infiltrate someone's computer and make them think everything's fine, you're gonna probably be able to do more damage if you don't act- Mm-hmm...

294
00:50:26.574 --> 00:50:32.204
immediately, right? If you're kind of- Mm... moving under the cover of darkness and striking when they don't expect it.

295
00:50:32.244 --> 00:50:44.584
And going back to your point about Telegram, to me it seems like a perfect storm of maybe not coincidences, but just features of Telegram in the sense that the, they store the cookies in a weird way that allows for access.

296
00:50:44.614 --> 00:50:54.264
'Cause I, I did change my Telegram stuff and it ended up not mattering at all. The other thing- Wow... too is like you, right? I- The other thing you said-... wish Telegram would do something about this.

297
00:50:54.324 --> 00:51:03.104
Like I feel like they can do something about this. Let's get to my next point. Like everyone uses it in crypto. They have over a billion monthly active users, and they have no support basically.

298
00:51:03.604 --> 00:51:12.704
Now I will say- No, I know... I don't know how you're supposed to have support for a platform that has a billion users. This is not Meta, right? This isn't Facebook.

299
00:51:12.744 --> 00:51:24.164
Telegram doesn't have the resources and the manpower that a company, a Mag Seven company like Meta has. So it's also extremely convenient to them for if this happens to you, you're basically screwed.

300
00:51:24.184 --> 00:51:25.464
You're not gonna get that account back.

301
00:51:25.524 --> 00:51:34.404
Like there's no one in Telegram, especially now that they're inundated with requests on this, there's no way that they're gonna chew through that and actually be able to restore your account to you.

302
00:51:34.444 --> 00:51:43.494
So it seems to me that there's like this trifecta of, of coincidences with the cookies, the fact that it's widely used in our industry, and the fact that- Yeah...

303
00:51:43.524 --> 00:51:52.384
it just has such poor support, that it's the perfect target for something like this. So- Yeah. Yeah, no, your point about Telegram not...

304
00:51:52.594 --> 00:52:10.444
And, and so Telegram does react to certain very select cases, and it is very, very select. However, it is almost always what they call like a real threat of in real life violence, meaning like terrorism basically.

305
00:52:11.164 --> 00:52:21.454
There's like a line that they have at that point where if Telegram or people are being used to orchestrate a murder or a terrorist plot, they will actually, they do have the ability to like turn off...

306
00:52:21.504 --> 00:52:30.704
It's totally centralized. They can do whatever they want with the account, right? That's just where their line is, and they refuse to lower the bar even when the accounts are being...

307
00:52:30.724 --> 00:52:41.744
Like even when we have strong evidence that the account is taken over, it's being u- it's being used by the threat actor to send known malicious shit through. It's actively sending malicious files, right?

308
00:52:42.404 --> 00:52:54.224
So like on one hand like I, I realize why they do this, right? They want to be a platform for people. They don't want to be serving everyone's data on a silver platter, especially not to France or the US government.

309
00:52:54.284 --> 00:53:05.764
I get it. On the other hand, I think the best thing that they could do in this case would be to understand how the threat actors are stealing these accounts and close those doors.

310
00:53:05.804 --> 00:53:10.904
For example, if you change your password, like kill the session keys.

311
00:53:11.644 --> 00:53:26.944
Or, hey, wild idea here, if a session key is being used on device one and then is cloned and tries to be used on device two, don't allow it. It's a session cookie.

312
00:53:28.173 --> 00:53:34.304
[laughs] It's not supposed to be used on a different device at the same time somewhere else. I mean, I don't know- Why are you allowing this? Right.

313
00:53:34.404 --> 00:53:44.194
I don't know too much about cybersecurity, but I do know that the two things that you just said are pretty basic. You know, anytime I've used any other service, if I change the password, every single session- Yeah...

314
00:53:44.194 --> 00:53:55.604
gets logged out immediately, and then you have to start a new one. Makes a lot of sense. Which is expected. Yeah. So- If you change your pass... Bec- And you want that, right? If you change your password, you- Right...

315
00:53:55.634 --> 00:54:00.954
you don't want the other phone to have access anymore. That's why you're changing the password. Ugh.

316
00:54:00.984 --> 00:54:12.494
So, so Pavel, if you're listening to this, maybe don't focus on that potential IPO this year and then try to figure out a way to, to, to fix this problem for your billions of users. Yeah. Please. All right. Please do.

317
00:54:13.124 --> 00:54:24.734
One more question for you, Taylor, before we have kinda closing thoughts. You've been doing some, how should we say, counterinsurgency here- [laughs]... um, you know, against this threat. And you mentioned- Mm-hmm...

318
00:54:24.734 --> 00:54:36.184
stealing payloads. Mm-hmm. Uh, y- it seems like you and some other folks in the cybersecurity community have been trying to be proactive and, and trying to at least push back against this somewhat.

319
00:54:36.244 --> 00:54:43.884
You can't totally contain the fire, but you can dampen it a little bit. W- what have been some of your strategies? And when you say you're stealing payloads, are you basically,

320
00:54:44.884 --> 00:54:53.204
you're going on there under the guise that you're about to be duped, and then you basically take the code that they're giving you and, and you- Yeah... analyze it?

321
00:54:53.404 --> 00:54:55.664
What, what are some of your strategies for combating this?

322
00:54:56.524 --> 00:55:09.550
So I will say like there are way smarter people that are doing like way more technical stuff than meMy preferred method of, uh, countering a threat, so to speak, my favorite method, right?

323
00:55:09.760 --> 00:55:21.960
I just like to basically troll the shit out of them at all times. Okay. Like, I don't know why people keep putting threat actors on a fucking platter and, like, treating them like they're anything else.

324
00:55:22.700 --> 00:55:33.000
No, dude, you got... You... They wanna get on calls, let's get on calls. I'm gonna take every calendar slot of yours, and you're gonna get on a call with me. So that's, like, one thing I do.

325
00:55:33.640 --> 00:55:44.280
I also, I then have, I have a big Kim Jong Un poster, so whenever I go on the calls with them, Kim Jong Un is, like, he's sitting right here smiling, which always makes them very...

326
00:55:44.480 --> 00:55:52.720
They always, like, rage quit right then. They do. They really like hiding, so they're... Most threat actors will just, like, their malware is, is free for the taking.

327
00:55:53.460 --> 00:56:03.100
One reason why perhaps malware scans don't always work on this malware is because GPRKs, they, they iterate on their malware very quickly, but they also...

328
00:56:03.850 --> 00:56:14.880
It's, it's not something that they'll drop to anyone at all times. So the call... So for example, when I, I got on a call with them last week, finally, after a while, I finally snuck in. They set up the...

329
00:56:14.910 --> 00:56:28.340
They registered and set up the domain less than an hour before my c- my scheduled call. The exact URL that they were gonna give me went live maybe 15 minutes before I got on the call. They dropped it to me,

330
00:56:29.380 --> 00:56:49.440
and within five minutes of them seeing Kim Jong Un hanging out behind me, they had, they'd taken down this, the first stage, the second stage payload, the Zoom URL, deleted the entire chat, blocked me everywhere, probably told all their buddies to watch out for my new persona.

331
00:56:49.480 --> 00:57:00.440
They really, they don't like, they don't like being trolled. They definitely don't like people to s- like, get their malware in full and investigate it, especially if they don't, like, get a theft alongside with it.

332
00:57:00.980 --> 00:57:12.780
But yeah, the other thing, I mean, the... Most of what we do is, is very boring, but it's here to protect people. So Metamask has a number of features that if you visit a malicious site, we will warn you about it.

333
00:57:13.019 --> 00:57:24.700
This is, again, one reason why these guys like to spin up their domains very quickly and use them one time and one time only, is to try to prevent me from blocking them before, like, before they, they land their payload.

334
00:57:25.200 --> 00:57:37.240
But if you use Metamask, in, in most cases, you will get, like, a little anti-phishing screen if you have Metamask enabled at this point. Sometimes they get around it because they're...

335
00:57:37.260 --> 00:57:45.240
It's cat and mouse, constant cat and mouse. Yeah. Um- It's their, their, their tactics are constantly evolving, so y'all's are- It's so annoying. So that's, yeah.

336
00:57:45.840 --> 00:57:59.720
The other thing is just, honestly, is, like, the more that you know about what they're doing, how they're operating, where their weak points are, what motivates them, what they're doing, the better equipped we are at reacting and educating people,

337
00:58:00.700 --> 00:58:11.800
whether that's directly in our product or, like, adjacent to our product or just, like me yelling on Twitter at people. A great example is, is, like, the Telegram thing, right?

338
00:58:12.140 --> 00:58:20.600
A lot of people assumed, and because of, like, the victim-blaming culture, right? There was, like, a series of victims who were like, "But I changed my Telegram password. They still took it."

339
00:58:20.660 --> 00:58:30.000
And 99% of people heard that and was like, "You probably didn't change your Telegram password. You should've changed your Telegram password." Then they told the next 10 victims, "Make sure you change your password,"

340
00:58:30.940 --> 00:58:41.100
right? Until you, like, ask the question like, "Wait, does changing your password actually do anything?" Like, how are they, you know, how are they getting... What are they taking, right?

341
00:58:41.200 --> 00:58:51.240
Until you investigate it in full, you're not able to sort of properly advise, which was happening for a, a long time, honestly. Way too long.

342
00:58:51.900 --> 00:59:02.320
Um, and then yeah, just everything, like, for me it's, it's really, it's like, a lot of it is understanding what is bypassing people's red flag, like, their red flag detectors, I call them.

343
00:59:02.900 --> 00:59:09.900
You have been in this industry for a fantastic amount of time. You've seen, basically you've seen it all, right? You're not an idiot.

344
00:59:10.400 --> 00:59:22.009
The fact that you haven't been hacked in, like, a decade of this shit is testament to the, the fact that you're not a fucking idiot, right? Okay. Why did you fall for this? And the answer is not,

345
00:59:22.939 --> 00:59:28.600
Twitter will tell you that it's because you're an idiot. I'm sorry, but it's... They're wrong, dude. They're wrong. No.

346
00:59:29.340 --> 00:59:38.780
There's a thousand other answers to that question, and if you can answer them, then you can address, like, the underlying issue, whatever it may be. And so yeah, that's what we do.

347
00:59:38.840 --> 00:59:48.600
That's what the security team at Metamask, we're doing constantly with all different threat actors. I do it with security researchers at other wallets, other products in the space, malware guys, all sorts of people.

348
00:59:49.100 --> 00:59:59.860
We're just trying to, we're trying to simultaneously help and protect people, and also just fuck with the bad guys. Like, don't let them off easy. I, I, I love this idea of, like, DDoSing them with trolling.

349
01:00:00.160 --> 01:00:08.980
You know, you know, you can, 'cause you can take the payloads as y'all are doing and analyze them and get from any of them, and you kinda figure some things out, but there's only so much it could get you.

350
01:00:09.020 --> 01:00:13.860
Then the other side of the equation is just making sure that they can't go and get someone else, and you just kinda mess with them.

351
01:00:14.340 --> 01:00:21.699
And on that point, I think you have this on your X page, but, uh, Riccardo Spagni, Fluffy Pony, mentioned how they're on, like- Mm-hmm...

352
01:00:21.720 --> 01:00:31.220
they're on Discord now, and he was talking to one guy, and he said, "Oh yeah, I'll help you with this thing as long as you te- say, but you have to write to me, uh, 'Kim Jong Un is a big fat dork,' or something like that."

353
01:00:31.280 --> 01:00:38.070
Yeah. And he, and he's like, "I'm sorry, I can't do that." And it's like, "Why?" They can't do it. You know? So all this... Wait, hold on.

354
01:00:38.180 --> 01:00:46.380
That mechanism is actually, if you are unsure if you're talking to a scammer, that's actually a really good way to, like, clear the air,

355
01:00:47.300 --> 01:01:00.400
because in 99, well, in, like, yeah, in basically 100% of cases, if the threat actor is North Korean, they actually cannot, they will not talk shit about their dear leader or their country or anything like that.

356
01:01:00.440 --> 01:01:10.560
But if, even if they're not North Korean, a lot of times those threat actors will see you asking that question, and they'll be like, "You know what? I'm not gonna waste my time. This person's too smart."

357
01:01:10.840 --> 01:01:22.228
And so they'll peace out too.And so it's like, it's basically just like throwing a flag above your head being like, "I'm smart and I will not be scammed." And if you do that, it actually protects you.

358
01:01:22.268 --> 01:01:32.208
Yeah, so if you're worried about this, your safe word or your safe phrase could be Kim Jong Un sucks eggs, and then you'll be fine because then they won't be able to say anything back. Uh, Taylor, this has been great.

359
01:01:32.248 --> 01:01:37.648
We're going on an hour here. And, and you kind of, I think already said this in terms of what you...

360
01:01:37.688 --> 01:01:50.208
I mean, takeaways here in terms of just this is constantly evolving and try to give yourself some grace in the sense that it's really complex and a very, very malicious attack, the most precise I've ever seen.

361
01:01:50.228 --> 01:01:59.188
But what are your takeaways for this for our listeners in terms of things they should be doing to protect themselves or what they need to know about this whole saga? Yeah. So

362
01:02:00.548 --> 01:02:09.628
on like the very specifics, it's like, if this has happened to you or does happen to you, turn off the Wi-Fi, turn off the computer, in that order.

363
01:02:09.708 --> 01:02:23.048
Using a different device, go reset your passwords, move your crypto to a new place, re-up and recheck your MFA, hardware wallets, 2F, like the YubiKeys or Google Authenticator on your phone.

364
01:02:23.088 --> 01:02:31.588
Like, do all of those things immediately. Then once you've done all that, wipe the device, get a new device, et cetera.

365
01:02:32.088 --> 01:02:42.568
Anything you do on the computer, once they land the payload, anything that you, like, have or do on the computer, they can theoretically see. Definitely kill in Telegram the sessions.

366
01:02:42.888 --> 01:02:53.268
There's like a thing under devices that says terminate all other sessions. Like, do that from your phone. More generally speaking, though, like broadly speaking, like how do you stay safe in this insane industry?

367
01:02:53.648 --> 01:03:08.178
So number one is just be skeptical. I think that a lot of times scammers get away with doing things because they're not questioned, because people are scared to, like, push back.

368
01:03:09.028 --> 01:03:20.168
If a VC is proposing that you use some, like, esoteric video call platform, don't use it [laughs] and tell them that scammers d- like, use this, right?

369
01:03:20.947 --> 01:03:36.868
If you're having technical difficulties and they want you to run code, like, just don't. Just take a second. And my, like, go-to line for this is basically like, "Sorry, this is crypto. Everything's insane.

370
01:03:36.908 --> 01:03:45.618
I'm not saying you are a scammer, but you could absolutely be a scammer. I'm gonna stop." And then I will, like, literally just pause, right? Just stop.

371
01:03:46.328 --> 01:03:54.728
And if this is a legit person, a legit VC, a legit partner, a legit whatever, they should either understand you and take that seriously and respect that.

372
01:03:55.288 --> 01:04:05.388
And if they don't, they're a fricking idiot and they're gonna get wrecked. And if you're nice, you'll educate them in that moment so that they don't get wrecked in the future.

373
01:04:05.408 --> 01:04:10.378
But also, like, maybe just reconsider and, like, don't take money from them. [laughs] Like, you know what I mean?

374
01:04:10.428 --> 01:04:23.228
Like it's a we-- you, you are in the position of power where I think a lot of people do a lot of stupid things because they, they're like sort of on their heels and they think like, "Oh no, I can't, I can't push back on this VC who might invest in me."

375
01:04:23.268 --> 01:04:27.237
No, you can. And like, a real VC is going to respect you more for that.

376
01:04:27.928 --> 01:04:37.568
The other thing is just like, yeah, anytime someone tells you to do something, especially if it's urgent, if they're p-pestering you about it, again, like, just pause.

377
01:04:37.728 --> 01:04:46.668
Do things on your own terms, not because someone tells you. If you feel, like, embarrassed, like, lay it out on the table and say like, "Sorry, there's a lot of scammers here.

378
01:04:46.728 --> 01:04:55.608
I gotta, I gotta double-check this," or, "Hey, you know what? My daughter's crying right now," or, "My wife just walked in. I'm gonna have to call you back in ten minutes." And just stop, right?

379
01:04:55.688 --> 01:05:03.308
Because the second that your brain is split between all these different things, your sort of like detection ability plummets, to be honest.

380
01:05:03.588 --> 01:05:16.008
There's so many cases with all different types of scams where people say, like, "My dad had just gotten out of surgery and I was thinking about that, and so I just clicked," or, yeah, "It was-- I was racing to get my daughter to school.

381
01:05:16.028 --> 01:05:25.538
I had to sign because I was gonna be late to pick up my daughter," or, "I was sick," or, you know, like, "The dog had just vomited on the carpet." [laughs] Like there-- you know what I mean?

382
01:05:25.628 --> 01:05:38.608
And it's not necessarily that that specific thing allowed them to be scammed, it's that that thing was, like, eating up a huge portion of their, like, brain, and you need your brain to be able to detect scams.

383
01:05:38.628 --> 01:05:50.948
And the second that it's split, you can't reliably-- like your red flag detection just goes out the window, and then that's what the scammers take advantage of. So keep that in mind, and always, like, just

384
01:05:52.088 --> 01:06:02.148
pause, take a breath, reset. Don't do things that people tell you to do. [laughs] And yeah, it helps to assume that everyone is, is North Korean and ask them if they're North Korean, 'cause- It helps- You know?

385
01:06:02.228 --> 01:06:04.928
It helps to recognize that you could always be swimming with sharks in the water.

386
01:06:04.948 --> 01:06:12.908
And I think the biggest takeaway for me was don't take a six thirty AM call when your daughter's in your lap, when your infant daughter is in your lap and wiggling around.

387
01:06:12.948 --> 01:06:18.778
And also, uh, one thing for me would've been just send the invite yourself through your- Yeah.

388
01:06:18.808 --> 01:06:25.668
Like, if you, like, are using Google Suite, send the Google Meet link yourself, and if they have a problem with that, that should raise alarms. Yeah.

389
01:06:26.548 --> 01:06:32.668
But- And especially today, I don't-- like, there's so many, there's fake call platforms. These are so common.

390
01:06:32.708 --> 01:06:40.248
There will come a point where you'll see a VC and a founder fighting because they're both trying to send each other the legit Google links, and you know what?

391
01:06:40.308 --> 01:06:46.028
We'll cross that bridge when we get there and everyone will be better for it. [laughs] We're not there yet though, so just let it happen for now.

392
01:06:46.348 --> 01:06:53.768
We're not there yet, but hopefully one day we'll be there instead of having to deal with- I will be-- if that's the problem to solve, like, I've done my job. I'm doing good.

393
01:06:54.588 --> 01:07:02.348
Uh, Taylor Monahan, thank you so much for joining us. Really appreciate you taking the time. Everyone, go check out her X, her X profile.

394
01:07:02.408 --> 01:07:14.608
I'll link it in the show notes, as well as a really good article on Secure List that breaks down basically every inch- Mm-hmm... of this malware and this attack so that you can be guarded against it.

395
01:07:15.068 --> 01:07:25.268
Uh, stay frosty out there. Do not make the same mistakes I did. Thank you, Taylor. Take it easy. Thank you. [outro music]
