Security Vendor Phishing – Could this be a new supply chain risk trend?
In this video, Molly McDougall from Cofense discusses the evolving phishing threat landscape and its implications for security platforms. She highlights how threat actors are constantly innovating their techniques, making it crucial for organizations to adopt intelligence-driven security awareness training to stay ahead. Molly emphasizes the importance of creating a culture of vigilance and automation to effectively combat phishing threats and safeguard sensitive information.<ul><li>The evolution of phishing attacks is a continuous game of cat and mouse between threat actors and cybersecurity defenses, requiring constant adaptation and vigilance.</li><li>Current global events and technological shifts, such as the transition to remote work and cloud platforms, are often exploited by threat actors to develop new phishing tactics.</li><li>Implementing a culture of security awareness and empowering users as the last line of defense is crucial in mitigating phishing threats effectively.</li></ul>
Guests
Video Transcript
Welcome everyone. Episode 1 0 3. We just hit 4,700, uh, people now have viewed the cyber call. I hope all 4,700 show up today for you, Molly. Um, we'll, we'll introduce you shortly. Um, just a few things, Gary. I was prepared today and if people scroll all the way up in the chat, I put all of the announcements and fun things up there. All 50 announcements. All 50. Yep. Um, there's only three, I think I said that's pretty easy. Yeah, I I I'm taking it easy.
We certainly could do a lot more, but, um, okay, let's jump right on into it. I have a poll there and let's just, we have hundreds on right now, so again, if you could just fill out the poll. It's like a yes no, Molly, it's insane. We get hundreds and hundreds of people on here. We put up a poll and we get 10 people at answer. That be fine. So, uh, okay. Let me kind of just set the stage a little here. Um, so as we know in 2021, we have a lot of supply chain attacks.
Um, we also really haven't done much on the cyber call when it comes to phishing. And, um, you know, I thought, wow, you know, with the late earlier this month, the, uh, CrowdStrike phishing campaign, although not really exploited to any degree, it certainly ha isn't the first time we've seen it. I think last year it was Proofpoint. Um, but it kind of begs us to ask the question as threat actors keep evolving their phishing techniques, will security platforms become a target more so?
And so I wanted to bring on an expert in this area and, uh, I was, you know, fortunate that Amit, um, who used to be Cyber Phish is now part of Conce, um, allowed us to get to their head of intelligence. And, um, Molly McDougal joins us today who heads up that platform and product at Conce and has a little bit of a background in Intel. So Molly, welcome to the show. Um, can you tell everybody out there a little about your background and what you do today at, at Conce? Absolutely.
Thank you for having me. Um, so I'm currently the director of product management at, for our phishing threat intelligence product and running the threat intelligence team, which, uh, beyond what we do for our own customers who, who are, um, consuming our own threat intelligence directly, we do a lot to empower the rest of our product line, which is really kind of formulated our approach to the phishing threat, which I'll get into a bit. Um, but I have been at Conce for almost five years now.
Um, and before that I was with the Department of Homeland Security looking at threats to our, uh, nation, our critical infrastructure, federal networks, understanding what threat actors wanted to be able to do, um, and considering what red lines might take them from capable to detonation or actually actioning on their capabilities. And, uh, before that I was more in the international security field, so got my master's in International. Wait, I thought before that you were in elementary school.
That's A lot of experience. Experience. Uh, I appreciate it. It's been, uh, it's so funny. So I joined cybersecurity. I was an international security person and I thought if I don't know cybersecurity, then I can't call myself an expert in international security. So I'm just gonna go for two years and learn it a little bit and then go back to being like a general international security SME and eight years later and I'm hooked and loving being in this field and could not imagine going back.
Um, so yeah, could not have, every day I wake up like, how did I get here? I did not like do the computer science degree thing. I did not ever think I'd be here. But it's phenomenal field and, uh, there you're just constantly learning because it's constantly evolving. So it's really cool. Fantastic. So that's Gary Pika. Just so you know, Molly, we didn't have a lot of time to introduce everybody.
I know he's the sarcastic person on the call and then the slightly less sarcastic person, Wes Spencer will be asking you questions starting off only Slightly less. Yeah, only slightly. And then we have the very awesome Phyllis Lee, um, who has kind of a kinship to from NSA for 25 years and, uh, now at CIS is the senior director of control. So we she's The actual professional on The call. Yeah, she's the smart one. Yeah. Yeah, absolutely. Um, okay, Wes, let's uh, kick it out. Yeah.
Hey, one question off the cuff that I, I'm super interested in Intel, Molly, I have a long background in it, in in threat intel. Do you guys produce, is, is there, is there anywhere we can, like, can people consume that intel in any way that you guys create or do you have like a Twitter feed or anything like that you can share with us that we can just learn more? Yeah, absolutely. Um, so we do have Conce more broadly has a Twitter feed and we also have a conce intelligence Twitter account.
It's at conce Intel. Um, that's something that we're just kind of reenergizing today. We do post and contribute a lot of blogs on the conce blog. Um, and then for our customers, we are producing daily tactical intelligence content and weekly strategic intelligence on how the phishing threat landscape is evolving. Our team focuses really at the tip of the spear of the phishing threat. We are focused on campaigns that we know are reaching end users.
Um, we really care more about that high value intelligence around like, what are, what are the methods that threat actors are using that are actually likely to pose an issue or a threat to your organization. Uh, so we're not swimming around and like mouth spam that your settings are gonna block. We're focusing on what's going, what's getting through, and how are threat actors evolving to ensure that they can get that campaign to your inbox or your organization's users inboxes.
That's, that's super valuable because I come out of enterprise threat, Intel is in a bunch of like private threat intel sharing groups, and much of it was about mal docs and mal sharing, and that's super valuable for sure.
But you're right, like you see a lot of the, it's difficult, like especially my older days of getting into it, they're sharing like complex regexs to like identify, you know, the name of an email string and then, you know, every order then go out and search for those strings of like, you know, the specific wordage that was in the subject title and then go pull it out of email. And I'm like, this is just like only the biggest of the big, of the big orgs can can, can do that profitably.
So it just seems like we're missing. That's why I asked you that question, Molly. It seems like we're missing that component, which I'm glad you guys Say we is. You stole Gary's thunder, he's huge in RegX and, and you know, metadata, so I appreciate you. Yeah, Yeah, I'm sure Gary has got a lot of riveting RegX discussions coming up, so, so get ready, Molly. Yeah, yeah. Uh, in fact, it'll start with him telling you what RegX stands for, uh, as well, right, Carrie? Yes, absolutely.
Uh, and uh, Wes, you definitely can, we, you can maybe start by taking a look at those poll results. They're amazing. Yeah, Well, they're interesting, aren't they? And I'm wondering if there's some confusion. There was some, I think Frank said, you know, is this for us or for our clients? This is Andrew, this is for you and your MSP, right? Is the intent of that question. Yeah. Right. And so, But look at the results. Does it matter? Does, yeah. Right. Yeah. Which Yeah, yeah.
So Like, because these, my thought would, here, Wes, I mean, you know, it's a fair question when I did it and poorly, I guess poorly written was, you know, as an MSP, they're targeting your platforms, right? So that was like, what are you doing as an MSP internally? Are you doing anything internally? Right? Um, define security vendor phishing.
Tim, if you take a look at what happened, just Google CrowdStrike callback campaign, um, that was the most recent exploit where a CrowdStrike was, uh, the platform that they tried to exploit. So yeah, West, no, it's good. And that, Andrew, that brings up my first question. So I do, if you're listening to us today and you haven't seen that CrowdStrike, Phish, Andrew, maybe if you get a minute, you could post a link into chat. Yeah. If you'll could See what we're seeing.
I'll just put my, if it's okay with everybody, I'll just put my LinkedIn post. Yeah, Do that. Um, 'cause I have it right there. And Yeah, Go ahead. Bless. Okay. So Molly, this, I mean, that's the stuff that scares me personally. I remember my banking days, my, my teller staff would actually get phone calls from people being like, Hey, this is your printer technician. And they'd make up a company and they'd want someone to go download a file and install it so they could check like toner levels.
It's total scam stuff. And man, that stuff, I mean, I remember years ago that stuff was happening all the way into today where you see very, we've talked about spearfishing and targeting stuff, but actually leveraging a vendor like CrowdStrike that has great street cred, I have to think that's like really effective kind of stuff. Can you talk more about that evolution and what you guys are seeing around that kind of attack vector? Yeah, absolutely.
Wes, and exactly to your point, call center types, types of attacks are not new. Um, I remember in 2017 getting a call to my house saying like, we've detected that there's some malware on your computer and you need to boot up and you need to go to this website. And, um, my husband is also in the cybersecurity field, so we're like, let's kind of see how this conversation unfolds. We're curious.
So we were pretending we were doing it and um, like just having issues, uh, accessing it, and we kind of strung 'em along for a little bit. And then we said, we know what you're doing, how dare you. Goodbye.
Um, to give a little bit of insight into where these operators are coming from and what their mindset is, it was clear that the operator who was on this call with us was going to be in hot water with his manager for, I don't know if he had given any indication that we were on the hook or what, but he was outraged and call. We, we had a landline, I mean, good old days and just kept calling and calling and calling us back. We had to disconnect our phone. He had his manager on screaming at us.
It was bizarre, but it also gave some insight into the, um, actors behind here who are likely getting paid and getting paid by the number of successful, uh, infections that they cause. But yeah, this isn't new at all. What we've seen though, is a hybridizing of a phishing element with this type of scam or malware delivery tactic. Um, so it's an evolution of this threat that we've known for some time. Uh, here at Conce, we've been tracking bizarre loader since October of 2020.
Um, this is a malware that popped on our screen, on our radar because we saw with Riot ransomware, which I'm sure a lot of people will remember, was, um, wreaking havoc in, uh, the US and Western Europe. Um, especially targeting a lot of hospitals and taking down a lot of hospital networks. And we noticed that threat actors were shifting from using Trick Bot to deploy riot, um, to then using Bizarre Loader.
And so we've been tracking this, uh, malware for quite a while and in, I wanna say spring of last year, we saw this emergence of this phishing threat paired with the call center threat, um, where similar like phishing campaigns were sent out saying things like, oh, you're subscription, your free trial for this subscription is about to expire and or, and so you're going to be automatically charged if you don't, um, let us know that you're not interested.
And if you don't want to be charged for the subscription, call this number. So then you call, you engage, you go to the website and inev inevitably malware, if you continue to fall prey to this, the malware is deployed to your system.
And now we're seeing this taken up a notch exactly as you all said, where they are using cybersecurity, providing companies to enhance the legitimacy and also to invoke more fear that, I mean, it's one thing to let a, uh, free trial move into paid subscription and it's like a few dollars a month, then that's one thing.
But if you are worried that CrowdStrike or another major and like, well-respected organization in this field is saying, you know, we have a problem and we need to figure it out, now you're just increasing the legitimacy and increasing, increasing the fear and emotional response, which is what we see in phishing.
They want to look legitimate and have a major sense of urgency so that you'll act as quickly as possible and you'll be moved to act before your like, rational thinking mind might catch up and think, well, hey, maybe something's not passing the sniff test here. Test. Yeah. So what you're telling me then, and I I think if I can put a few extra words into your mouth, Molly, is you're saying that we're seeing an an A raise in the arms race, right? Mm-Hmm.
In, in terms of like, not just the, the sophistication of the language used in the ingenuity used by threat actors in this.
And I think you're right, this is gonna be a growing problem, even thinking about how many researchers that operate on their own Twitter channels, but under, you know, under the day job of a major security researcher, it's so easy for threat actors to like take the identity of one of those, or mimic the identity of one of those because everything's very, very, very, um, how do I say it?
Uh, it'd be, it'd be easy for someone to even reach out on a Twitter handle and say, Hey, I represent, I'm a, you probably know my name. I, you can go look 'em up on CrowdStrike, this is me, uh, uh, and here's my Twitter handle and I'm deeming you these, this stuff. I mean, for sure CISOs that are out there, security analysts that are out there are gonna see that stuff and like, man, it just bypasses your controls and it certainly is a spooky kind of thing.
And I just have to wonder, where do you think that stuff comes from? Like, where does this arms race, like that scene, is it inside knowledge they're getting this, these tactics from like, how are they learning the language? How are they getting these in, in, in like, where's this ingenuity coming from in their part? This is just the evolution of a cat and mouse game that is fishing the fence. I mean, they, and, and what we will often see two s is, well, we see this all the time.
Like we'll be tracking a particular malware, for example, and saying, okay, all of a sudden we're seeing it using all of these varied delivery tactics to reach end users. What's happening there? Their operators are testing, they're throwing a lot of spaghetti at the wall and seeing what sticks. Yeah, that's marketing 1 0 1 man, AB testing. Yeah.
They're testing to see what's getting through, what's getting clicked, and then we'll watch them kind of consolidate what tactics they're using for a time. Then everybody's reporting on it, everybody's talking about it. Those who are playing the defense game catch up to it, and that forces them to innovate further. That is, that's what we've been tracking at Conce since the beginning, the founding of this company is this evolution.
But what's so amazing too is you'll see them turn around and loop back to tactics or malware families that were used like 10, 15 years ago. And because we have started to, we've been so focused on what's been successful in the last three years, that we're not looking at what's worked before, how that they can evolve those tactics too. So it's, it is quite a mix around, um, ingenuity and creativity.
You know, how often do we think if people, like were using this creativity for good, how far we could be as a society? Um, but there, there, there in, as we are innovating and it's just We, The game shifts the wind shift. Well, I love what you just said going back to the old stuff, Wes, because it really typifies like vulnerabilities, right? And, and if you think about Sun Neil's cyber defense matrix, right? Right now we're, we're in user protect if we're gonna ground everybody, right?
We're talking about user protect, the asset being the user here, but they're, as Molly said, they're recycling old stuff that our defenses aren't really looking much for anymore. And similarly in device, um, protect as well For a year, right? We've been talking about assumed breach mentality and MSPs continue to throw, I get to see the tool stack for 250 companies, right?
And I see where they're piling their money into, you know, to protect and you know, just saying like, Hey, you gotta go beyond that because there's nothing you can't protect. There's social engineering around almost everything. Yeah, yeah, yeah. Oh, write a boom is, is such a vital piece. Gary, you course, Go ahead. So Molly, here's something I want to ask you about. Is this Arms race that's raising and the ingenuity you're talking about.
I'm gonna post a link into chat for those that don't know about this, but Bleeping Computer did, uh, an article a little while ago about Lock bit 3.0 and their new Bug Bounty, and again, a very creative thing. So what Lock Bid is now doing is they're saying to people, Hey, we will pay you if you find interesting things.
We recognize that you may be not willing to go run a ransomware campaign yourself, but you may be somebody with very dubious moral and ethical liability, and you might want to tell us about something and get some crypto back in honor of it. And please, if you're listening, if you have that in mind, don't do that. That's the way you go to jail. Um, but we're seeing that Molly could make millions, right? I mean, pay my, my better call all lawyer, maybe I get out, right?
They're like, oh, we see your bug bounty programs and there's something to this, this is a great idea. Okay. Right, Right. Yeah. And so we can do this too. I just, are you, I, my question is do you, have you seen evidence of this or do you feel like some of the ingenuity that's coming outta this is coming from vectors like that?
In other words, every person's gone through a PIN test and there is a social engineering element to it, and they're all like, man, if they had just asked this question over here that they didn't know about, 90% of our company would've clicked on it, right? Like, do we all know those kinds of weaknesses? And are you seeing evidence of like people pushing in the, those trade secrets inside a company to use to leverage for a phishing vector?
Or are we seeing that, or is, is that still not there yet, do you think? I can't say that we're seeing evidence about of that, and I'm not sure it's really needed except for some probably very specific targeted scenarios like you're speaking to us. Like if you're going after a highly protected and highly educated individual, in those cases, there may be benefit.
Like they may be able to leverage some of that if you are trying to access a company that is quite a large company and you only need one person to fall for a fish to give you the access that you need, unfortunately, from what we're seeing right now that they just may not need to pay for that additional, like an additional info or intelligence on their side.
Um, but that is something, you know, we're constantly mindful of, you know, as we're seeing more targeted techniques take place is something that we're mindful of. I just can't say we've seen the evidence directly of that. Um, yeah. Okay. That we could at least link back to that at that at this time. Okay.
It just scares me because I feel like as we mature our security processes, and obviously you mentioned cat and mouse, at what point did they start getting really insidious with some of these ideas? And you know, you even saw the, the meet last year with, uh, the, the Tesla employee and one of the threat actors trying to leverage a Tesla employee employee to get into their network, right? Like, do you're seeing this stuff begin?
And boy, that's the stuff that I think for any defender becomes pretty scary. My last question for you before I flip over to Gary to grill you on the technical bits and details, um, is let's talk a little bit about like what kind of campaigns reach end users. And I think this is important because we all have mail gateways that are good at blocking things.
If you're blocking macros, for example, if you're blocking like, you know, um, strange domains and, and locations that shouldn't come in, we can throw a lot of that stuff out. But what stuff do you see that actually reaches the end user that's the most dangerous? So it's all dangerous. Um, and I'll say by and large, in terms of volume, we mostly see business email compromise and credential phishing campaigns, reach end users that said, we can't get complacent around malware.
And we do see malware campaigns reaching our customers daily. So that's not to say take your eye off that prize and only focus here. Um, and credential phishing campaigns and business email compromise campaigns, as you'll know, they're very complicated because with BEC style campaigns, there's nothing inherently malicious about an email. So you can be doing language pattern matching, but threat actors understand that we're doing that too.
And so they're varying things or create doing things that shouldn't, that would mirror, uh, legitimate businesses as much as possible. Again, that cat and mouse dynamic. Um, but there's nothing inherently malicious about those campaign types. Uh, and credential phishing campaigns, you know, of course the credentials are the king keys to the kingdom. So the threat of that, I don't, I don't wanna come off as condescending to go into that.
I think everybody here knows how big of a threat that poses. But credential phishing campaigns also are like very easy to change around malware hosting, malware infrastructure, C two infrastructure, um, everything that exposes or highlights, hey, this to a, to a defense tech stack, Hey, this is sketchy infrastructure, do not connect. That's more bulky.
Credential fishing, harvesting pages is so easy, inexpensive, very little time requirement to just change where you're hosting your credential harvesting pages and, uh, sites. So that changing over those URLs, that's really easy to do. And so those IOCs, as you all know, are very short-lived.
Um, and so that for those reasons, and again, it's not like a payload or a malicious payload, um, is being delivered as part of that campaign that as SAG is seeing and, and understanding, no, no, this is malicious do not permit. So it does make sense why we see those at such higher rates. But again, um, malware actors are constantly working on getting their threats through, um, or using indirect means to land and deploy their malware to your system.
So they're finding, they have found ways to evade this and overcome these issues as well. So, like I said, it can't like rest on our laurels that malware based phishing is not a threat. It very much is. We, Wes, can I ask? Mm-Hmm.
Molly, a quick question before we go to Gary, Molly, you know, you've mentioned with like BEC and your, you know, being one of the top things or the top in phishing are should, should we not be like on LinkedIn and social going, Hey, I'm going to black hat, or I'm going to this conference almost like telling everybody, Hey, by the way, I'm leaving my home. It's open, you know, it's unlocked for the next week, but because, uh, people fall, you know, if they are being targeted, right?
Isn't that, is that a vector, or I shouldn't say a vector, but is that something that we should be a little more vi vigilant about these days? About not saying 'cause Oh yeah, Gary told me to wire this. Now I know Gary's out of town. I know it's a simple thing, but is it, is it the simple stuff that matters sometimes? Yeah, absolutely. And education is so critical.
I mean, people throughout the organiz, your organization, especially anyone with access to the purse, um, or a company credit card, they need to be very, very, very well educated in business email compromise. And I would definitely recommend that that is a part of their onboarding for whatever access they're given.
So if you have a organization and they're, you, you, um, provide credit cards for business expenses, every employee should have to go through understanding training of business email compromise because that their target. Yeah, That's fair. So As we, as we end, I just want to reiterate this, we're in 20 freaking 22, and you heard it right from Molly Business email Compromise and Credential phishing we could have reversed 10 years ago, 15 years ago, and those have been the top two.
It's incredible to me that that's still there. And uh, I'll just close with saying this, cyber insurance is aware of that and they're now forcing things like good wire transfer and money transfer policies, they must now be in place to mitigate this user awareness education that covers these topics must be in place because it's crazy to me that we're still in 2022 and you heard it from Molly, those are the top two threats still today. That's gotta be Interesting.
But now what we're seeing all the time too, are these gift card based, uh, fraud attacks too. So again, okay, what's a way that doesn't involve like a wire transfer? Oh, I'm going to impersonate the CEO and say I'm going to this event and I wanna give out like five, $100, um, Amazon gift cards for like, we're gonna have a lot a raffle prize, something or other. We see that all the time too. So again, finding ways to think outside the box to still get it done.
And then it's really hard to trace how those, uh, gift cards are used after that happens as Well's. Really good point. Thanks for that, Molly. Uh, Gary, over to you. Yeah, so you saw the poll, it came up basically 50 50 Molly, Right? Yes, I did. Yeah. Yeah, so like, I would say I would give us as a community an F on that, a 50% is a would be an F unless we grade on a, unless we grade on a curve. You know, it's funny, I get these all the time, right? To my True Methods account.
Um, but I saw the first one, like you're talking about in my personal email account where it came something, it looked like it was coming from, uh, the Geek Squad and that they had charged my credit card, uh, for a warranty or something. And, and there was no link. It just was a phone number, you know, to call. And so I couldn't help myself and I had to, you know, call it and did the same thing. I just had some fun with them and strung 'em along, you know, for a while.
But that's the first time I had seen that tactic used. I guess it's more disarming, right? 'cause you're just, we're programmed to look for links not actually have a, a number that we can call that makes us feel much safer, right? Yeah. I think depending on the individual too, and again, when they offer a whole host of options, like what fish would you like to call for today?
There's something for everybody because people are just going to be more, um, inclined to different lures and different tactics. And like I mentioned before, we just see so many different things, um, tried. And invariably we know because we know of the losses, we know because we know of the incident response stories. Um, the, we know that the stories that are publicized in the media are a fraction of what's actually happening too.
And it, it is devastating how effective the phishing tactics are. And that's because they are so varied. Um, and they are like, it's such a noisy attack surface to monitor for our team. It's, it's incredibly noisy. And that's why we did have to kind of focus on the front tip of the spear, like I said. Yeah. So I mean, we know that so many people aren't deploying to all their customers, right? Security awareness training.
But even if they are, do you think even then a lot of people that are trying to like, make themselves feel better or check some regulatory box, um, then truly something that they understand is mitigating threats? Yeah, I, yes. There's nothing more disheartening than coming across a program that is more just, let's tell the regulators we're getting it done kind of an approach. Um, I think if your security awareness training is not, um, built for impact and it needs to, it needs two things.
It must be intelligence driven. You need to be training individuals to understand the threats that are actually likely to face 'em. Like creating your own little phishing page because you think it's fun and sending it to your users to see if they spot it as a fish, that's not nearly as effective as really aligning your program to the actual, uh, threat landscape and the fish that are likely to reach their inboxes. So it needs to be intelligence driven.
Um, you also really need to bring your employees into the defense strategy. So just telling them, this is how you engage or this is how you spot a fish, that's not enough. You need to be empowering and enabling them to be your last line of defense in the phishing threat. And to understand that they play a critical component to that defensive strategy for your organization.
Um, so giving them the ability to report any suspicious campaigns that they see, or any suspicious emails that land in their inbox. Um, getting them to understand that this is really a team sport. This is not a, like, I'm just something else that I have to do that I'm a critical component of this company's mission. And this is a part of that. Uh, you bring people in. So you're talking about creating a culture, right? Absolutely. Around governance. Absolutely. Yes. Yeah.
Um, so what do, do you think at some point that there, um, 'cause I've seen this, that there needs to be, um, you know, the other side of it, like you're talking about community and some type of a, a carrot. Do you think there also needs to be a stick? I mean, like at some point you're having these trainings and if the same person on, even if they're on an executive team over the course of six months, now it's the third time that they have clicked on something.
Like at some point, do you think there needs to be recon, you know, repercussions that impact your job? Absolutely not. And here's why. So we've been doing a ton of study. We've as a company has studied this over the years. And what happens is when you have re retribution policies in place around this is you get people to disengage. They don't wanna risk click, they don't wanna risk anything.
And so your, um, last line of defense, your intelligence gatherers and real time on phishing threats reaching your inboxes, that gets weakened. So your organization becomes more susceptible overall to the phishing threat. So let's say for example, you have 10 users in your organization and they all get a fish, let's say three of them identify this as a fish, let's say six of them don't identify as a that it's a fish, but may or may not click. And one is a clicker who's a repeat offender.
Okay, repeat clicker. We don't like to say repeat offender. Not, I did not say that. Repeat clicker. So let's say No, You can't take it. No takebacks. I know I'm no takebacks. This is, this isn't live or recorded, right? Okay. Oh, it's both. Yep. Um, okay. Let's say though that three of those users are able to say, this is a phish, I'm reporting it, they're able to report it.
You're getting that real time intelligence that you have a phishing campaign reaching multiple users within your organization, and now you can go and quickly identify if anybody has clicked, you can go if you have the right tech of on hand, which we highly recommend, you're able to identify who else in the organization has received that phishing campaign and remove it.
So maybe you even can remove it before that repeat clicker gets to that campaign because of your three frontline folks who saw it. Now, let's say six of your frontline folks, front six people that were six of those 10 people reported that Phish, you're getting that real time intelligence going through, you want people as engaged as possible.
And what we have seen firsthand is that if you are using retribution and you're using the stick that we, that fabric weakens because people just become fearful of engaging at all. Um, and so like cannot be more, say it more strongly that we completely view this as bring everybody into the fold. And by enabling this like circular input, real time intelligence, you're able to accept the risk of those who will click. Yep.
Um, well I'm glad you said that because I was just about to put Andrew on a PIP because, uh, I got him to click three times on, uh, a phishing using keto supplements, right Andrew? He can't resist. Yeah, that's okay. Alright, I, some other stuff, but I, I'm gonna, I'm gonna make sure we have time for Phyllis, so if we have time, we can circle back at the end. But I'm gonna, I'm gonna hand over to you, Phyllis. All right, thanks. And thanks, Molly.
I mean, I really love, um, the fact that you have, uh, your experience behind you at Conce, you know, really, um, uh, imparting your knowledge to us on this call. And as you see, you know, um, around 50% of the organizations on this call, mainly MSPs, um, really don't do much with, um, phishing. So as you know, and there was some discussion, do you mean just me, do you mean my clients as well?
What would you recommend with your experience and your role at Conce, uh, that MSPs do on behalf of their customers? It's not just one, you know, it's hundreds, tens, however many, how can they help their org, the organizations they support?
Yeah, I mean, it's important that your organizations, and again, I know that there can be different areas of focus with particular MSPs and their customer bases, but understanding how pervasive the phishing threat is and how it is the initial vector for so many threats. Um, supporting and encouraging, uh, simulation-based phishing awareness, uh, and also implementing, uh, and, and, and nurturing a reporting culture within these organizations is really important.
I think for MSPs, you know, understanding that they may be a smaller organization operating, um, security controls for so many users, it, it would be hard to be, uh, one by one looking through individual phishing reported phishing campaigns to identify if they're a threat or not. Automation is so critical and there are, um, tools that fins offers. There are tools out there to help ensure that a lot of those threats can be removed or neutralized, um, from the get go.
So, uh, allowing automation in terms of identifying who has received a known fish and removing that fish from an inbox. The clock's too short to leave that to manual operations. And I think that that would be really important. Um, again, it's also, I think, really tricky to manage different tech stacks with different configurations. Mm-Hmm. Um, so if you don't have an automated capacity to identify or neutralize what's coming in, that's going to be difficult.
So having those phishing specific automated phishing defense tools is really critical in our, in our view. Of course. Yeah, I agree. I mean, automation is always important. So, you know, um, it's really important to understand, kind of be beyond the phish or behind it, like what really, um, our organization's trying to defend against. What do you think from your experience that advanced threat actors are really doing behind these successful campaigns? What's the end goal? What's the end game?
Great, great question. And it really depends on what their objective is. Mm-Hmm. So, um, and it's, so, it's, so one thing that's been really fascinating to watch over the last five years since I joined Conce is when we say advanced threat actor, um, the floor has really come up on the least sophisticated actors.
Uh, overall, you, I think we've seen, um, an improvement in what, like the low point the, the floor is on skill sets too, because of the open source tools available, the amount of resources, sadly, that new hackers have, I mean, it, it's really disheartening to see how much better your most novice threat actors are and how much more they, they seem able to have an impact. But going back to your question, it really depends on their objectives.
You have your traditional espionage actors, um, who are targeting those close to policy makers, those, um, those who may be in a competitive field to them. So that espionage can also include business espionage that they just want information. So they're just looking to establish persistence and, and they just want to be able to see what your organization is doing, um, for that to keep their thumb on the pulse for their own traditional espionage, um, reasons.
And you have those that are seeking to steal, uh, PII or ip, um, that may be for whatever organization they're working for. It may be for themselves, or it may be to sell to the highest bidder. Um, we also see that with like gaining access, just establishing access and then selling that access to someone that wants to then maybe deploy ransomware, um, or deploy any other malware to a user or engage in an extortion campaign with the user.
Um, and then of course we see a lot of financial theft and, um, I, yeah, I think that there's a range, a great range in terms of sophistication for a lot of these threats. But what we're seeing is you see the implementation of, um, different tactics in service of different objectives across those primary ones.
Phyllis, what's interesting is how we have to, we have to implement automation as defenders, and then it seems like the attackers, um, really embrace automation more quickly, um, oftentimes than defenders. Go ahead, Andrew. Sorry. Yeah, No, I, I was, what, it was interesting what Molly was saying. Um, Molly, it almost would also seeing like, you know, going back to the intelligence, you really have to understand the vertical too.
For example, if you're in the defense industrial base, to your point about, like, I'm not saying people don't wanna steal money, but they may be much more motivated to steal blueprints or information, right? For, for, which is the whole method, you know, the whole obviously, um, motivation behind CMMC and what we're seeing in the defense industrial base. So I, it, it just kind of made me think about what you said, it's gotta be intelligence led.
It can't just be, here's a security awareness campaign. Yeah. And a lot of our like critical infrastructure organizations, like in the financial sector, energy sector, they're in this, like, I know a lot of people working, um, cyber intelligence for these organizations and they're very worried about like, what's happening geopolitically, because they know that they could be used as part of, as part of a conflict.
For example, if a nation state wanted to punish or send a strong warning to the US without taking a direct hit on US government, US federal networks or organizations, these industries are worried that they could come in the cross hairs as a way of escalation without formal, formally taking us into active war territory. And a lot of these lanes have not been defined. We're seeing this in Ukraine today, right?
Like there's a lot of gray area around what's a trigger for article five, for example, with nato, if some there was to be any spillover out of Ukraine and the cyber space, what is kind of, what's the threshold? What's the red line? What are the red lines here? A lot of that has not been determined. And so a lot of organizations that sit kind of on the boundaries of this are monitoring these things very closely.
So what would you recommend, I mean, I, I like what you said, you, it has to be intelligent and you have to use some intelligence behind what you implement. What do you recommend, really, what kind of process do you think MSPs should use and when looking at their client base and trying to help them? Yeah, they need to be, um, we've, we've touched on all of this really. They need to be looking at what is their vertical, what are the types of common threats to target them? Um, mm-Hmm.
There are things though that are not, that you don't wanna be too sector focused either, right? Because just because a tactic hasn't been used against a particular sector before, doesn't mean it won't be soon. And by being, and, and what we do see as we are looking across sectors, um, from my team is that when something starts to work against one, we see it, we see it. Those tactics, those campaigns appear across others as well.
So that's why, I mean, that's why we view our, our offering is very valuable. 'cause we're phishing specific, focusing on the tactics that are effective in getting to the end user and providing our customers with the tactical intelligence to neutralize that, those campaigns in bound while also providing the strategic intelligence to understand what are the tactics and, um, we call it, it kind of TTP based intelligence.
So of course we're referring to tactics, techniques, and procedures that threat actors are using. You have to, you can't just focus on like hammering out one IOC at a time and blocking one IOC at a time. Those are too short-lived to be really effective at a strategic level, you have to understand what threat actors are trying to do and what's working for them and apply that as well. So, sorry if I kind of went on a, but having that blend is really critical. So I think that's important, right?
So while there are these different trends, like you can see it, it, it will be pervasive across everybody. And so I think that's important. That's the kind of benefit that you can get, um, from the different, just Quick tangent, we have a little bit of time, Gary, business side. So one, would you be, if you were, you know, direct selling again, would you be using this kind of as a wedge, as a kind of, as a maybe a, a, a commercial insight, you know, to a prospect about threat intelligence?
Are there, is there current MSP talking to them about this type of information? And then I'd love you to take it on the process side. I'm sorry, the role responsibility side. 'cause again, as you always talk about, sounds expensive, right? In, in terms of operations. Could you just talk about those two things for A moment? Well, as a wedge, a hundred percent, right? So this is one of probably four or five things that have come out right of uh, what we do.
We see, you know, half the people maybe aren't, might not be addressing this fully, right? And I get it, we have, we're trying to run businesses. The bad guys get to focus on this 24 7. Like we have to actually, and our customers have to actually, you know, you know, run businesses. But I think of it in two ways. Andrew, if I'm an MSP right now, I'm, this is one of those question areas that I'm using as a wedge also with my customers.
It's what I'm using to package new things together to go back and get my price up in chunks. Like we're seeing margin erosion because there's so much more process and so many more tools and many MSPs are shy 'cause they think they're increasing price, right? And they're not. They're responding to the environment that we're talking about with, with Molly today. And so I feel like they, they really need to get to get past that.
And kind of like thinking about what Jennifer is saying, like part of this is, hey, you want to use automation as much as possible. That's true. What we really wanna do is have ourselves and our customers better positioned against phishing. If automation is one tool to do it, and it is, we should, but we shouldn't, like, you know, okay, so we bought a tool, it's smart check, we go on to the next thing, which is what happens in the whole tool stack for most MSPs.
Andrew, No, there always has to be a human element to fight the fight against phishing. Um, because we just see firsthand, I, I do not believe that I'll ever see a silver bullet that allows us to be hands free in depending against phishing campaigns. And that's exactly right. And you know, a lot of these organizations, especially NSP customers won't have the type of, um, resources or sizing to ingest intelligence fees for example, and block based off of that.
So ensuring that what you're using is intelligence based and is on the basis of intelligence being provided against, um, combating phishing threats as well is a super critical component of this. You could still be basing on intelligence, your phishing defense, even if you're the, a smaller organization that can't be operating a threat intelligence feed and, and action handling alerts based off of that, et cetera, et cetera. Gary, one one last question to you before we go back to Phyllis.
So we've talked, you know, we kinda set the stage here that CrowdStrike was a me, you know, used as a potential mechanism. Yep. Would you be educating your customers about hey, we could as our MSP be targeted, let me share with you how we will only communicate with you. Like you might see our logo come through. Here's what we always want you to do. If you see it. Like, would you take it a step downstream for Oh yeah.
I mean anything we can do, what our job is to do for our customers is to paint more clearly what the risk landscape is. 'cause the only reason that they're pushing back on a project or on, you know, additional investments so that you can do a better job is 'cause they don't understand the risk landscape the same way that we do. And these kind of things are really real. And of all the things you talk about, they're probably the scariest.
'cause any one of their employees can look and say, oh that's from Wells Fargo, right? That's from CrowdStrike. Uh, and everyone has at least seen these things. So any tool we have to make the threat landscape real is something that we have to lever leverage a hundred percent and all these things. And what you're finding, like they should be at the minimum in your newsletter.
So you're keeping people educated, but also some mechanism where the, where your customers actually get these real time, you know, updates. Yeah, well it dynamic digital, right? Back in the day when it was your MSP, right? It could be Wells Fargo, it could be CrowdStrike, but it could also seem like it's us. It could also, right, exactly. So, alright, Phyllis, sorry I didn't get as fired as Gary does at times, but, you know. No, it's a great conversation.
Um, so Molly, uh, you had mentioned, and you know, Wes mentioned, you know, 10 years ago we were seeing these phishing campaigns. They're still, um, you know, one of the highest ways that organizations or, um, bad actors are getting into networks. Are you seeing, um, malware families, um, also repeating themselves and, um, coming back around and, and, um, are they just rebranding themselves? Like what are you noticing?
That's a really timely question because one of our biggest concerns right now that we're focusing on is a malware called Quack Bott. Um, this is like a fairly basic banking Trojan that I believe was released in 2007. It's been a long time. And all of a sudden we're seeing it reach in enterprise and users at an alarming rate. And we're finding that it's been added to, it's become more of a multipurpose malware. It's kind of modularized, which is something that we saw happen like 2018 to 2020.
We saw, um, threat actors kind of stopped going for zero days as much, and they were just like, how can we modularize these malware to just make 'em whatever we want them to be, and then kind of hide in the noise, uh, because it's so crowded with these low level malware. Um, but they've also made changes to the delivery tactics that are allowing them to be successful. Like they're hijacking.
They'll get access to someone's email via successful phishing campaign, and then they'll hijack their conversation with someone else to proliferate to then spread the malware to other, um, to other users. And so it's just shocking to see this little pesky malware that, you know, we would've rolled our eyes at five years ago. Like yeah, that's handled cropping right back up and reaching end users, um, and and being effective. Yeah. Right. Yeah. Yeah, exactly.
And they're getting innovated further. They're just getting built upon and, um, you know, we saw some emote is another great example. Emote, uh, very prolific, hugely prolific botnet, um, was taken down in January, 2021, a coordination between private public sector, and at the time we said they'll be back and we were right that November, they came back, it was too lucrative an operation to not at least partially reconstitute. Um, and so you just, what goes around comes around, right?
Same with delivery mechanisms like macros. I think think they were 20, go ahead. Go ahead. Oh, No, go ahead. Like macros. Yep. Yeah, in 2012, they were the delivery tactic that was beloved by all completely went away. And then 20 17, 20 18 cropped right back up. It's just what goes around comes around in this space. I think, uh, security folks would get really focused on what's the main problem problem right now and aren't keeping everything in the past up front of mind.
And it's hard to, and it's just such a busy attack surface, like I said, I think that's a good point and also drives home that you always have to be vigilant. Exactly right. Like you said, we all thought, oh, that's taken care of. Take that off the table, you know, let's move on. And then, you know, what's old is new, as you said. Um, you did briefly early touch upon, um, you know, things that you're seeing because of Ukraine and things like that.
Do you, do you have any other last comments about that? You know, perhaps, um, you already talked about current events and trying to be vigilant that way. Was there anything else you wanted to add to that? Um, we are finding overall that global events tend to be much more popular in terms of what's weaponized for phishing war content. Uh, we expected a lot more around the last presidential US election, for example, than we got mm-Hmm.
Um, we did see some, but not at all at the levels that we anticipated. Uh, COVID themes around when as the pandemic unfolded remote work themes as we shifted to remote work world, um, and Ukraine we've seen a lot more content on. So right now that's, that's what we're tracking though, always subject to change. You've always gotta be really mindful of, um, current events, themes in phishing campaigns. Oh, Andrew, you're on, um, mute.
I was gonna say, Molly, do you think it's any, um, coincidence that post, you know, COVID that we saw a lot more vulnerabilities discovered in firewalls, VPNs, meaning the threat actors knew obviously remote work, work from home was a thing, and therefore, hey, well why don't we start really looking into these devices that enable that? Is, is that coincidence or do you think there's a direct correlation there? Not a coincidence at all.
Similarly, as we saw businesses shift to, um, cloud platforms, we saw phishing follow suit, uh, hand in hand. So this is not a coincidence whatsoever. This is very typical kind of tracking, uh, trends and identifying ways to leverage and weaponize what we are most reliant on. And also recognizing that as we're shifting, there's likely to be more soft spots, more soft underbelly, if you will, for them to target.
So as organizations are shifting to the cloud, as organizations are shifting to remote work, um, there, there's this opportunity to take advantage of the, for some organizations it might be chaos. For some organizations it might be just a little transition where things aren't in focus in the same way as they typically are, and threat actors are excited to capitalize on that. Sure, sure, sure.
Well, in the, in the last few minutes here, um, Molly, um, Lee asked a question, Lee, I'm, I'm gonna paraphrase it, but I think you're saying, are there specific, you know, um, focus target, you know, things that, uh, you know, threat actors focus on the MSPs? Um, we did, you can actually look at it. We did a, um, we used Gold Southfield as an example when we did Wes, Gary and Ryan Weeks, and I, um, a, uh, uh, a threat, uh, emulation, um, gosh, uh, Wes help me with the correct term threat.
Uh, adversarial emulation. We, we brought in atomic red team. So yes, if you go to Mitre, if you Google managed service provider, absolutely there are tt there are techniques the threat actors use to exploit MSPs, no doubt about it. Um, so in the closing, like minute and a half or minute we have here.
First off, Molly, so wonderful to have you on, and for all of the hate I get out there, I'm kidding around Molly, we now have, I, I just want everybody to know there are two females on the cyber call at one time, Molly, for, for the longest time it was only males. And, but so anyway, we're trying to continually evolve our, uh, space here. Our Goal is all female, no male. What's that? All female, no, male is our goal. Yeah, Exactly.
Um, you just have to let us know who that next Gary Pika would be, uh, Gary. But, uh, Molly, wonderful, really wonderful to have you on and bringing, um, you know, you know, the, the wealth of information and expertise you have. Um, so very, very grateful. Thank you so much. Oh, my pleasure. Thank you for having me. Yeah, and as always, on behalf of Phyllis, uh, Wes, Gary, thank you guys. Uh, my cohost as always. Hey, great job today, everybody. Yep. Yeah, great call and our, our community.
As always, thanks a million and we look forward to seeing you all next week. Take care, everybody.


