The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Decipher Security Podcast
Decipher Security Podcast artwork

Fable 5 Export Controls, the Dual Use Paradox, and the ARToken Phishing Framework

Decipher Security Podcast · 2026-07-02 · 37 min

0:00--:--

Key moments - from our scoring

Substance score

21 / 100

Five dimensions, 20 points each

Insight Density5 / 20
Originality4 / 20
Guest Caliber2 / 20
Specificity & Evidence7 / 20
Conversational Craft3 / 20

Anthropic recently lifted export controls on Claude 3.5 Fable after reaching an agreement with the US Government, implementing new classifiers to block cybersecurity tasks while moving some functionality to older models - a compromise that raises questions about the effectiveness of restricting AI capabilities rather than the underlying risks. The episode explores the broader dual-use paradox that has haunted technology since encryption export controls in the 1990s: restricting tools typically impacts defenders more than attackers, who simply pivot to alternative methods. Hosts Dennis Fisher and Lindsay O'Donnell discuss how this regulatory approach mirrors historical precedent with tools like Metasploit, where restrictions create theater rather than actual security. They also cover the ARToken operator panel - a backend control system for the Evil Tokens phishing-as-a-service framework discovered by Cisco Talos researchers - which reveals sophisticated automation in the cybercrime ecosystem, including AI-powered email analysis for business email compromise targeting. The conversation addresses how attackers continuously innovate around barriers like MFA, why government lobbying power makes such restrictions ultimately ineffective, and the emerging pattern of early regulation around AI capabilities compared to previous platform evolution.

Key takeaways

  • →Export controls on AI models are theater that primarily hinders defenders while sophisticated attackers simply shift to alternative methods, as demonstrated by historical precedent with encryption export restrictions.
  • →The Evil Tokens framework uses AI to automatically analyze compromised email accounts for business email compromise opportunities, dramatically reducing the labor needed for targeted phishing attacks.
  • →Dual-use technology restrictions have plagued cybersecurity since RSA encryption controls in the 1990s, and regulatory approaches that impose blanket restrictions miss the nuance that tools can be abused regardless of legitimate use cases.
  • →AR Token represents a sophisticated phishing-as-a-service backend that reveals how cybercriminals build hidden infrastructure mimicking legitimate business economies with specialized labor divisions.
  • →Anthropic and other AI labs have significant lobbying and financial resources to navigate government restrictions relatively quickly, making regulatory showmanship unlikely to meaningfully constrain their operations long-term.

Guests

Katie Masouris

Topics in this episode

Dual-use technologyMetasploitClaude/Fable 5Evil Tokens frameworkAR TokenPhishing-as-a-serviceMFA bypass techniquesExport controlsCisco TalosRSA encryption restrictions

Questions this episode answers

What did Anthropic do to resolve the Claude 3.5 Fable export control issue?

Anthropic redeployed Claude 3.5 with new classifiers to block more cybersecurity tasks, while moving routine coding and debugging tasks back to Opus 4.8, aiming to reduce false positives while continuing to refine restrictions to distinguish legitimate requests from potential misuse.

What is the Evil Tokens framework and how does it bypass MFA?

Evil Tokens is a phishing-as-a-service framework that automates labor-intensive phishing attacks and helps attackers bypass MFA barriers through various methods including push notification exhaustion and token theft, rather than exploiting actual weaknesses in MFA systems.

What is the ARToken operator panel used for?

ARToken is a backend control panel for the Evil Tokens phishing-as-a-service framework that was discovered by Cisco Talos researchers; it enables attackers to manage and orchestrate phishing campaigns, including using AI to automatically analyze compromised emails for business email compromise opportunities.

Why do export controls on AI models like Fable 5 potentially hurt defenders more than attackers?

Attackers can pivot to alternative tools or techniques (like social engineering or help desk phishing) to achieve their objectives, while defenders lose legitimate use cases; historical precedent with tools like Metasploit shows restrictions create regulatory theater without meaningfully reducing attacker capabilities.

How are threat actors using AI within the Evil Tokens framework?

Threat actors use AI to automatically sift through compromised email accounts, identifying high-value BEC targets like communications between employees and finance personnel, which significantly reduces the manual labor required to find viable attack opportunities.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

5 / 20

The episode is dominated by weather small-talk, World Cup digressions, Sammy Kamkar fan-club tangents, lobbying anecdotes, and MFA mean-tweet nostalgia. The only substantive segments - ARToken/Evil Tokens and the dual-use paradox - are brief and stay surface-level, offering almost no novel claims a working security practitioner wouldn't already know.

it's basically been all. All I've been doing is, like, watching soccer and doing this stuff
I remember when Metasploit was released, I don't recall what year it was

Originality

4 / 20

Every framing deployed here - dual-use paradox, defenders hurt more than attackers, MFA is critical despite bypass attempts, cybercrime as an economy - is well-worn conventional wisdom in security circles. There is no contrarian argument, no first-principles reasoning, and no fresh angle introduced or defended.

the dual use argument or not argument, but dual use kind of conundrum never has
attackers are going to find other means to achieve their objectives most of the time

Guest Caliber

2 / 20

There are no guests whatsoever in this episode - it is entirely two co-hosts chatting. A past episode with Katie Moussouris is mentioned warmly but she is absent here, so her caliber cannot credit this transcript.

I did, uh, I mean, I mentioned the podcast with Katie. I'd encourage everybody to go listen, watch to that one
Anytime we get a chance to have Katie on the podcast, it's just a treat

Specificity & Evidence

7 / 20

There are a handful of concrete specifics - ARToken panel discovered by Cisco Talos, Evil Tokens framework, Peter Stokes aged 19 arrested in Finland and extradited, an Iranian national targeting 150+ US universities since 2013 - but most claims are vague and unquantified, and the hosts frequently acknowledge uncertainty about basic facts like Metasploit's release year.

researchers at Cisco Talos discovered this operator panel called AR Token that had not been publicized before
Peter Stokes, who's 19, dual citizen of the U.S. and Estonia, was, uh, arrested in Finland and then extradited

Conversational Craft

3 / 20

With no guest and no interview structure, there is nothing resembling probing questions or productive disagreement; the two hosts almost exclusively validate each other's takes. Conversation drifts freely into unrelated personal anecdotes with no attempt to anchor back to actionable substance.

that's a professional way to wrap it up right there. Lindsay. Nice job. You're welcome
I sound super cynical. Maybe it's because I was watching this, like, Netflix five part documentary

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A72%
  • Speaker B28%

Most-used words

funny12remember11podcast10different10dual9katie9away9sammy9back8cool8world7tools7trying7money7sure7worm7

Episode notes

It's a pre-July 4th extravaganza! To celebrate, we dive into a little cybersecurity history with a story about the MySpace Samy worm, then we jumpe into the news of the week, including an update on the Fable 5 export control drama, and the emergence of the ARToken operator panel.

Full transcript

37 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello, everyone. Welcome back to the Decipher podcast. I'm Dennis Fisher, joined as Always by Lindsay O' Donnell Welch. It's a pre 4th of July episode, Linds. It's hot as hell in Boston, and I think pretty. I mean, a lot of the US Honestly. And if there's one thing that people in New England love complaining about more than winter weather, it's summer weather. It's like everybody's surprised every year when summer occurs again, just like they're surprised in January when winter shows up. But, um, yeah. So just hiding inside, watching an unhealthy amount of World cup, basically, for the last week.

Speaker B: Yeah. Not leaving the house. I think it's like. Like high 90s these few days, so.

Speaker A: Yeah, yeah, it. It's, uh, you know, it's like everybody in the US has been kind of laughing at people in the UK and Western Europe about, like, their heat wave or whatever, and then just like, whining that they don't have air conditioning. And then it hits here and everybody does the same thing, even though, like, most of the US Is air conditioned, you know? Um, but, yeah, everybody just loves to whine about stuff.

Speaker B: All the more time to go read, uh, about the latest security news. I guess we're all inside, not at the beach.

Speaker A: It's basically been all. All I've been doing is, like, watching soccer and doing this stuff. Yeah. And, um, yeah, there's. There's been plenty of stuff. I mean, luckily, no, um, no big supply chain stuff, which is nice to see how a little break from that. No crazy, massive AI like disputes or nonsense. I guess the, uh, Fable 5 thing is still ongoing. There hasn't really been a resolution to that. Like the export control situation that occurred, uh, probably three weeks ago now, something like that. In early June. I want to say that was.

Speaker B: I thought I saw. Did. It was just like last night that anthropic said that they lifted the export controls. Oh, I think so. I think it's, like, breaking as of whatever day it is. Wednesday.

Speaker A: Yeah. Today is Wednesday. Yes. Um, yeah, I was probably watching soccer last night when that happened, so there you go.

Speaker B: Yeah. Being a real human.

Speaker A: Yes. Yeah. Well, you have small kids, so you're up at weird hours doing weird things.

Speaker B: True. Yeah. The anthropic tweeted Claude. Fable 5 will be available again globally tomorrow. Um, they said after a series of productive conversations with the US Government, we're redeploying the model with a new set of classifiers to target and block more cybersecurity tasks in the near Term some routine tasks like coding and debugging will fall back to Opus 4.8. And we'll continue to refine these classifiers over the coming weeks to reduce false positives and better distinguish genuine misuse from legitimate requests.

Speaker A: Uh, okay, yeah, so basically a compromise, like, we, we watered this down a little bit and made it a little less, you know, responsive to cybersecurity stuff. But if they're moving some of those functionalities to a different model, what does that solve exactly? I don't really understand, like, if we have this car that has like, uh, a feature that makes it dangerous, if we take it out of that and put it in our other car, how is that better for people? I don't really understand, but there's a lot about these things. Like, the way that this is all being governed or not does not make a ton of sense to me, honestly. Everything seems to be, we're going to shove it out into the world, see how people react, and then gradually walk things back and. And then another one will leapfrog that in a few months and then we'll walk that back a little bit and then repeat, repeat, repeat.

Speaker B: Yeah, it's so true. One thing that does stick out to me, though, about this entire, like, saga and anthropic and just AI models and the conversation about, like, dual use and potential abuse by cybercriminals is that it's interesting this is happening right now while, you know, at the very forefront. Like, I feel like for a lot of the different platforms of everything that threat actors abuse, like, it always has started out as like a legitimate platform, and then later on we see the abuse and then those conversations start. So, like, I'm curious if there's going to be any sort of conversation or any sort of, like, difference in, you know, how the platforms are abused, given that these discussions seem, seem to be happening earlier on than what we've seen previously with other types of platforms that are outside of the AI spectrum.

Speaker A: I guess that's a good point. And it goes back to the things like metasploit and Core Impact and those sort of, um, attack frameworks and pen testing tools and things like that that were developed for defenders, for red teams to go and find weaknesses in networks before the attackers could, that sort of thing. And I remember when Metasploit was released, I don't recall what year it was, but I know that not just then, but for years afterwards, H.D. moore, who created that, would constantly take heat from people about releasing these, or releasing new modules for new bugs and I don't remember him ever really being publicly mad about it or like getting in, getting in any like, real arguments about it. Other people were doing that themselves, like kind of like proxy wars, but probably because HD is one of the smartest people on the planet and nobody really wants to argue with him. But, um, the whole dual use thing is, uh, an issue that's gone to the beginning of like, forget kinetic weapons, to the beginning of, you know, computers and software. And it occurred. I had this podcast that we put up this week with Katie Massouris. We talked a lot about this stuff, about the, you know, the Fable 5 thing and the munitions and the export control and the dual use nature of it all. And we talked about, you know, the RSA ciphers that were. There was an watered down export version of RSA that was used in the 90s because the government decided it was a munition and was too dangerous for our, even our allies to use. You know, we couldn't let them safeguard their own data because we needed to be able to break their encryption. Uh, thankfully that eventually went away. But the dual use argument or not argument, but dual use kind of conundrum never has. And it's, it's an interesting problem because as Katie said in that podcast, if you take this away or restrict it, it hurts defenders more than it does attackers. You know, and that's true, I think of most of these things. You know, attackers are going to, they're going to find other means to achieve their objectives most of the time. And if you take away one of their tools, they're just going to be like, okay, I have this other thing, I'll just go do that, or I'll call your help desk and I'll, you know, I'll do some scattered spider stuff and ipso facto, boom, I'm in your network anyway. So it's not, um. Sometimes these things strike me as like big showpieces for the government where they're like, look, we are protecting you. Ta da. But three weeks later we're kind of not.

Speaker B: Right? Yeah, exactly. Yeah, I feel like. And it's even, even beyond like defenders using tools like just threat actors are using completely legitimate, not even for cybersecurity things like Google Drive or like, we've seen all kinds of things where it's just like, it's not even in those cases, like a defender versus an attacker thing. It's like a regular, um, plain old user thing versus an attacker thing. So it just is really, really complicates how those, those types of dual Uses need to be approached. But then, obviously, with AI, you know, while. While we're talking about these things, it's just on a sheer different level and scale. So.

Speaker A: Yeah.

Speaker B: So it'll be interesting to see where that goes moving forward.

Speaker A: It does strike me that Anthropic, specifically, and some of the other, uh, AI labs, I don't know whether it's intentional or not, but they really seem to have a knack for getting under this administration's skin, which. Yeah, I'm okay with that. And, you know, it doesn't seem like that's a conflict that's going to go away anytime soon. Like, you know, a company that is obviously trying to make giant piles of money is not going to be dissuaded by, you know, even one of their things being classified as a munition. Like, they. That got fixed in a matter of weeks. You know, they're. They're not going to really care. You could throw a bunch of hurdles at them. That's fine. We have literal trillions of dollars. Like, we can pay every lobbyist on the planet to just form a circle of hands around the White House until you figure it out.

Speaker B: Yeah. I would love to talk to someone who's, like, more in tune with politics about, like, lobbyists and how that plays into, like, cyber security sometimes, because I'm sure that's.

Speaker A: No, you wouldn't. Um, I don't think you would.

Speaker B: It would probably leave me very, like, depressed. Honestly. Afterwards.

Speaker A: You would hate it. Honestly, it's.

Speaker B: Yeah.

Speaker A: What? Like that whole inside the Beltway lobby thing is, like, we always talk about the spyware game is like, one of the grossest things lobbying is. It's a gross. For a different reason. But I have several good friends who either are or were lobbyists for large portions of their career. And to a person, like, they know exactly what they're doing. This is not a, uh. They're not surprised by what the job is. You know, they don't think that they're doing God's work there. They're just like, this is a really good way to make money.

Speaker B: They just know.

Speaker A: They know. Yeah.

Speaker B: I guess that's the mentality you have to have. Yeah.

Speaker A: Yeah. I mean, I remember this is a long time ago, but in the, like, mid-2000s, when the, um. When Microsoft was in all that antitrust trouble and they wanted to break up Microsoft and all that kind of stuff, I remember the smarter people than me, where I was working at the time, the older folks were just like, this is never going to happen. Do you Know how many lobbyists Microsoft has? Hundreds and hundreds and hundreds. And they contribute money to every politician in Washington. And in one way or another, either directly or indirectly, there's not a chance on earth they're going to split the company in two. And that's not how that works. Uh, it's all, you know, gamesmanship and showboating.

Speaker B: I hate that. I hate it so much.

Speaker A: The American Experiment, Lindsay. It's showboating and just peacockery. Yeah, that's great.

Speaker B: Yeah.

Speaker A: Yes, it's. I sound super cynical. Maybe it's because I was watching this, like, Netflix five part documentary that's literally called the American Experience Experiment. That's really, really good. And you see, you get like all the idealism and everything that started in the 18th century. And then you get to the last episode and you're like, oh, no, it's just a. Not all of it, but it's 4th

Speaker B: of July is coming up.

Speaker A: It is.

Speaker B: Sounds like something that I don't want to watch for the.

Speaker A: No, no, you really. I know, it's really fun, but at the same time, you're just like, man, we were really doing it a few hundred years ago, we really had it figured out and now we don't.

Speaker B: Damn it.

Speaker A: I mean, only took 250 years. I don't. Yeah, um, almost exactly.

Speaker B: Well, I will say this tweet also says that. I mean, again, what did you call it? Like, peacockery or something? Like, comes out and they say anthropic is saying we're scaling up our collaboration with the US Government on model testing and safeguards. So, um, I don't know, there's some show of collaboration there, I suppose.

Speaker A: It's amazing how those things work. It just really is like, oh, gosh. It's one of those things that you just kind of realize everything is a negotiation at some point, and whoever has the leverage usually wins the negotiation or comes out a little bit ahead. Uh, and, you know, compromises are never a 50, 50 proposition. Somebody is always getting a little bit more, you know.

Speaker B: Yeah. Um, so true.

Speaker A: Yeah. So, yeah, I, I do think that stuff's not going away. I mean, anthropic's certainly not going away. AI is not going away. God help us. And the government's not going away. So that conflict is going to be there, I think.

Speaker B: Um, definitely. It'll change. I'm sure it'll evolve.

Speaker A: Yeah, it will. It'll keep evolving. New companies will come up. You know, things will kind of shift form and the issues that are at. In the conflict will change. But the core conflict won't go away. I mean, you know, those kind of things never really do. They just kind of change shape and, um, get bigger or smaller, depending on what the, Whatever else is going on in the world at the time.

Speaker B: Right?

Speaker A: Yeah, yeah. Um, yeah, so I did, uh, I mean, I mentioned the podcast with Katie. I'd encourage everybody to go listen, watch to that one. I think it's. Anytime we get a chance to have Katie on the podcast, it's just a treat. She's so smart and so good at, like, putting things into perspective and getting the big picture, but also drilling down into the very nitty gritty specifics of, like, here's the historical perspective, but also here's what we need to change right now, or here's why this isn't gonna work. Or here, here's why this might work. Um, and it's really good. I mean, it has nothing to do with me. It was just her being herself on the podcast. And at the end of it, she tells a great story about the Sammy worm, the MySpace worm from 2005, which probably, I don't know, maybe half the people listening to this podcast were alive at that time, I don't know. Or were aware of that worm. I don't know. Were you on MySpace in 2005?

Speaker B: Uh,

Speaker A: you were probably too young.

Speaker B: I was just, like, two years too young. I think I went, I got on it when I was, like, like a senior in high school, which would been like, 2008, probably. So, uh, yeah, no experience with the Sammy Worm. I, I, I know of it from, like, yeah, you know, reading. But, yeah, that's, that was a great, that was a great, uh, podcast to listen to. Like, I feel like when we have, like, when, when we talk to people like Katie, like, I actually learn things instead of just, like, you know, someone who's, like, commenting on an existing issue or topic. Like, I fully, like, like, start learning, like, new things that I've never heard about it before. So I think that's, like, my favorite type of, uh, interview.

Speaker A: Oh, me too. Same. And I think, as I told you, I've known Katie for 20 years, and I know Sammy, the guy that wrote that worm. I've known him not quite that long, but a long time. I didn't know that story that she told, which is great. It's just, you know, and it's, I, I love that kind of stuff. Like, I'm a nerd for the kind of history about our industry, too. Um, so that was, it was very cool to hear her Tell that story. And to. If people haven't listened to that podcast yet, go. It's at the very end. Or there's. We. We clipped it for a short on the YouTube channel too. It's, you know, like 90 seconds. It's worth your time. It's very funny. Um, the. The worm could have been stopped before it started if. If somebody listened to Katie, which, you know, that's the lesson. Kids listen to Katie. Honestly.

Speaker B: Another T shirt idea.

Speaker A: Yes. Well, that's the funny thing we did. You'll still see them. I don't know if one or both of us will be a black hat this year, but you will still see people wearing T shirts that say, Sammy is my hero. That. I don't even remember who made those, but they came out like after that. Like, not immediately. Not in like 2005. It was a little bit after that and I can't remember. I've never had one. I would kill to have one. Um, um. It would be really funny.

Speaker B: Yeah.

Speaker A: But actually they're probably around. I could probably find one somewhere. I'm not paying like 90 bucks for it on ebay, but I'm sure Naren has one somewhere and he, like in his little museum in his house or whatever.

Speaker B: But that's awesome.

Speaker A: I don't know. We'll see. Actually, I should text Sammy, see if he'd send me one. Um, if. Yeah. Not to go off on too many tangents, but if people are not familiar with like, Sammy Kamkar's work, the Sammy worm is like a footnote in what that guy has done. Go and look, uh, him up. S A M Y K A M M K A R Google his name and just go look at all the cool shit that he's done in the last, you know, 21 years since then. The projects this guy has come up with and, um, and done, most of them are not most, but a bunch of them are sort of hardware based things that he's done. Like when drones first became pop, he immediately just decided, like, I'm gonna figure out how to hack drones. He did it in like a weekend. He's like, oh, yeah, this is easy for me. He was out there, like hacking garage door openers, like, things like that. Just cool side projects. But also does like insanely cool hardware and software stuff too. I don't even know what his actual job is these days. I have no idea. But he's just always, um. Every once in a while he'll just pop up on Twitter or somewhere else and be like, hey, look at this thing. I did. And you're just like, what? He's kind of like Joe Grant or Joe Fitzpatrick in that way, where you're just like, how does your mind work? I don't get it. I know that my mind is not like those guys, but they just see things in a different way and forget about understanding how software and computers work. They just see systems in the world in a different way as, you know, just a series of puzzles or challenges.

Speaker B: Mhm.

Speaker A: Which is cool. I think it's just a very cool mindset to have.

Speaker B: Yeah. Uh, what strikes me about him is like, it's. I feel like a lot of people in this space have like one specific thing where they, you know, are where they're experts at. And that might be like, you know, like macOS or like looking at hardware specifically or something or the other. But like, yeah, he does it. He's done it all. Like he's done like car related research. Like, um, you know, like, I don't know, what was the like magnetic straight like thing that you created, like mag spoof or something like that all about that?

Speaker A: Yeah, he did. Yep. When that was a big problem, it was like an issue with subway cars. Like there was some guys here in Boston who you probably remember that got in trouble for figuring out how to spoof, um, the mag stripe cards for the tee here in Boston, like years ago. Um, yeah. I don't remember exactly what Sammy's version of that was, but he did that as well. Yeah, it's just like.

Speaker B: But it's all just thing. Yeah.

Speaker A: Oh yeah. And it's.

Speaker B: Yeah, yeah.

Speaker A: As you said, he's not a, like, it sounds like we're damning him with faint praise of like he, he's good at everything but that. It's like that's real praise. Like he's not a jack of all trades and a master of none. He's one of, you know, just one of those people where you're just like, I don't know, good at everything. It's like when you meet somebody that's like really good looking but is also like an elite athlete or something like that, and you're like, what the hell? Are you serious?

Speaker B: Not fair.

Speaker A: No, exactly. Or they're just like the nicest person you've ever met. You're like, that's not cool. Like I need you to be a jerk. Like if you're going to be that good looking, you need to. Yeah. You need to be rude. Or it just have some kind of personality disorder. I don't know. It's not there. Uh, yeah, but. All right, so that was our, our um, fan club for Sammy and Katie, which is, you know, fair. Um, to get to a couple of stories. I wrote a story that um, went up on the site this morning about this control panel. I guess that's the way, or operator panel, same thing called AR Token, that is related to the Evil Tokens framework, which is one of those, It's a phishing as a service kind of framework that attackers, um, use to sort of automate a bunch of the labor intensive and more difficult tasks associated with phishing and getting past, especially the process of getting past mfa. Um, there's a bunch of different ways that attackers do that, and most of them have nothing to do with actual weaknesses or bugs in the MFA systems. You know, usually it's some combo of social engineering or you know, like a push exhaustion thing where they'll just keep sending you push notifications to your device until you approve one of them, which is the sort of lowest tech version of it. But this Evil Tokens framework has other ways to sort of steal MFA tokens and get past MFA barriers, which is usually one of the major hurdles for um, for cybercrime groups when they're trying to do something like bec or get in, you know, something like that, that's going to actually get them to where the money is or where the credentials are and then get to the money. And you know, MFA really presents a pretty hard barrier for a lot of those groups. And Evil Tokens is one of those frameworks that lets them get around that. So the researchers at Cisco Talos discovered this operator panel called AR Token that had not been publicized before, had not been disclosed. That's sort of uh, the backend control system for part of the Evil Tokens framework. And it's really cool. These are former colleagues, all really smart people that did like this deep analysis of the panel. Um, I point to it in our story. It's one of those things where even if you understand how the cybercrime ecosystem works in general terms, where there's a division of labor and there's people creating the tools and there's the people running those tools, there's the sort of initial access brokers, there's this whole ecosphere of people doing different jobs. It's an economy in the same way the legitimate economy is. Even if you sort of have a grasp on all that sometimes, or at least I do, you kind of forget that there's like, there's stuff that's under the surface. You don't really know about that these people are using. And when it, when it's sort of disclosed or pushed out into the light, you're like damn, that's clever. You know, like there's smart people on the other side of this ball too. Mhm.

Speaker B: Yeah, I agree. I think like we did a fair amount of research into the, into evil tokens at um, my day job at Huntress because we saw like a lot of the device code phishing attacks that came out of, you know, that whole platform. Um, and one thing that I read about was that um, and that we saw was that evil tokens was using essentially um, threat actors could use AI so that um, at the back end of, once they were compromising like emails and things like that they would use AI to essentially just like shuffle through all the emails that they compromised and look for opportunities for uh, bec. So they look for like threads where users were maybe like talking to someone in finance and things like that. And if you think of like if you compromise an email and you go through all the different uh, emails that might be in an account, like that's a lot of work to potentially do. So like even just using that one little feature, they're just like saving so much time from that. Um, so like to your point, it's just they're thinking of things that are you know, really kind of raising the, raising the bar when they're launching these types of attacks which are, you know, the attacks themselves have been around forever. Like we've, we already know about device code phishing, like adversary in the middle. Like all the things that you know, we're seeing with phishing as a service. But um, it's really just the commoditization and like as you mentioned like kind of at the background how attacker, how attackers are um, like using this as a broader marketplace and landscape.

Speaker A: Yeah, it's, I remember uh, like when we were a duo. But these you know, MFA bypass attacks were very well understood. The, the researchers there and the engineers and the smart people like understood exactly how these work and there's, you know, there's technical barriers that you can put in place. But then if somebody's just going to approve a uh, push notification, there's not really a great technical defense against that. That's where you just have to be aware of these things. And if you're getting 12 pushes in a row from the same thing that you're not sure that you we're trying to approve, don't push the green button. But you know, again like thanks for nothing AI. I Don't need you automating, uh, email sifting for bad people. Uh, I mean obviously there's nothing we can do about that. But yeah, that's a clever use of the tools that are available to them to go through these things and find the valuable data and automate uh, a, uh, labor intensive process so that they can get to the money faster, which is what the whole game is for them.

Speaker B: Yeah. And the other thing that sticks out to me about just this topic in general and like mfa, um, like bypass I guess if you call it that. But like is just, it's, it's so dangerous as a writer to think about how to write about it because you really don't. Like, MFA is so critical and like a lot of people have no mfa, so that's the worst. But then this, you know, threat actors are also targeting MFA protections that have been set up. And I think it's just like when, when I write about these types of things personally, like I try really hard to make sure that people know that like we need like MFA is like critical. Like just because uh, threat actors are, by trying to bypass it or taking those measures doesn't mean that it's like failing and we should move on to like, we shouldn't even start to implement it, I guess.

Speaker A: Uh, no, I, I know it's, there's all kinds of stupid analogies you can make to, you know, real world protection mechanisms like seat belts and things like that that are inconvenient or annoying or whatever. But it's so critical, critical these days that if, if MFA didn't exist, do you know how much worse we'd be? Like it would just be shooting. Uh, uh, it would be so simple for cybercriminals. It's crazy in, you know, 15 years ago, before MFA M was really a thing. That was before a lot of these automated tools were available to the cyber criminals. So you know, both things have kind of advanced uh, at the same pace, which is, you know, kind of how it goes. But yeah, it's, I completely agree with you. It's, it's funny, I don't think you ever saw these, but um, when we were at Duo, Duo probably still does, has like a huge customer base in the higher education world, like in universities and things like that. And you know, it came out of the University of Michigan and we would always get, especially at the beginning of the school year when new students got to campus and realized that they had to set up Duo to get to their, you know, online accounts. There would just be these Floods of tweets and Facebook posts and Instagram posts from, you know, 18 year old college freshmen that were just super pissed. They're just like. There was an entire Slack channel dedicated to these and they were the funniest thing I've ever read in my life. We made T shirts out of them, none of which ever saw the light of day, but they, like, they exist. There are some like, world famous ones that were just like, I don't care. Steal all my shit. I'm not pushing the green, I don't care. Just all that kind of stuff. They were hilarious. Like, I have an archive of them somewhere. Like before, I can't even remember, we were going to do something with them. Um, for decipher. I think we're going to do like dramatic readings of them or something.

Speaker B: I. Yeah, because I came in. That was right when I came in. And so I got. I got to see that channel. Thank God, because it was amazing. But I think they wanted to like. Have you ever seen the YouTube videos where, like, celebrities hate tweets about. About themselves?

Speaker A: Exactly. Yes.

Speaker B: Yeah. Something of that style. Yeah.

Speaker A: I think that's what we were gonna do. We were gonna have like Ben Armes, one of our video producers or somebody that has like some sort of comedy chops, like, read like, do dramatic readings of them. Yeah, it would have been so good that it would have done numbers. Like, it would have been really funny. It's just because some of those like it. I'm going to have to go into the. I'm going to have to text some people and be like, does anyone have a copy of these? Yeah, I'm sure it still exists somewhere because I know that those Slack channels were archived, uh, somewhere. And I, I think I have a feeling I know where they are. It would still be super funny to read some of those. They're just incredible. People get so mad about pushing a button on their phone, just like, oh, my gosh.

Speaker B: And it's so funny because it's like, you know, a lot of the times it's literally like you're trying to log in somewhere and then your. Your phone's like across the room on your bed.

Speaker A: Huh.

Speaker B: And you're like, damn it. Like, I need to get up and walk across the room and get my phone.

Speaker A: Yeah. Even when I worked there, I was like, oh, really? Like, I have to. Okay. God, yeah, it's. But it's just like the human nature of like, oh, I have to do another thing to get to the thing that I want. Like, yeah, yeah, sorry. Like we're trying to help you. But it. It was just. It was the funniest thing I remember. There was at least one intern I can recall from Michigan who came in and was like, oh, yeah, I wrote one of those tweets. Like, I was one of those people

Speaker B: that was like, yeah, duo hater.

Speaker A: Just like, I didn't know what it was. I didn't care. I just wanted to get my assignments in my email, you know?

Speaker B: Yeah.

Speaker A: Those are so great. Yeah.

Speaker B: I guess if. If users are feeling that way, to our point about dual use, like, imagine how it makes hackers feel.

Speaker A: Exactly. Yeah, exactly. It's very. Yeah, that. There you go. That's a professional way to wrap it up right there. Lindsay. Nice job. You're welcome. Yeah, yeah, Good job. Nice. Nice way to bring it back. Um, we did have some. We. We always like to drop some good news when we can. And you found some just, uh, before we started recording. Um, we. We love to joke about people going on vacation in the wrong countries, uh, in. On this podcast. And it's funny because people do it. Like it and continue to do it, apparently.

Speaker B: Yeah, I know. Like, how does a nice trip to Finland or Montenegro, uh, sound to you?

Speaker A: Montenegro. That was the funny one. I saw that. Yeah. This morning. Very funny. Yeah. I couldn't pinpoint it. Don't know where. I have a general idea where it

Speaker B: is, but very random. Yeah, that was. There was a couple of, uh. Couple of law enforcement announcements, uh, regarding some threat actors who decided, I guess, to vacation in the wrong country. So. And one of those was, uh, Scattered Spider. A Scattered Spider member who. I'm looking, trying to find his name. Allegedly. Yes, allegedly.

Speaker A: Was it Peter Stokes?

Speaker B: Is that Stokes? Yeah, I guess the, um, DOJ just came out on Wednesday and said that, uh, this Peter Stokes, who's 19, dual citizen of the U.S. and Estonia, was, uh, arrested in Finland and then extradited to the US which is interesting.

Speaker A: I. You know, if you're. I don't know what our extradition treaties are with Estonia. They're probably not as favorable as they would be with, say, Finland. So. Uh, yeah, I don't know. Like, if you're. If you're an alleged bad guy, I. I mean, I don't know, why are you going to places where. Where the FBI can reach you? I. I appreciate it, but.

Speaker B: Good question. Yeah.

Speaker A: Yeah.

Speaker B: And then this other one was that I saw also, uh. Well, this one actually was from a couple days ago, I think from even over the weekend, but I guess in Iranian nationals suspected of, um, hacking Attacks that damaged the US infrastructure. Was arrested in Montenegro. So that was a 39 year old man with dual Iranian and Turkish citizenship.

Speaker A: Again. Okay. Yeah. I don't understand.

Speaker B: I mean, it must be something, right, like to do with the fact that, you know, allegedly these people are doing highly illegal activities. Like.

Speaker A: Yeah, I mean, I'm gonna just go with the most basic human motivations. It's usually I'm gonna say it has something to do with money or possibly a, uh, love interest or something like that. A reason that they have to get on a plane or a boat and go to a different country. You know, I've seen a lot of, uh, movies. Those are, those are my two main guesses. Yeah.

Speaker B: Yeah. Well, this guy was, I guess for, from 2013, which is a long time ago, uh, was like carrying out hacks that targeted more than 150 universities in the U.S. oh. Yeah. So, and I guess looking at specifically targeting data and compromising university accounts, that it sounded like we're used for research or like, you know, espionage. Targeting, targeting research. Which is interesting coming from, uh, the, um, irgc.

Speaker A: So, um, sure. Is that, that makes a lot of sense actually. Um, hopefully Duo got in his way

Speaker B: at some point back then. Yeah. But anyways, some, some good news. Some. Yeah, I was saying before we started, we need to make this a segment like Hackers who Got Caught on Vacation or something.

Speaker A: Yes, it does. We can definitely make that a regular segment and I'm going to try and see if I can dig up those mean tweets. They're just so funny.

Speaker B: Please.

Speaker A: Uh, do.

Speaker B: Yeah.

Speaker A: Even if we could just get a handful of them and have, have somebody come on and do. We could have Donahue do it. That would be really funny.

Speaker B: Yeah.

Speaker A: Do some dramatic readings of these things. They're just so great because they're just the angriest. Like all caps, so many exclamation points. People just getting mad at the wrong things.

Speaker B: Yeah.

Speaker A: Delightful.

Speaker B: That's great.

Speaker A: All right, well, have a great long weekend. Enjoy the fourth of July. Stay inside, I guess, and uh, everybody stay safe. Enjoy your cookouts if you can. And we'll talk to you next week.

Speaker B: Awesome. Thank you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Weaponized Supply Chains: U.S.-China Trade and National SecurityMIT Supply Chain Frontiers · on Export controls88 / 100
  • Arctic Edge Panel: Defence Tech, Dual-Use, and the Future of Canadian InnovationTank Talks By Ripple Ventures · on Dual-use technology86 / 100
  • Decoding the Cybercriminal Mindset, with Ryan ChapmanThe Cyber Insider · on MFA bypass techniques85 / 100
  • Beyond SpaceX: War, AI, Orbital Infrastructure and green utopia | Mark Boggett | Seraphim SpaceFund Shack Private Equity Podcast · on Dual-use technology82 / 100
  • Jake Brukhman (CoinFund) on Anthropic Fable 5, Agents & Asymmetry in AI the un# podcast · on Claude/Fable 579 / 100
  • AI-Powered Forensics: How Attackers Automate BreachesCloud Security Podcast · on Metasploit78 / 100

More from Decipher Security Podcast

All episodes →
  • The (Bug) Disclosure Day Conundrum and How AI is Changing the Game with Katie Moussouris
  • The Gaslight macOS Backdoor, Cisco Zero Day Exploit, and Operation Endgame
  • How Much Do Data Breaches Really Cost? | Alex Pinto
  • The Shrinking Exploit Window, Patch Schedule Changes, and the Vulnpocalypse
  • How The Conversation Predicted Our Surveillance Society 50 Years Ago
Explore the best B2B AI & Data podcasts →
All Decipher Security Podcast episodes →