The OpenSourceMalware Show
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
The OpenSourceMalware Show
Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This week we talked about:
- Hacker Summer Camp trends. Jenn and Paul share observations from Black Hat, DEF CON, and BSides Las Vegas last week, including a maturing AI security conversation that has shifted to focus on where AI still falls short, particularly the last mile of precision and finesse that still requires a human to verify. They also discuss the emerging challenge of identifying malicious AI skills, where the natural language format makes static analysis much harder than it is for traditional package ecosystems. And they revisit the recurring gap between security teams who understand binary malware and incident response and those who understand the open source software supply chain.
- GitHub revokes npm bypass-2FA token privileges. GitHub announced it is closing a gap that let npm granular access tokens configured to bypass two factor authentication perform sensitive account, org, and package management actions, a change Jenn and Paul say is overdue but underexplained.
- DPRK's NullReceiver technique keeps spreading. Following up on last week's episode, Paul shares that the number of packages using the NullReceiver technique, tied to the PolinRider campaign, has grown well past the seven originally confirmed, and that DPRK's use of crypto payments for infrastructure like VPN services could offer new tracking opportunities for defenders.
Episode resources:
Oh. All right. We are live. It is Thursday, August 13th. We are back from Las Vegas in our respective uh, I guess I wasn't gonna say time zones or hemispheres because it's still the same hemisphere and time zone for me, but you know, you're back in yours.
Paul McCartyI'm I'm upside down again. I'm in the upside down. Um good job. And uh but by the way, that transition to live. That happened fast. I was like sitting here typing, I was like, You were like we're live. I'm like, whoa, hey, good day, everybody, good morning. As a case may be. I'm not quite caffeinated yet, but I'll get there.
Jenn GileI think I need a little extra. Um, okay, so we're gonna talk about some takeaways from last week in Las Vegas. We're going to talk about some new activity that you're observing with um North Korea in particular, like kind of a follow-on to the null receiver stuff we were talking about last week. And hot off the press, we're gonna talk about GitHub um revoking NPM bypass 2FA granular access tokens. So let's start with Hacker Summer Camp. Um takeaway number one. Well, first off, let's rewind. Um, maybe not everybody listening knows what Hacker Summer Camp is, but it's the nickname for uh a week in Las Vegas in the middle of the summer, hence summer camp, where a lot of the cybersecurity industry goes for conferences. And it used to be, I think, just three conferences, and now like there's no way you could go to all of them. Um, there's B Sides Las Vegas and Black Hat and DEF CON, those are the three big ones. There was an imprompted thing, there was an AI summit, there was the list goes on. There was a ton of stuff. We went to B Sides, Black Hat, and DEF CON. They all have different flavors. Um, you know, you see different things, you talk to different people. I think that's part of what makes the week a little bit interesting for us is it's it's an opportunity to see a lot of what's going on. Um let's start with AI first. So here's my observation. Uh, and I kind of think of things sometimes in terms of conferences because you like when you go to a conference, you start to hear like what a lot of people are thinking at once. So, like last year, 2025 at RSA, the AI industry for security was very new, and a lot of the um narrative was about uh this is gonna be terrible. Basically, like we're all like headed toward uh Doom. We don't know what's gonna happen, but engineering is going bananas, and we have no idea. Like that's how I would describe the very like early conferences when AI, you know, driven stuff first started coming out. And then starting like last fall when I was at LASCON, and then into the spring, what I started seeing more of was how security teams can operationalize AI to you know do their jobs more efficiently, to keep up. Like it was a lot more practical. Um, you know, we're starting to see another uh evolution, you know, in terms of it being practical, but also finding the edges. So, you know, Paul, you mentioned as we were prepping an observation that um the last mile is the issue at this point. Uh so say more about what you feel like is missing, because obviously it's not perfect.
Paul McCartyYeah, I mean, I think that the you know, I was we were getting this vibe even before Hacker Summer Camp, but then just talking to everybody at Hacker Summer Camp, we're gonna just we're we're all using AI, we're all using it in lots of different ways. And by the way, anthropic, if you're listening, you're letting us all down. So basically, everybody in cyber right now is moving off of your tools. Uh and Jen, I saw your post actually. You saw my post. I saw your post. Codex, um, 5.6 Saul. Like, listen, I am no friend of the open AI team and Sam Altman. I think they're part of the the pending apocalypse. But that said, um, Saul 5.6 like is crushing it. It's fast, it's good. Um, so a lot of us are moving, and this is anthropic is just like just it's the worst own goal ever. So, anyhow, sorry to side there.
Jenn GileYeah, you know, it's frustrating uh while we're in that tangent. You know, I moved to Claude, uh, whatever it was when everybody else did, because I was frustrated with what was there, because what was there, you know, with Gemini was going downhill, and Claude was really great for a while. And the post that Paul's referencing is me hitting a security roadblock with Claude this morning when I tried to get it to read one of my blogs, and it was like, oh, you're doing something scary. And all I had to do was change my post. This is the second time this week, where I changed my not my post, my um my prompt to be like, this isn't dangerous and there's no malware in here, and then give it the exact same thing. And it's like really that works, yeah. That's all that works. Um interesting. I mean, granted, there was nothing scary, and there was no malware, so it shouldn't have flagged it in the first place. But the fact that that's the only thing I have to do to get around their uh security block. I have questions.
Paul McCartyYeah, for me, when because when when I'm actually analyzing bad stuff, what happens is I get 70% in, 60% in, and then anthropic loses its chisel, right? And the problem there is that I'm not done. And then I have to do a model switch, which is relatively easy now inside of Claude. You basically just change model, you drop down to Opus 4.6 or 4.7, which tend to be the go-tos, right? Sonnet 5 is pretty good, but I'm I'm starting to get blocks in Sonnet 5 too as well. But Opus 4.6 and 4.7 still are the go-to's. But the point is that you're you're like you're in, and like if you can't get past that block, you now have done all this work and you spend a bunch of tokens and you haven't gotten the the the payoff. Um, and that's very frustrating. So that's where I'm moving to um codex, and eventually when I get time, you know, doing some of our own model stuff. But anyhow, um all of that aside, everybody's using AI, and I think uh all of us are realizing yes, it's two things at the same time. There's the quantum state of AI epiphany, which is it's amazing, it's changing my job, it's it's you know, it's life-changing like the internet was and you know, all these other big technologies. But that last mile, you have to carry that last mile. And if you don't, if you don't, it's so freaking obvious that what you've delivered is shipped directly out of the agent because it reads a certain way and it lacks finesse, and most importantly, it lacks precision. You and I have seen that ourselves when we give these big data sets to Claude, you know, and create these big technical uh you know posts, and we have to go through it. It just doesn't get a lot of that right. And so you have to have a human that go through each one of those things and make sure that everything it's saying is actually precise. And this lack of precision, I know I'm going on here, but that's where I think everybody in our industry is kind of seeing this same kind of problem is that it does it lacks that precision and it makes it assumes things that it shouldn't.
Jenn GileSo yeah, I will say um I was, I think, um pleasantly surprised, and maybe this is not a great thing that the industry agrees with us right now, but pleasantly surprised that a lot of people in the industry kind of agreed that they're seeing a lot of issues with false positive if they just throw AI at malware analysis. And, you know, I actually talked to somebody I know who works at OpenAI, I won't say who it is. Um, I don't want to get them in trouble, but they did mention that they um they actually tell people users not to use it for the security purposes. So it's, I mean, these are just not designed for vulnerability remediation, they're not designed for malware analysis. It just uh goes to show that that additional expertise that you bring when you set up the model and you give it the context and you apply, you know, the static engineering, uh static analysis between the LLM stages is necessary and probably not going away anytime soon.
Paul McCartyYeah, I mean, we have a bunch of our own techniques here at OSM that I won't go into detail because I don't want to give away the special sauce, but the reality is that um I think a lot of people right now are trying to be cheap on tokens because tokens have gotten really expensive really quickly and they're still not we're still not paying for the tokens, right? So we're still like, you know, it's gonna get worse before it gets better. And so because people are dropping down to some of these cheaper, faster models, what's happening is they're getting cheaper, faster outcomes out of findings out of what they're shipping, right? And I'm seeing that myself when I look at some of the cheaper open AI models, Mini and Terra, for example. Um, you you see discrepancies, right? And so people are trying to save money because they're doing a lot of analyses and they're dropping down, and they're not using these other things that are wrapping kind of precision around it, like the static analysis, some of the other things that we do. So you're right, man. False positives from from malicious package detection is going up. Um, not for us, but which is good, it's going up.
Jenn GileUm, so a natural segue from there is to talk about another theme that we saw uh in particular toward the end of the week last week was people uh talking about malicious AI skills and developing tools uh with the intent of being able to tell if a skill is malicious. And um, so myself included, I had a talk at DEF CON. Um, I talked to a couple other people who gave talks on it. And um, you know, the general consensus right now is it is hard to determine if a skill is malicious, and it's also hard to tell if sketchy-looking behavior is in fact malicious or benign, meaning lots of skills do things and have no malicious intent behind them. They're the official skills from like big companies, and on paper they just look bad. So that's a challenging space right now. But um, found out about three separate uh early tools that are designed to like, you know, stick the GitHub repo or the file or whatever in the browser, and then it'll, you know, in some way analyze them. Um I think there's a lot of work to be done in this space. There's a lot of uh unknowns. I don't know that we're gonna see anything super mature right now, but it may be very much like things were a year ago, where there's a lot of experimentation, and then in three months or six months, the products that come out to deal with this may look very different.
Paul McCartyYeah, I mean, the you know I've talked about this before and on the podcast, but you know, the natural language barrier here, and not barrier, but the natural language, you know, environment that skills exist in are just really hard to find malicious stuff in. So I think that you have to, and I've I've tried taking our own internal analysis engine and kind of tweaking it for skills, and it works to some extent, but it needs a proper, like built-for-purpose thing. Because the the problem is that the you know the rigor around these skills in terms of like a specific release with you know a hash and and a way to tell that that was uh the provenance from that person's machine pushed that uh you know uh thing, that skill. None of that exists. It's all just a wild west. We've gone backwards, like all the things that we learned that we need to do in NPM PiPi, we're doing none of that over in AI skills land, right? And so because we're lacking that rigor, you know, we just have to fall back on more AI because static analysis doesn't work because it's natural, well, it doesn't work as well because it's natural language. It's just it's a very complicated space. Um, and I and you know, you and I were talking about this before we were rolling that you know, a lot of these best and breed kind of point solutions in these individual places are gonna be the way to go until somebody kind of starts to wrap these together in bigger platforms. I don't know if that's necessarily gonna be the ultimate play here because this just moves so quickly. I think these point solutions are gonna be the better way to go, which means you just have to like manage a quiver of these things.
Jenn GileBut well, and as we talk about the way things have changed over the last, let's say, 12 to 18 months, you know, when MCP servers came out, there was a lot of like, oh my gosh, these are super vulnerable. We saw lots of conference talks about all the ways that you could, you know, exploit somebody through an MCP server. And I don't feel like I see the same level of where of awareness with skills. Um I I yeah, I don't know why. It's interesting.
Paul McCartyI I think the other problem is that just skills can be imported from multiple places on your disk, like there's not one, like you it can be in the local directory, like you know, Claude and Codex look in three or four different places alone for you know in in succeeding order. There's like a there's a hierarchy of where it looks for these. And so it's just really easy for malicious stuff to drop bad skills into places and get it to be executed as basically like dependency confusions instead of calling Jen's version of you know the OSM modify uh you know skill, you're gonna run the bad guys because they dropped it in somewhere that gets checked before yours does. So just everywhere you look, there's all these complexities, right? It's just a very hard space to we just kind of have to come to the realization as a culture, and I don't know if we're gonna be able to, that things like skills, we just need to be a lot slower about adoption of these things, and we're not like we're we're rushing ever faster at using these things, which is a problem.
Jenn GileI think that's true. Okay. Last uh topic that we wanted to hit on specific to Hacker Summer Camp, and then we'll dive into some of the news and research, is around, I guess I would just say this is a continuation of what we've been observing of the kind of divide that's present between the people who understand malware, who are typically in more of a SecOps, InfoSec, IR side of a company, um, versus the people who understand the software supply chain who are you know more in the development and app sec side of the company. And um because of the silos that tend to happen with those teams, like there really is. I'm I don't know, anyway, for anybody who's listening, I'm physically like pulling them apart because that's really what it what it's like. But yeah, we're I think I would say we're continuing to see, you know, people in application security certainly they understand malware is bad. Don't, don't, don't do the malware, um, but don't necessarily understand um indicators of compromise or typosquats or you know, I could the list goes on. And then the people on the more Secops side uh are more used to the binary malware that you know gets detonated and and is handled, you know, hashes. You know, we had the conversations with people about virus total. Um, yeah, so there's there's still very much like a knowledge divide there, I think.
Paul McCartyI actually talked to the team or some of the team that was at DEF CON, they actually were at DEF CON in the malware village, the company which is called X-rays, I think, that makes Ida. And I was like, I didn't even know the name of your company. He's like, Yeah, we hear that a lot. But just when you talk about malware, they're just like, What's your what's your binary analysis, you know, kind of toolkit? And I'm like, I rarely use it, like I rarely open up binary ninja or some of these other tools. Um, I have more lately. Uh, something I forgot to mention to you is I'm actually seeing an increase in binary-based you know, software supply chain malware. I think because of just the um, you know, people are vibe coding up stuff, and so a lot of it is Go-based. Um, uh, like I was looking at this crazy Windows. I haven't even talked to Jen about this yet. This crazy Windows thing that pretends to be this agent called Kelki. And this guy, this bad guy, just built all these things. His OPSEC is crap. So, mate, I think you're gonna you're gonna be in for a bad time. But anyhow, I'm I am seeing an increase in that, but overall, you know, that's still a vanishing, vanishing small mouth. I do have one other thing to say about Hacker Summer Camp, which is not on the list. I want to call out my man. I'm wearing a shirt right now, the sick DEF CON 34. Um, this is the off by one um uh DEF CON official.
Jenn GileAh, this is from the the One Password crew. That's a nice shirt. Uh uh no no, it's off by no, uh uh no.
Paul McCartyThis is the off by one guy. I don't even know his name. Like, I introduced myself and he didn't say his name, didn't want to take a picture, which is fine. Like, that's kind of his thing. But he has this amazing website. He does those metal shirts, like basically he takes like malware concepts and makes it all metal and then sells them. I have a couple of them and I love them. My kids love them too, as well. But um, this is how I introduced the idea of death metal. How do you introduce the idea of death metal to your kids? Like, that's like interesting conversation. Anyhow, big shout out to him. Thanks, man. I really appreciate it. It's very sick. I'm gonna wear it all day, and and uh it's going into my high rotation um uh cover of shirts. All right, that's it.
Jenn GileAll right, that's it, we promise. Um, so right before we started, you sent me an ex post that I think yeah had just gone up this morning from NPM. So let's start there with NPM's announcement. I'm pulling up the blog now and I'll drop it in our uh comments so people can take a look at it. But essentially, they announced um that they're revoking these tokens that can be used to bypass 2FA. I mean, there's very obvious reasons why they would have decided to do this. I don't think they actually, oh no, they did explain why. Um so the reasoning they gave is you know, if you've got a 2FA bypass token and you're an attacker, well, gosh, that's a real easy way to take over someone's account. Um, and there's not really a need for 2FA bypass tokens. So yeah, I think this is a good thing. What do you think, Paul?
Paul McCartyYeah, I think it's a great thing. It's actually, you know, and when I read this, I was like, oh, I I'd forgotten that this gap exists. Um, and I'm very aware of this gap. I just forgot it exists. But yeah, this is I'm glad they've closed this gap. Um, it seems like it's obvious. Um, and we're celebrating it now in August of 2026. But I mean, come on, guys, this is probably something you could have done ages ago. But anyhow, that aside, not trying to be the jerk. Um it's a great thing. I also want to point out though, like all the other recent NPM, this thing is 81 words. It's like it is super short. I just made that number up, by the way. I don't know. It's a it's a very small number of it.
Jenn GileIt's probably more than 81, but it's not a lot of words.
Paul McCartyBut the point is that it just lacks a lot of the technical details. Um, you know, you can you can get to it if you understand the the the background like Jen and I do, but I just come on, NPM, can you just put a little bit more effort into explaining because I think they don't for some reason I I feel like they don't want to go into too much detail about the problem. They just want to say, hey, we we're fixing it, you know, call it good, and we're okay. There's no problem to see here. Um so I don't know, maybe I'm speculating, but I just can you guys put a little bit more effort into these things? Like and Jesus, can you please offer a light mode for these things? See, they're so damn dark. My old ass eyes are can't read these things.
Jenn GileYou crack me up. Um, well, yeah, net, it's a good change. Wish there was more detail, but in this case, uh, I would say I have fewer questions about this change than we have on previous ones. It's pretty straightforward. Okay, I don't know if you noticed. Yeah, yeah, yeah. Uh, we have a comment uh that I'm gonna go ahead and pop up on the screen right now. So uh somebody on our LinkedIn stream asks, uh MCP slash CLI abstract risks. Can you explain and elaborate, please? Many thanks. You want to tackle that, Paul?
Paul McCartyUm MCP CLI abstract.
Jenn GileI don't know if this is coming out of the I'm not sure exactly what we were talking about earlier where CLI would have come in, but um I don't know if this was driven by the conversation we had at the panel.
Paul McCartyI did a panel at Cloud Village um on what was that Friday at DEF CON. And I don't know if this is coming out of that, but one of the things we talked about in that panel was I was talked about my personal experience around some of the CLI tools and how they interact with MCP, um, and you know, just the kind of types. I guess I was talking on a high level about the types of problems they're in. And one of the things I talked about is like there's this intrinsic, it's kind of this like it's like what Thomas Roscia was talking about, you know, the the AI security and the security of AI. I I was focusing in in the cloud village less on the intrinsic kind of problems inside of MCP, right? Which are numerous, um, and more about like the supply chain, because that wasn't that was the intent of the the the talk at Cloud.
Jenn GileSo I'm gonna take a uh stab and say this person is not asking about that. I just took a look at their profile. They don't look to work in uh cyber, and I don't think they were attending the conference. So uh maybe just like a real basic primer might be useful of um yeah, well, I'm I wouldn't call myself an MCP expert.
Paul McCartyI think I think there's a couple issues with MCP. One is that many people rushed them into production very quickly, and then they've sat mostly unmaintained since then. So that's the first problem, right?
Jenn GileDon't I I guess I would say many of them were vibe coded to begin with. And I know this because I know a lot of the people who developed Belma.
Paul McCartyThe one main one that I had to deal with, and I won't say how, was absolutely vibe coded in a short period of time, and it was absolutely it was horrendous.
Jenn GileBut I So a lot of these have a lot of the common security challenges that we see with software applications. So it's not necessarily that new categories of risk have been invented. It's that they all got crammed into one little piece of code that were, you know, one little component asset. And so they can open you up to several different kinds of risk that, you know, previously wouldn't necessarily have all come from one place. When it comes to malware, we don't see a ton of malware related to MCP servers. What I would say the extent that I've seen tends to be more like uh something pretending to be an MCP server, but really it's kind of you know baiting you to download it so that you download malware. But I would say typically with MCP servers, assuming it functions and does the thing that it says it does, probably it's software vulnerability risk, is the majority of what you're getting there, as opposed to malware. That's just what I've seen. Paul, I don't know if you I agree with a lot of that.
Paul McCartyWhat I have seen too is well, like that, for example, the Service Now, I think it was the Service Now MCP server, the official one. Somebody copied it and it and it worked. It still did its job. It's it did what it said on the tin, but then they also added um, you know, X for basically. So I think the issue with MCP is that I'm gonna use old timing language to describe something new because the problem with MCP is that like an MCP server is typically just an NPM package or a Python, you know, it's just source code that you install that does something and it acts as middleware. So this is the old timing language I want to use. It's like it's middleware, it sits between authentication and specific tool choices and a LLM, a non-deterministic by design LLM. And therein lies the challenge is that uh MCP servers often have problems with role-based access and being able to you know differentiate and use granular kind of access controls. They have problems with non-deterministically you know choosing tools, right? That are you can that's what you've designed them to do. So, I mean, it's just a it's just a huge problem space. And uh Jen's right, a lot of it comes down to the fact that there's a lot of vulnerability risk there rather than malicious intent risk. But absolutely, if you go to NPM right now, I would just I would pause it if it's less than a month old, anything that has MCP in the name, there's probably a 61% chance it's malicious, straight up, right? I'm just gonna say so.
Jenn GileI know that's uh uh pulling it out of the air, but I would say probably true. Um okay, so moving on. Yeah, uh, you've got a couple of notes here for us to cover on North Korea, stepping up some attacks on the software space. Uh so last week, yeah, last week we talked about null receiver on the podcast, which is a new way that North Korean threat actors are um hiding their traffic. The way that I kind of explain this is just like a software application needs infrastructure to deliver the software application, you know, to get traffic in and out and to serve whatever images and stuff, you know, malware needs infrastructure also. Um, but the threat actor wants to hide the infrastructure so that you don't know where that traffic is going. You don't know that it's going somewhere nefarious. And so this null receiver um technique is quickly becoming a go-to way for uh North Korean uh malware to kind of hide the second stage of what it's doing. And that's really the game. You know, they want to hide their behavior. So you've been seeing more and more of it. You've tied it now to the Pollenwriter campaign. I know when we talked earlier this week, we had seven uh confirmed packages that were using it. What are you seeing today?
Paul McCartyYeah, I mean, we definitely have a lot more than seven now. Um, NestTron and a couple other companies um and and individuals have been submitting things to OSM null receiver stuff. Um, so in addition to what we're finding and what I'm finding, we now have other orgs uh introducing it too as well. So you're right, there's been this like overlap between the Pollenwriter style campaign where they're basically pushing malicious code to compromised assets, um, but they're inside of that. So the null receiver is a technique like ether hiding that that you said it a second ago that DPRK North Korea uses to obfuscate where the next stage is coming from, right? That's what null receiver is. Uh on writer is a style, is a threat actor and a style of campaign that is an evolution of contagious interviews. So they're they're it's they both are overlapping here because one they're two different things, but um anyhow, we called it in last week's episode, which is the we said null receiver was gonna quickly become supplant the other stuff, and it's sure enough it has. Like we're seeing it everywhere now. So and it makes a lot of sense because it's simple, it's lean, and you can put ether hiding behind it, and that's uh we're we're seeing it in all kinds of different variations. We're seeing it where it's replacing ether hiding, we're seeing where it pulls an IP, and then that immediately then goes back into an ether hiding um stage, which means that sometimes we see six and seven stages now in some of these kill chains. Um, but one thing that I noticed that I wanted to call out is that one of the things that's great about null receiver that's different than ether hiding is that it allows DPRK to kind of reuse what the next stage is and make it a lot easier for them to do that. So the point of it is that it's very portable and they can highly iterate it quickly, and it's very lean. However, for some reason, I'm seeing that they're not doing that. So they they were doing that, they were using a bunch of different IPs originally, but now they've kind of I've kind of stalled on this one IP. Now, here's the thing is that this IP is hosted in the UK, it has an RDP server. Uh you can like you can go to go to Shodan and you can see it. I'm not gonna say the IP right on the air, but um uh you know, we have it in OSM. But um if if anybody from you know the UK government, maybe NCSC, is listening to our podcast, um, you know, maybe you want to take a look at that or reach out to us and we can point you in the or you know, consume our threat feed because we've got lots of this. You know, all these new IPs will be there for you to to to find. So yeah, they've kind of stalled in this IP gen for some reason, which means that you know we can collect data. Um, I shouldn't probably be saying that too loudly, but there you go.
Jenn GileWell, so why don't you for the people who are listening who maybe are not you know experts, because again, we've talked about how people who are on the more code side may not understand the other side. Um what would you be asking the NCSC to do if you could wave a magic wand?
Paul McCartyWell, the IP is hosted in the UK, which means that um UK law, uh rule of law governs, right? There's jurisdiction, which means that UK government could, and I don't know, I'm I'm originally American, so I would use American language, but could be, and I don't know, I know I live in the Commonwealth now, but I'm I don't know all the language. Um, you know, the the UK government could gain access to um uh you know the the underlying server from the host, which is a company I've never heard of before, but I guess they're relatively big. They are called Evo XT. Um and it's just a VPS hosting service, like all these right are. Oh, this brings up a secondary thing, Jen. Ah, this is I meant to put this on the list last night, but then I didn't. Um I saw um DPRK has lots and lots of money tied up in crypto, and so they like to buy things with crypto because then it saves them from having to do the complicated laundering.
Jenn GileYeah, you don't have to exchange your money and launder it. Yeah, it's convenient.
Paul McCartyAnd lose like more than 50%. By the way, when they launder, they typically lose more than 50% of the value, right? They don't have to do that.
Jenn GileThey really know one of the way they launder it is by gambling, and so yeah, that's gonna be going with this.
Paul McCartyYeah, where am I going with this, Jessica? Where's it going? That's the reason that they like, for example, Astral VPN. Astral VPN accepts crypto as payment for the VPN. So DPRK likes to use third-party services that accept crypto. This is where I'm going with it. And so I've now started seeing these third-party services, and I won't talk about them this week, but we'll we'll put more formality around it and talk about it maybe next week. But I'm seeing these third parties start to offer middleware where they basically will take a crypto payment for a company that doesn't accept it. And so we're now seeing that with some registrors and hosting services. So the reason I bring this up is that we need to be aware of this because that means that DPRK now is going to be able to spread their services across a larger number of SaaS providers, hosting, registrars, all this kind of stuff, you know, proxy um uh providers, all that kind of stuff.
Jenn GileUm, so yeah, yeah, the way that I might uh uh sum that up is certainly whenever possible, they choose not to spend money. You know, they choose free services, people know that. But at some point, we are entrepreneurs ourselves. We know you have to pay for infrastructure at some point. So this is, you know, if they can pay for it with crypto and more places are accepting crypto, this can kind of maybe help us see where they um are putting their infrastructure and where they're where they're spreading out to.
Paul McCartyYeah, more more to come next week or or soon. Um we'll we'll leave it at that.
Jenn GileAll right, let's call it here. Um it's it's been an interesting episode. Stay in touch. Let us know what else you want to learn about. Uh don't hesitate to ask questions. Take care.
Paul McCartyThanks for listening. Cheers. Bye bye.
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Open Source Security
Josh Bressers
Future of Threat Intelligence
Team CymruAbsolute AppSec
Ken Johnson and Seth Law
Coffee, Chaos and ProdSec
Cameron Walters and Kurt Hendle