Ransomware and State-Sponsored Threats – Paul Prudhomme, Rapid7
Paul Prudhomme from Rapid7 talks about threats to Japanese organizations by relevant industry and highlights two key cross-industry phenomena: Ransomware and state-sponsored threats.
Transcript
This is Textron tv. Hey everyone. Welcome back to Textron tv.
I am happy to have on Mr. Paul prude, Dom principal security analyst with Rapid Seven. Today we're gonna be talking about Rapid Sevens recent, or 20, it's 2023.
It's a recent though, uh, Japan Cyber threat landscape report, and I'm excited to hear about it. But before we do that, let's welcome Paul to Text Strong TV and find out a little bit about kind of Paul's story. Hey, Paul.
Welcome. How are you? Good, how are you?
Good, thank you. Hey, man. Oh, no, it's my pleasure to have you on.
Paul, before we jump into this report, let's talk a little bit about, you know, your principal security analysts over at Rapid seven. Why don't we give people a little bit of your background? Okay.
Uh, well, I came to Rapid seven, uh, through the acquisition of, uh, insights, which was a, uh, threat intelligence, uh, startup, uh, that Rapid Seven acquired, uh, almost two years ago now. Uh, so, so Rapid seven ha ha ha having had a whole variety of security services, uh, and offerings. Uh, but what it did not have was threat intelligence.
Uh, so, so, so the, the, the point of this was to, to add a threat intelligence capability, uh, to that broader, uh, suite of, uh, security services that we provide. Uh, so, so I've been doing threat intelligence, uh, in, in, in my career in, in, in, in one sh one, one way, shape, or form or another for 16, 17 years now, uh, the second half of that career has, has been all in, in, in the commercial space, uh, focusing specifically on cyber threat intelligence. Uh, started out, uh, at, uh, Verisign, uh, when, when, when I, defense was part of that, uh, and then moved on later to Deloitte, uh, where I was a leader of the cyber threat intelligence, uh, subscription service, uh, for quite a few years, uh, before I moved on to, uh, to, to insights.
Uh, so wonderful. So, uh, that, that's the second half of my career. The first half of my career, uh, I was a contractor in the US intelligence community.
Uh, that was not cyber threat intelligence, per se, that was, uh, intelligence in cyberspace. Uh, and that is where I acquired both, uh, my grasp of the discipline of intelligence with an uppercase I, if you will, uh, you know, the, the, the discipline of, of, you know, spycraft as practice by, uh, government intelligence services, uh, and then also, you know, collecting that information in cyberspace. So slightly different, uh, wrinkle on it, but that's where I acquired the two main halves of my skillset that I've been using, uh, for the past decade or so.
Very cool. Great. It's a great story, a great career.
I had a feeling there was some three letter agencies or something in there somewhere, but let's leave it at that. Let's not get in trouble. Yeah.
Um, so Paul, I think most of our audience, of course, is familiar with Rapid seven. You spoke a little bit about kind of the breadth of Rapid seven today. I mean, I'm, I'm familiar with Rapid seven pretty much since Alan first started Rapid seven.
I, I'm going to guess it was around 2005, 2006. Uh, and back then it was pure vulnerability scanning, right? Is I, I had co-founded a security company, which was a competitor, was very similar.
We, uh, we had a product called VAM and Rapid Seven, and there was, there were a bunch of others back then. There was Tenable and Qualis and yeah, Foundstone, which got bought by, I guess it was McAfee at the time. Uh, it was, it was a, it was a, an interesting era of vulnerability scanning.
But of course today the security industry or cyber as we call it, has grown up and you can't just have vulnerability scanning. And Rapid seven has kind of, you know, grown and expanded during that whole time, adding AppSec capabilities, threat intel, as you mentioned, you know, a, uh, a full menu, if you will, of, of cyber offerings. And, and today they're one of the leaders, you know, in, in the space there.
Um, I was intrigued when I saw this, uh, request for an interview come by because I've never seen a, a, a Japan specific cyber threat landscape report, and people lose sight of it, right? Japan is still, I think, the third largest economy in the world, right. Probably hamir US and China and it, it, but it's a, it's a unique economy, right?
I've always, and I've got 30 years in tech, 25 plus in security, always been told, look, if you, if you wanna play in the Japanese market, you gotta have a native language tools there. Your interface has to be native and you know, Japanese and everything. And I never worked for a company that invested in that, so I never had a chance to really understand the Japanese market in the Japanese, you know, threat landscape.
What, you know, is this the first time, uh, rapid sevens done one for Japan, or have you guys been doing this for a number of years? Uh, well, well, let me get back to, to the, to the first point you mentioned, uh, you said you've never seen a, a threat landscape or anything specific, uh, devoted to Japan. Uh, so, so, so that's, that's exactly why, why I decided to write this.
I, I, I, I thought that, uh, that this is a, an area that's been really, I think underserved, uh, by, by, by the security research coverage, uh, in English. Uh, so, so, you know, you know, so, so so much of the security research that we see out there, uh, is heavily focused largely on the us uh, primarily and then, and, and then to a lesser or secondary degree on Europe. Uh, and a lot of that is just because, okay, well, the US is what, what part of it is, cuz the US is the largest economy in the, the world by big margin.
But also part of it is because so many of the, the security companies that dominate the market globally are also American companies. Uh, but Okay, well, well, who, who, who, who else is important, you know, economically be besides the us Okay, well, well, there's China, but when we talk about China, uh, we're not usually talking about 'em as a target, you know, if you get my drift or mm-hmm. In a different context.
Mm-hmm. So well after China, who's next? Okay, well, well, there's Japan.
Okay. Uh, well, where can we find some information about, uh, threats to Japan? You look, you know, no, I've never seen any, that's what I'm saying.
If you want that, that's sort of quick handy, Dan reference, uh, you know, sort of, you know, threats to, threats to this country 1 0 1, a sort of a quick primer, a broad, uh, 10,000 foot overview. Uh, it doesn't exist. And, and, and, and, and you, and, and you brought me, you saw, as I go through the report, I really had to piece together a lot of these things from, from just sort of passing or fragmentary or standalone references here and there.
There might be, there, there are plenty of references to incidents in Japan, uh, that are buried, uh, you know, within the nooks and crannies of broader reports on other things. But to find a very broad standalone piece, you know, a Japan 1 0 1, uh, it, it, it just doesn't exist. And I said, okay, well, maybe we should have it.
Uh, now with that said, uh, I, I I, I like to, to recognize some of the work that, uh, the Japan cert has done, uh, in English, uh, that, that, you know, shedding light on some incidents in Japan, uh, that might not have otherwise come to the attention of the broader, uh, you know, global, uh, security community, uh, publishing this information in English, uh, does help to transcend the language barrier. Uh, and I'll, and I'll say personally that I found quite that some of their research quite useful as I was putting this together. Absolutely.
Absolutely. Um, is it, is it strictly the language barrier that you think I, I believe, has prevented it? I think that that is a problem.
Uh, it, it, it is, it is maybe not the problem, uh, but it is a factor. Uh, I, I, I, I imagine, uh, there are other ones, of course, but I think some of it is just a matter of perspective. It's just maybe somebody just hasn't asked the right question yet.
Uh, the way I approach is, okay, well, you know, outside of the us who are the, who's the most significant, you know, target economically? Uh, so, so some of it is the thought process, but yes, I do believe language is an issue, not just in the security coverage, uh, but also when we get talking about attackers, uh, or, or, or the actual incidents. Um, a as you may notice in the report, one of the, the, the points I raised was that, uh, you know, we're, we're, we're not just talking about, uh, incidents inside Japan, we're talking about global companies, uh, that are headquartered in Japan.
Uh, and that's why I explained the scope geographically a little bit to also include the overseas, uh, subsidiaries and affiliates of Japanese companies. Uh, and in my mind, you, you, you can't just arbitrarily stop at the borders of Japan because the companies are all over the world. The, the, you know, the Japan's global economic footprint is, is huge and really only a second to the US when you think about it.
Uh, and, and how many of these Japanese brands are so familiar to us that we almost figured that the Japanese is just so familiar that we don't, we don't think of it as foreign. And, and, and in that sense, uh, so Well, it's part of this global economy and that globalist view, and I'm a globalist, so I I'm all good with that. Yeah.
But, um, I, I will tell you just a personal observation, and I don't have metrics to back this up. I have seen you want to call it the opening of Japan over the last, let's say, five years, certainly since Covid. Um, whereas as I said earlier, before it, look, if you weren't, if your, if your product wasn't native language for j the market there, you didn't really stand a chance.
Yeah. But I have seen now English language products penetrating Japanese markets, and I've seen, I've seen a larger number of Japanese companies and, and true, you know, based in Japan, folks participating in cyber and DevOps and, and, you know, industry conferences, whether it's in Singapore or Australia or here in the US West coast and so forth. So I do think we're seeing more of a integration of Japan in, into that global sort of community, where earlier in my career, not so much.
Yes. So, so, so you're talking about the importance of, you know, localization. Uh, so, so this is an issue not just for the security professionals, but also for the attackers, and, and, and the, as I kind of alluded, it's true.
Yeah. That's one way of thinking about it. Uh, if you're going to try to, you know, phish somebody, uh, you know, generally speaking, uh, uh, attackers, especially criminals, tend to prefer, uh, targets whose language they speak.
Uh, and, and, and of course English, uh, you know, being, being the primary, uh, international lingua franca, uh, makes us in the US and the UK and so on, uh, more accessible to a fairly wide array of threat actors. Uh, but with Japanese, uh, a language that's not really very widely spoken outside, uh, Japan, uh, and, and, and, and can, you know, be, be challenging for foreigners to really, uh, master especially some of the, um, uh, social and, and, and cultural, uh, nuances, uh, that that might not exist in other languages. Trying to write a convincing fish, uh, in Japanese, uh, is gonna be kind of tough.
So, so, so why do that when you could just fish, uh, their, their employee in New York or London who speaks English, uh, and then, and then use that initial access point in the overseas subsidiaries to move laterally into the parent company in Japan. And, and, and, and as I was doing this research, I, I saw this so many times, uh, that, that I thought that this really needed to be highlighted, uh, that, that, that, for, for, for a global Japanese company, uh, one of the main, uh, you know, access factors are one of the main, uh, points of vulnerability, uh, is, is those overseas subsidiaries, uh, and being more accessible, uh, either cuz of linguistic issues that makes them more vulnerable to social engineering. Uh, or it could be if it was an acquisition, uh, maybe there were some existing security issues, uh, that the company inherited with the acquisition or the merger.
Uh, and that just exposes, uh, the parent company in Japan, uh, to whatever, uh, security issues they had overseas. I mean, look, even English language phishing emails are sometimes so poorly written that it makes it kind of easy to, to, to identify 'em. But you're right, I mean, the fact that they, you know, that their language, it's a barrier not just for marketers, but for the bad guys as well, though, I'm sure, well, I'm not sure, but I've gotta assume that there exists within Japan itself, a malicious element, whether it be crime, financially, you know, criminal financial activity related or, or activist, activist or whatever, who, who are in fact are native Japanese speakers.
Uh, there is, uh, but I, I didn't find a whole lot that that was really compelling or interesting about it. Uh, and it, well, well, now of course, again, the language barrier, uh, is an issue. And maybe there is information out there that, that, that I simply believe wasn't in a position to appreciate.
Um, but, but you mentioned criminal activity and I found actually that, that the most really, really significant, some of the most significant criminal attacks on Japan have been actually from the North Korean actors. Uh, really, yeah, that sense, although being who, although being state sponsored, uh, have been engaging in, uh, criminal activity, uh, for the purpose of raising, uh, revenue, uh, for the government, uh, especially the former cryptocurrency, uh, since they, that, that they can, uh, move and use that, uh, outside of the, the traditional, uh, you know, financial services, uh, channels cuz of the sanctions, uh, that they're under. Well, eh, I mean, no ha hacking and, and for financial gain is a cash crop for North Korea.
I mean, it's probably one of their leading industries from an export point of view, right? Yeah. Uh, and it's not just Japan we should mention, but, you know, let, let's jump into the report a little bit more.
Paul, before we do, I wanna let people know, anyone who'd like to check out this report, I'm gonna try to give you the URL here. com/info/cyber threat dash landscape dash of dash Japan, and we will try to put that, uh, link into the notes on this interview for Textron tv. But if you're listening to this via podcast, are you seeing it streamed on the Textron network?
If you come, that is the address where you can get it at, or you can come through the Textron TV and we'll have the address there for you in the notes. Uh, Paul, that being said, so you mentioned language being a big barrier external, or excuse me, uh, non-Japanese based outpost of Japanese companies being probably the leading sort of, uh, vector in, in, into these Japanese companies from a an attack point of view. What else would you say are come at some of the big takeaways there?
Uh, so ransomware, uh, that does really stand out, uh, among the various criminal threats. Uh, I mean, obviously, you know, ransomware is at, is at the forefront of almost everybody's minds, you know, around the world when they're concerned about criminal threats. But, uh, Japan, I think it does hit a little bit harder there, uh, just because of the nature of the economy, uh, you know, you know, so much of the economy consists of manufacturing, uh, and, and, uh, when, when, when you're a manufacturing organization, uh, you know, e e e even the slightest disruption, uh, can, can have a really significant, uh, impact on the business.
Uh, so, you know, normally when we talk about ransomware, uh, in, in the US or Europe, uh, you know, we ask what, what, what are the preferred victims? Uh, uh, I know the first answer, most people are gonna say it's healthcare, uh, because, you know, healthcare, it's easier to, you know, extort them, uh, because the time sensitivity, sensitivity to what they do, you know, or people are gonna die if, if they can't get their services or it's gonna affect their health in some serious way. So, so, so that that notion of, you know, having a low tolerance, uh, for downtime because of a ransomware related outage.
Uh, now with manufacturing, obviously it, it, it's not the potentially life or death issue that it might be for a healthcare provider. Uh, but you know, if your job is to make things, uh, and you can't make things, uh, that, that, that, that's a very, you know, serious problem. Uh, so, so, so that perception of, you know, greater vulnerabilities to extortion, I think is part of it.
Uh, and, and, and, and actually the Japanese, uh, authorities did release some figures last year, and it showed that, uh, manufacturing wa wa was, was the most frequently targeted sector for ransomware by a fairly wide margin. Uh, somewhere in the neighborhood of, uh, one third of all incidents, uh, where, whereas manufacturing, whereas healthcare was much lower in the, on the list somewhere in the, in the, in the single digits. Uh, so, so, so, so, so there's that.
And then also, uh, you know, if you're gonna compromise a manufacturing organization, uh, sometimes ransomware is the best way to do that, uh, to, to monetize it. Uh, so, because sometimes a manufacturing organization, uh, might not have a whole lot of information that is useful to resell on, on criminal forums, you know, they might have some, some, some personal information for employees and so on and things like that. Uh, but it might, the, the, just the content that you take from there might not just, might not be that juicy.
Uh, and that depends on what it is. Now, if it's company that makes ball bearings or something like that, is, is that, you know, intellectual property really useful? Probably not.
Now, if it's something more sophisticated like, like, you know, consumer electronics or cars or something, maybe that would have some more resale value. But basically, if you're going to monetize a compromised manufacturing organization, ransomware is often, uh, the best way to do it. So, so, so it's funny, we, when, when I was writing the court report, I had a whole separate section on, you know, just manufacturing outside the automotive industry.
And, and somebody said, well, you need to stay in little section on ransomware. Uh, and I realized that the ma the section I had on manufacturing outside the automotive industry already was pretty much a section about ransomware. Uh, so, so, so the section that you've seen now started, uh, uh, was labeled as ransomware, was actually just the manufacturing section.
And then I realized that the ransomware section and the manufacturing section where they overlapped so much that that, that, that it just turned into my whole treatment of ransomware for the paper. Uh, now obviously, ransomware does affect other industries, including automotive. Uh, and, and, and, and I do think it's important to separate out the automotive industry in particular, uh, from other, uh, types of manufacturing.
And actually, I found that in contrast to, to non-automotive manufacturing, uh, the automotive industry actually had one of the widest range of threats, uh, affecting it, uh, compared to the other industries. All, all, all the other ones were fairly straightforward, and there was a pretty obvious reason why, why people would be taking an interest in them. But with automotive, it was all across the board.
Mm-hmm. Certainly ransomware as part of it. Uh, but then there's things like, uh, stealing intellectual property, uh, stealing, uh, diagnostic and dealer tools that you could use in car hacking.
Uh, you know, like these, these sort of things that you see at Black Hat and Def Con and people hacking into cars, uh, and so on. What, what, well, if you steal some of the proprietary tools that the company has, uh, you, you, you can use, you can, you can, car hacking gets a lot easier and a lot more interesting when you have access to that sort of thing. Uh, there's consumer data, uh, like when people sign up, uh, with the brand or the manufacturer, uh, for connected car services, uh, or, or, or, or for, you know, maintenance and warranty things and so on, uh, that could be compromised either with a compromise and the manufacturer or the dealership, uh, or some of the third party vendors that provide, uh, these services.
Uh, security misconfigurations can happen in any industry, but I, I was surprised how frequently I came across it in the automotive industry, uh, to a degree that just was really disproportionate. Not sure why, if that was just a fluke. Uh, but so, so, so many, uh, when, when you, when you see something so many times, uh, that, that it jumps out at you like that, uh, I think that, that that's a good sign that, you know, something's up.
So they, they did seem to be a bit more prone to it, uh, than the other industries that I came across. Uh, so, so really automotive, the automotive set it, it for, for the, the, the half of the report that breaks threats down by industry. I think the automotive one is the most interesting simply because of the wide variety, uh, of issues that the industry faces.
Uh, and also because the automotive industry is such a huge part of, uh, Japan's very recognizable, uh, global, uh, economic footprint. Hey, great work on this. Paul, I want to thank you.
I thank you for coming on and, and great. And thank you for doing this report. Oh, thank you.
Yeah, no, thank you for joining us. We're gonna take a break here on Text Drunk tv. We'll be back in a second.