The Post-Content Verification World
Audio can be cloned in seconds. Video can be faked in minutes. Holding up an ID card to a camera no longer means anything. John Wojcik, Senior Threat Researcher at Infoblox and a seven-year veteran of the UN Office on Drugs and Crime in Southeast Asia, joins Alan Shimel on Techstrong TV to lay out what he calls the post-content verification world — and the industrial-scale criminal economy already exploiting it. John walks Alan through Infoblox’s preemptive DNS security model that secures more than 75% of the Fortune 500 by treating new domains as guilty untihttps://vimeo.com/1204595964l proven innocent, the human trafficking crisis powering pig-butchering scams across Cambodia, Laos, and Myanmar, the $25M deepfake CFO heist in Hong Kong, and why basic hygiene — segmentation, MFA, and separating personal from corporate devices — is no longer a nice-to-have.
Transcript
Hey everyone, it's Alan Shimel here on Techstrong TV. I want to introduce you to our next guest. He's someone deep in the throes of what's going on in research and threat intelligence, everything else in cyber.
His name is John Voochich. Did we say that right, John? Yeah, Voochich, that's just fine.
Okay. John is a senior threat researcher at Infoblox. So, John, how long have you been at Infoblox as a threat researcher?
I've been at Infoblox for about a year. Before that, I did about seven years at the UN Office on Drugs and Crime based out of- Oh, very cool ... but overseeing all of East and Southeast Asia.
Really? Oh, that must have been exciting. To say the least.
To say the least is right. Well, this must be almost mundane compared to that, right? But nevertheless, still important.
Hey, John, not everyone out here is familiar with Infoblox, right? Our audience is cyber DevOps platform engineers, but I've known Infoblox for years and years, more around DNS, to tell you the truth. But for those who aren't familiar, how would you describe Infoblox to them?
Sure. So I think Infoblox is, at this point, really a leader in preemptive security built on DNS. We run enterprise DDI, so it's like DNS, DHCP, IP management.
I think we're securing over 75% of Fortune 500. Lots of cooperation on investigations and cyber threat intel across the board with law enforcement partners from the US and far beyond. And that gives us a vantage point that almost nobody else has.
Over recent years, and really part of my recruitment was to do with how we're moving into the direction of a security company. We do one thing really well, and that's protective DNS and kind of the founders of original DNS-based threat intelligence, and I'm sure we'll be talking a bit about that today. Sure.
Before I did the media thing, I had started a few security companies. And man, I still remember the day when Dan Kaminsky found that DNS, the bug that almost broke the internet, as they say. And that really put DNS for the first time in the spotlight, though Infoblox had been talking about DNS as a weak point for years even before that.
John, we're living in strange times, though, different times. AI presents a whole new level of challenge, a whole new level of threat, unfortunately. And even though our DNS today and strong DNS and everything, our DNS today is not what it was in 2005 anymore, thank God.
But AI, as I said, presents a whole new level of challenge. So it's this cat and mouse game that we play in security. Talk to me about the threat that AI poses specifically around DNS and stuff like this, and how DNS could be used actually as a shield.
Sure. So maybe just to step back a little bit, I can start off by introducing who I am and what I do. Okay.
As a senior threat researcher, I was basically brought in to focus on APAC, so the Asia-Pacific market. So my expertise is regional, the regional threat landscape. Really?
Oh, I didn't realize they do it by locale. I figured it was just global. Yeah.
The threat landscape is really dynamic, and obviously, you give me a nice Russia or Iran-focused threat, I'm going to dig in. But my bread and butter is definitely Chinese organized crime, and a lot of these kinds of pig butchering and types of fraud that's proliferated exponentially and causing a lot of havoc and damage across virtually all corners of the world. So basically, I've been tracking that space for about seven years, and that was really what brought Infoblox and my research together.
And so just to get to your point about the force multiplier that AI-driven threats and technologies pose, it's kind of a double-edged sword, right? It's obviously a miracle in some cases for defenders, but equally, a really powerful catalyst that's supercharged the global threat landscape. And certainly in the region.
I'm sure we'll speak more to that. But irrespective of what's happening within the broader threat landscape, you really have DNS that's emerging more and more clearly as a key choke point that attackers can't really avoid. There's usually a DNS nexus across any sort of vertical that you look at, typically.
Whether it's fraud, ransomware, malware, phishing, you name it, there's very likely a DNS component. I think that DNS said like 92% of malware threats have a DNS component at some point. So what we specialize in is really that kind of preemptive DNS security, where we assume that a good majority of new domains that are registered today are being registered and ultimately controlled and weaponized by bad actors.
And so in doing that, that allows us to leverage our provenance, our bread and butter- ... as a more traditional DNS company and moving into that security space in order to operationalize what we're really good at, which is identifying, tracking, and ultimately disrupting bad domains from reaching our customer networks. And trying to shift the conversation away from what's traditionally reactive and more towards something preemptive.
So it's almost like zero trust for DNS for domains, right? Assume they're bad actors. Right.
Yeah, you mentioned pig butchering. It's a term I've heard and know about, but a lot of our audience may not. Why don't you explain it?
We're not really talking about selling pork chops, are we? No, we're not. Wish we were, though.
Oh, me too. Yeah. Unfortunately, it's this kind of nasty term.
I'm not the biggest fan of it, but fundamentally this is what the Chinese criminal networks are calling it. And the idea is pretty similar to any sort of traditional investment scam. Could have a romance dimension, it could be kind of like so-called financial grooming.
But ultimately, these massive criminal networks have gotten to the point where they're pretty good at emulating what appears to be a legitimate investment platform, crypto trading platform. Could be an online casino that's rigged. They've gamified it also.
And so, very convincing social engineering that goes into this. It's resulted in large banks defaulting because a bank manager thought he was raking it in and doing the bank a service, was not. It's obviously ruined people's livelihoods and pensions, right?
It's terribly destructive and oddly effective. " Unfortunately, it's not the case. We're moving, and this is also a good segue into the AI component here, we're moving into a sort of post content-based verification world.
Where you and me on camera right now, I might be a deep fake for all you know. And that's the reality. And unfortunately, the systems, we're talking about zero trust a little bit, but within that reality of this post content-based verification world, the systems, the locks that we've had set up over the past decades, across e-commerce, across financial technology, online banking, you name it, they're just proving insufficient.
And so it's really, I think, rapidly causing a lot of chaos because a lot of these institutions that depend on trust, and verification by content means are unable to make sure that their businesses and their clientele are safe. But going back to pig butchering, and again, we can go down this pathway if you so choose. We've been seeing this pig butchering phenomenon or the proliferation of cyber-enabled fraud scams really just blow up over the past few years.
It was initially perceived as a Chinese criminals targeting Chinese people type of a problem. I was certainly on the front lines trying to sound the alarm since 2020, as we saw this evolving and morphing. And COVID-19 really exacerbated things.
People working from home. A lot of this stuff is driven by victims of human trafficking who are lured into the region, into Asia, into Southeast Asia specifically. Countries like Laos, Thailand, Cambodia, Myanmar, the Philippines.
Cambodia. Yeah. Some people call it Scambodia.
I'll be on that boat. And yeah. Basically, I ended up in a situation where you've got hundreds of thousands of people forced to scam, increasingly also voluntarily participating because it does pay the bills, and some people have gotten quite good at it.
And it's a part of this nasty, booming illicit economy in the region that's pretty pioneering in the way that they're innovating, they're integrating new technologies. There's a whole ecosystem of criminal service providers sort of fueling these developments. And part of my work is not only to track and detect and disrupt these actors as a security researcher, but also monitor the way that they're evolving.
And unfortunately, the scary part here is that against this backdrop of new tech and obviously AI-driven tools and capabilities, is a growing threat. And that threat is unfortunately moving in the direction of things like malware distribution and just industrial-scale phishing pipelines. Anything they could do, man.
The bottom line is here, when we talk about the term pig butchering, the pig is you. People out there watching. Yeah.
That's what they're calling about. John, I'm reminded, I taught a security class in Singapore for regional banks. It was 15 years ago.
Long time ago. We had banks from all over the region, including Cambodia. " I was trying to get an idea of what...
This one's using Check Point, that one had Cisco, whatever. Would you believe the banks in Cambodia didn't have firewalls? I don't know, because they didn't have money there or whatever.
I do believe it. Yeah. These are countries with no incident response teams either.
Yeah. It blew me away. But That was 15 years ago.
I hope it's a little better, but it doesn't sound like much. My breath. And right, deepfakes, AI, it's just taking this up a notch.
Now, I don't want to be the pessimist, all pessimistic. AI also allows us, we could use it as a shield and a weapon as well. Unfortunately, it's just the nature of cybersecurity that there's sort of an inherent advantage to first mover.
And that's what we're up against there. One of the standards is this KYC, know your customer. Talk to us about that, John.
Get our audience smart on it. Sure. So KYC is traditionally sort of a term discussed within the sort of compliance, anti-money laundering, counter-terrorist financing sort of a space.
It's much broader than that, but it stands for know your customer, right? Almost forgot. So again, bringing this back to the idea of post-content based verification.
KYC is sort of this process you and your audience can imagine as, I've got my ID in my hand and you're a platform, you're a service provider. It might be a crypto exchange, it might be some cool technology, and you want to make sure I'm going to be auditable. You want to make sure that I'm going to be using this technology safely or perhaps using my bank account in a responsible manner, so I put my ID up to verify who I am.
Again, post-content based verification. Fundamentally, our detection of these types of validators these days are frankly getting worse than better. And that's because the tech on the adversary side is improving.
And as a result of that, like I said, the traditional way of doing business is fundamentally shifting beneath our feet. Unfortunately, not at a pace that's fast enough. And so going back to the context that I know, which again is sort of regional, East and Southeast Asia, I spent a lot of time myself, both with the UN and now in my role as a senior threat researcher with Infoblox, monitoring these sort of underground platforms.
Not just dark web monitoring, but the criminal networks in this region really prefer and gravitate towards Telegram- Mm-hmm ... online marketplaces for criminals, where they can congregate and do their business. So I spend a lot of time in those spaces.
And there's been really a surge in tech that enables those types of, some people call them attacks, but I'm just going to, it's deepfake abuse, we can call it that. And so these tools are being more and more widely available. They've kind of diffused across the threat landscape in this region.
They're quite affordable, frankly. And it's enabled a whole lot of problems for not only financial institutions and enterprises, but equally for victims trying to validate who's on the other side of a phone call or a- It's impossible ... bank phone call.
It- Yeah. We've all heard these cases with, I think one of the most famous ones relating to a $25 million fraud from- Singapore ... Hong Kong or Singapore-based company.
Hong Kong, yeah. It was a deepfake. The guy was the CFO and the- Right ...
it looked like the CFO anyway. Yeah. Yeah.
So, we're at a stage where it takes three seconds to, probably three seconds or less at this point, to clone my voice. Somehow I think that vector was used recently for me to get a new Aeroplan card on my online banking setup. Which is great.
Really? Always wanted one of those, but didn't apply. Called my bank the next day to say, "Hey, did you guys set this up for me for free or what?
" I said, "Guys, I've been living in Bangkok for eight years. You know that. It's on my file.
Why would this be set up? " You'd be surprised. So to this day, I have a canceled Aeroplan card set up on my online banking that they won't remove because they can't.
So, it's- It's- And that's the softest of the stories these days, right? No. Look, I agree.
It's funny, I've been getting, and I don't even want to say this online, but I've been getting attempts to log in or w- I have so many different mail accounts, but someone's trying to log in to one of my Microsoft accounts. But I have it pretty locked down. It goes through my authenticator.
And so I just don't approve it, obviously, and I'm reporting it to Microsoft. But I'm sitting here thinking, I'm not going to change my password because it's not a question of, it doesn't use a password, thank God. Mm-hmm.
And for all those people out there who b***h and moan about 2AF, two-factor authentication, and what a pain in the asset, excuse my language, what a pain it is. You know what? It could save your bacon.
Back to the pig butchering thing. It could save your bacon. And I really don't understand why more people don't use these things and help anything.
Because the nature of these crimes, John, and you know this, you're living this life, it's akin to walking down the hallway in the hotel and they're jiggling handles trying to see who didn't lock their door. If you make it too hard for them, they'll go to the next door. And unfortunately, it'll be someone else's misfortune, but that's just the world we live in.
So John, let's end this, though, with some good news. What can people do? I said two-factor authentication, but what do you recommend to people to try not to be the pig being butchered here?
Sure. Yeah. I was going to go down a different route and tell you that the multi-factor authentication is also being increasingly targeted by- Absolutely ...
new attacks, right? Stealing your browser sessions, right? Emulating the session you're in and bypassing your 2FA without you even knowing.
But- Mm-hmm ... let's shift to a brighter note. Yeah.
No, let's end it on a brighter note, John. Yeah. Surely.
I have a tendency of not doing that. So let's give it a try. So, I think first and foremost, I think our relationship with cyber needs to change, right?
I think your platform and this conversation is part of that, and cyber awareness is critical, right? So I think the more and more people who get interested in these threats, right, I tend to say that I'm in the business of scaring people into caring, right? With some constructive components, right?
So, what you can do, and I know it's annoying, but regularly changing that password, using different tools that are available, obviously the trusted commercial ones, to ensure you're aware of your vulnerabilities online, right? Your exposure to underground data markets and brokers, to the threats that are out there, right? To my parents, I say double, triple-check the links you're clicking on, right?
We're at a point again where it might look like a legitimate link you're clicking on. Next thing you know, you're getting pushed by some sort of back-end systems, traffic distribution systems into something bad. Have a plan for when things go wrong, right?
Unplug your machine right? Have resources at your disposal to be aware of how to respond urgently. That said, it could be too late.
And, fundamentally just kind of taking security more seriously, right? I think more and more we're finding needs to distance ourselves from immediate exposure, right? Creating alternative profiles to be browsing the internet on, right?
Having a dedicated machine for your personal life versus your work life, in my case, versus my threat hunting, right? Yeah. I would imagine.
Equally, you're sort of, and this is probably above what most people want to do, but network segmentation is also quite important, right? Yeah. So- Well, no, but at the commercial level, it is very important, right?
Of course. Microsegmentation and so not having that flat get in and boom, the whole thing is open. Yeah.
At least have a couple of doors for them to poke at. So John, I've been in security over 25 years. It seems so...
Of course, you want network segmentation. Of course, you don't want a flat network. But yet, okay, the Fortune 50, the Fortune 100, they don't.
They have network segmentation. They've got microsegments. They're doing all their things.
But when you get to the bread and butter, the bulk of the six million odd businesses that there are in the world, I would say the majority of them don't have any segmentation. They don't even have a clue- Of course ... to what it means to segment.
And- Right ... and so here we are talking about it, but that's also why they look to companies like Infoblox, right? Because a lot of it, look man, if we could lock down the DNS so someone doesn't hijack the site, so that's one layer in this defense in depth, right?
Yeah. Absolutely. And so I'm an optimist by nature.
I also do believe that with AI, we're going to use it as more of a shield. We'll figure out some new technologies that are going to help because like you talking to your parents, I think every single person in IT becomes the IT person for their family. This one, the aunt, the uncle, whatever, right?
People call up, and they do stupid things. Sometimes it's too late by the time they call you. We've all done that, taken those calls.
We need better tools. We need to develop better tools for people, I think. Absolutely.
And then John, we also need people like you being vigilant and sounding the alarms on what you're seeing, right? Yeah. I hope all of that together can do a number on what we're up against, but certainly optimistic.
I think the direction things are trending, cybersecurity writ large is kind of evolving away from a nice to have to a need to have, right? And it goes- Oh, I- ... the same way we- I need to- ...
do with protective DNS. I think more and more enterprises and more and more governments, frankly, are waking up to the idea that DNS is a critical component of any sort of- Absolutely ... infrastructure, right?
Absolutely. You know what, I don't know if we mentioned the... Did we ever mention the Infoblox website?
No, I don't think we did. I don't think so. com, isn't it?
It is. People get information there. All right.
Hey, John, it's like the middle of the night there or whatever, so I'm going to let you go. But hey, keep doing what you do. People, if no one's told you lately, we appreciate it.
I appreciate that. Thank you. We appreciate it.
It's a pleasure. All right. Thank you so much.
My pleasure. All right. Hey, you're watching Techstrong TV.
We're going to take a break. We'll be right back.