Vanguard Panda Insights with Crowdstrike’s Adam Meyers
Adam Meyers provides deep expertise and insights into Vanguard Panda, a prolific China-nexus state-affiliated threat group. Meyers dives into the group’s history and motivations, as well as their tactics, techniques and procedures (TTPs). Then, he discusses why critical infrastructure is a primary target and best practices on securing these systems.
Transcript
This is Textron tv. Hey everyone, welcome back here to techron tv. You know, I'm really well, I'm always happy to meet a fellow Long Islander, to tell you the truth.
It's good to be home, or it makes me feel like I'm home, but it, I, I'm really excited to have this next guest on. He recently coming off some testimony in dc. He's, he's head of counter adversary operations over at CrowdStrike.
And what a, what a, if you're into cybersecurity, what a great place to be and what a great position to have. Let me introduce you to Adam Meyers. Hey, Adam, how are you man?
Hey, doing great. Thanks for having me. My pleasure to have you up here.
I have you on here, Adam. Um, as I said, always nice having a fellow Long Island around with me. Um, are you still out Long Island, Adam, or where are you These guys?
I'm out in DC. Okay, very cool. Uh, as some of us do, you know, we, we call that like halfback territory for people who went all the way to New York and then went halfway back, uh, all the way from New York down here and then halfway back.
But anyway, um, Adam, I mentioned your head of counter adversary operations over at CrowdStrike and went a great role. That is. But let's talk a little bit about before you had this roller crowd strike.
What's, you know, what, how do you, how do you train for such a job? What's your experience look like? What's your journey been?
Oh, well, uh, you know, it started off dialing into the 5 1 6 PBSs back in the day, uh, up in Long Island and, uh, oh, Like that baby. And, uh, I think it was, uh, some of the, um, the 2,600 stuff back then I was gonna do. But, uh, you know, and then, um, ended up working, uh, in the defense industrial base, did pen testing and red teaming for many years for military intelligence community and civilian sector government customers.
And that kind of led me towards playing with some exploit development, which kind of got me into reverse engineering. And then I spent a number of years, uh, working over at State Department with diplomatic security doing reverse engineering technical analysis and tying that back to threat actors. So when we launched CrowdStrike 13 years ago last week, the, um, the impetus was to, to kind of have an intelligence driven company, right?
Because we recognized that, and when CrowdStrike started, it was at the end of, it was just after the Aurora incident in 2010 timeframe, when everybody kind of realized, oh, the, the security products we're relying on every day. Antivirus doesn't actually stop advanced threat actors coming outta China and Russia and Iran and places like that. And so we kind of built this whole company around this idea that if you understood who those adversaries were, how they operate, what they're after, you're gonna be better at defending against them.
And this is how we brought the technology, the intelligence, and all of our cloud and, uh, AI and machine learning together to be able to actually stop the small fraction of things that we're sneaking through, but causing the most damage. And then work backwards against all of the other threats. So today we track 250 threat actors across the globe and our, you know, in the identity space where we're really tracking what we call cross domain threats when a threat actor is, you know, stealing an identity, and then they come in and they go to an unmanaged device and they move to the cloud, they're going across from the identity to the enterprise to the cloud, and kind of one foul swoop.
You need to hunt that differently. You need to track that differently. You can't defeat that with just an endpoint product.
And so that's, that's what we're Talking that, yeah. So Adam, you know, I, I knew George, I knew George when he was at Foundstone before they sold it to McAfee. Mm-Hmm.
So go going back a little bit. And the, the company I had helped found back then that still secure, we also sold a lot about 60% of our business was DOD and related, you know, kind of work. Um, so I'm, I'm familiar with where, where you're coming from.
I, I almost feel like we gotta put out a disclaimer that not all of this type of adversarial, uh, uh, activity is necessarily nation state. There's also just the plain old criminals, right? We purely for financial and sometimes financial dovetails with nation state, especially like North Korea, who probably supports a good portion of their GDP from ripping off, you know, from hacking and financial gain, but, excuse me, CrowdStrike.
CrowdStrike. And there's really, I mean, look, let's face it, there's probably two or three companies in the, in our space today who like, you know, who have a lot of responsibility on their shoulders when it comes to these types of security threats that the industry and the, and the, the world relies on. Um, but, but nevertheless, it's not just nation states.
There are economic actors. There's the activists, there's, there's no shortage of bad actors in the world, unfortunately. And the mess we have all over the place these days is testament to it.
Right. com, I assume, right? Yeah.
com and we have something there called the adversary universe. com, put in your business vertical, put in the geographic regions you operate in, and you'll get a custom threat landscape to see which threat actors. And you know, if it's, if it's spider, uh, that's typically, you know, ransomware or data extortion, spider is criminal, pandas, China, we've got a whole kinda, uh, global perspective.
So you can actually start to now prioritize which threats you need to defend against, because those are the ones that are coming for you. Agreed. Good stuff.
Um, you mentioned Panda, right? So going to discuss Vanguard Panda, I know you recently testified when, let's hear a little bit, kinda weave that into the whole story. Um, and, and you, you know, for those who didn't catch it, right, spider is sort of our garden variety, criminals sort of threat actors.
Panda happens to be threat actors, specifically from, from China is Bear Russia, I'm just Making it is up Bear's, Russia, kittens, Iran. We track, uh, a whole bunch of other ones. We track Columbia, we track Who about North Korea, Shaima Shaima.
In fact, Shaima is one of the, the, the more interesting ones. We just released our threat hunting report a few weeks ago, and we exposed something we call Fe Shaima, which is North Korean threat actors who are applying for job jobs. They come in, I I saw this one.
Yes. Yeah. And I didn't realize you just hired a North Well, and We, we found 150 companies hired these North Koreans.
Absolutely. I'm gonna tell you another ticking time. I know we're going off topic here, but another ticking time bomb here is how many of those people are starting to contribute to open source projects and have been contributing for the last couple years.
And all of a sudden after contributing 12, 15, 20 pieces of code, they slip in a, a malware one, right? And, and Now, well, it's the SSH one, right? That that was a, that was big one.
Long tail operation where they, How many, how, you know, there's, you know, we, we get crazy. 'cause C-N-C-F-I think has almost 180 projects they manage right now, but there's literally millions of open source projects out there, right? Well, and also supply chain attacks that we see where famous Shaima, for example, likes to put malicious payloads inside of, uh, uh, node packages that no, no node packages.
So Oh Nodes. Yeah. When the, um, when the developers come a along and they download the MPM for, you know, whatever it is, uh, there's, there's North Korean malware built into it, or, uh, yeah, No, you've seen, you're seeing this in, in container repos every, look, it's always software's built today.
We use all these repos and everything else as well. And So supply chain is a critical, That's a different interview. Supply chain is a critical, uh, thing to pay attention to is Hezbollah just, uh, figured out.
They, well, the Israelis certainly put the bomb in bu huh? Um, let, let's, I have already done interviews on that one. Let's go back to Vanguard and tell us what it's about, Adam.
Well, Vanguard Panda, I think is kind of, uh, a different beast style all in itself, because this is pre-positioning. This is what we would call operational preparation of the environment, or OPE and DOT parlance. And they have been targeting things in Asia Pacific maritime operations.
They've been targeting transportation. They've been targeting, uh, you know, here domestically in the us transportation, energy, all critical infrastructures. And they're not doing intrusion operations.
We're not seeing them doing data xFi or espionage. They're effectively gaining access and maintaining access in the, you know, potential eventuality of a conflict around Taiwan. They wanna have that access so that they can use that to then diminish our capabilities to respond if they target maritime and logistical operations in, uh, Asia Pacific and places like Guam, and they can disrupt that in time of conflict and we can't refuel or, uh, get ships, uh, supplied, that's going to make a lot of problems for the Pacific fleet.
And so this is the big concern with Vanguard Panda, and we've seen them targeting, uh, you know, recently they, they've been exploiting, uh, zero day in an Apache, uh, uh, service. Um, and we've seen them, uh, you know, taking advantage of, um, uh, you know, different, uh, things like the, um, the huge graph server. And they're using various residential proxies and things to try to, uh, make it look like they're in that region.
And then they're just maintaining the access. They're keeping it alive. They're keeping it healthy so that if something happens, they can come in and do whatever they wanna, You know, all kidding aside, we were talking about the supply chain stuff with Hezbollah and Israel and, and, you know, I make light of it in joke.
We shouldn't lose sight of the fact. A lot of people, a lot of innocent people died in that. But the more, not the more important thing.
But the thing I wanna emphasize about that is it shows you that these attacks, you know, from the time of infiltration to the time of, of payoff, if you will, can be years, months, years even. And, and this kind of thing that you're talking about here with Vanguard Panda, you know, we don't know when something's going to pop up in the, in the SPR Sea or South China Sea or whatever they want to call it over there. But we're seeing every day then take very aggressive actions against Philippine, uh, shipping and, and other countries in the area there who have all Vietnam, you know, also have claims.
And of course, Taiwan, right? Sooner, sooner or later, probably something is going to, you know, have to come to a head over there. And, and I'm not a monger for armies or death or war, but I would hope it could get solved peacefully.
But you don't wanna find out that right at the time where you gotta do something, you've been, be clawed when you, you know, you've been infiltrated and, and, and made that way. So, you know, we can't emphasize how important this is. And, and I think all hasz, lot of working to talking beeper thing is a great example.
We don't want to be in that position, and us shouldn't be. Well, you know, they say Right hope for peace, prepare for war, and, uh, yep. I think that that means that having the infos sec, uh, security solutions position to identify these things, you know, we've seen China over the course of the past several years, uh, you know, going back to 2018, we started to see that they were changing the laws.
They, they started implementing these national security laws. And some of the things that they've done, for example, are to say, if you're doing vulnerability research, you, you don't send that to Apache. You don't send that to, you know, whoever the vendor or the, the open source project is to let them know you found a vulnerability.
You send it to the CNIT sec, which is subordinate to the Ministry of State Security. That would be like here in the US saying, if you're doing vulnerability research and you find above, don't send it to the vendor, send it to cisa. And in that example, cisa subordinate to NSA or CIA.
So it, you know, they've been doing that. And that is where we've seen a massive uptick in exploitation of vulnerabilities by China targeting VPN concentrators targeting remote solutions because they can come in. And the thing about a lot of these edge security, uh, apparatuses that are being targeted, they don't run modern security software because they themselves are part of the security architecture.
And so if you get a, a exploit on a VPN concentrator, everybody's logging into it, now you can get everybody's credentials, and now you can come in and look like a legitimate user, and this is exactly what they wanna do. I remember, I, I forget how many years ago it was, but Open VP n had a, a vulnerability that, I mean, again, you can never assume your software is not free or vulnerabilities and defects, and you gotta plan as if it is and what, what your strategy is. Um, Adam, you recently testified to Congress on this stuff.
Well, I testified about the, uh, the, the CrowdStrike, uh, incident that occurred back in July. Right. But we did talk a lot about, uh, adversaries and we talked a lot about, uh, artificial intelligence as well, which is, uh, another hot topic.
So that, that's really not necessarily ai, but the point I was trying to make, or I, the point I wanted to make was, um, you know, with all due respect to our politicians and Congress and everything, and I know they, they're patriots and they have our country's interest at heart in talking to these people. Adam, do you think they get it? And, and just between you and I, no.
You know, actually everyone's watching, but, well, I think my, my job in these situations is to work with the congressional staff, work with, with the, the representatives and the senators, and help them understand it, right? I mean, they, they, they're not necessarily coming at this from a technical expertise. No, certainly not.
And the best chance that we have, as you know, kind of the technical folks in the world, is to help educate them so that they make the right decisions and that they can bring the right legislation and, and oversight to the, to the general kind of environment. Um, and so the more that we can work with them and help them understand what's happening, the better off we all are. Cool.
I mean, 'cause that, that's the thing I worry about. 'cause do what we see happening all too often it seems, is you get people like yourself, you testify, these people get, you know, worked up that they're gonna do something. And in their earnest, uh, uh, in their earnest willingness and eagerness to get something done, they kind of, you know, shoot, aim fire or fire aim.
You know, I, I don't, and it's just not what you need. And, and so I think sometimes ready Fire, a Ready, fire, aim that, Hey, you'll be my age too. I'm dead.
Um, but, but yeah. You know, that's, that's what I'm talking about it, it's, you know, and, and, and I, and again, best of intentions, I'm not saying they do this on purpose kind of thing, but you know, I think there's a certain level of technical sophistication needed to adequately address these threats. Well, uh, think of it this way, right?
It's, it's our job to help educate, but it's also, you know, there's public private partnership. We need to work with government. We work every day with CISA and law enforcement Mm-Hmm.
And different government agencies to help around the world, not just here in the us to help them understand what we're seeing from the, the vendor perspective, from the commercial perspective. Because a lot of times their mandate, their, their REIT is to protect the governments that they're, they're a part of, not to protect the commercial sector, but they need to know what's happening, right? Sure.
So having that public-private partnership working together, bringing that education and letting them understand which topics are the ones that are really critical. You know, we're going into an election cycle right now where seen, uh, you know, massive, uh, unprecedented level of foreign interference already in terms of, you know, China, in terms of Iran, in terms of Russia, in terms of all kinds of different groups that have some, you know, political or, or some sort of agenda that they're trying to affect here using cyber operations and disinformation misinformation. And as we see generative AI and, uh, large language models and stable diffusion coming in, it's really giving them, you know, it's lowering the barrier to entry for nation state threat actors and those that would conduct disinformation.
And it's giving them a really powerful tool to, to take advantage of. Yeah, there no, no doubt about it. I mean, you know, I, i, I just feel like this really started bursting on the scene in 2016, though it was going on before, and, and it's almost like, you know, in our 24 hour news cycle, it's old news and old hat, and we're kind of numb to it.
Um, but it, it's real, it, it's certainly real. And you know, I will say, in my opinion, and again, this is just one man's, one person's opinion, I think csa, especially under the Biden administration, and I'm not looking to be political here, but CSA has really stepped up. Its its game in terms of working with private industry, working with the public, working with this InfoSec industry.
Um, I have a lot of friends who were on work groups and stuff like that, that are working through since, and I think that that's been, again, best of intentions, right? And, and, but I think they've made some progress there in some of the stuff that's come out. You know, I look at some of the stuff over in Europe, they seem to need, the EU seems to wanna move quickly, and they do, but sometimes I think a little more, a little more intelligence on the ground, maybe before they just make decisions.
But in any event, it's all because we, I think we all recognize what a, what a real threat this is. Yeah. It's, it is important.
We all, we're all in this together and, you know, like what, what we've been saying is that it's us first down, and that's why we've been working closely with, just had a, a, a meeting to sit down with Microsoft a few weeks ago. Um, and ultimately, you know, there's, there's, we, we all need to kind of band together and recognize that there are hostile forces out there that are targeting us as an industry, targeting us as a, uh, you know, collective, uh, organization. You know, whether it be, uh, the United States, Europe, whoever it is.
And we need to be able to work together, share information, and orchestrate our defenses to stop bad things from happening. Absolutely. Adam, I gotta run.
We're going to need to end this. I know you have another commitment too, but you know what? Hey man, keep up the great work.
If no one's told you that, I'll tell you that. Keep up the great work. Keep doing what you do.
A lot of us depend on the, kind, on the things you and your team are doing over at CrowdStrike. So thank you very much. Thank you.
All righty. All right. All right, man.
Adam, a buyer, head of counter adversary operations at CrowdStrike. You're on Techstrong. We're gonna take a break.
We'll be back in a a minute with more tech drunk tv.