The Fake Interview

The Factory: How a Lazarus-Attributed Credential Pipeline Collected Its Own Operators


Listen Later

Episode 3 focuses on the operator side of the campaign:


- why the collection pipeline did not distinguish between targets and operators;

- how operator workstations appeared in material collected by the campaign;

- how those workstations exposed social-engineering workflow, persona infrastructure, testing behavior, provisioning activity, and command structure;

- why OtterCookie should be understood as a post-access occupation tool;

- what defenders can learn from the factory model without needing access to sensitive data.


...more
View all episodesView all episodes
Download on the App Store

The Fake InterviewBy Red Asgard