Future of Threat Intelligence

ZScaler’s Brett Stone-Gross on the Tactics of the Dark Angels Ransomware Group (Black Hat Edition)


Listen Later

In our latest special episode of the Future of Threat Intelligence podcast, Brett Stone-Gross, Senior Director of Threat Intelligence at Zscaler, joins us at the Black Hat conference. He shares their uncovering of the largest ransomware payment in history — $75 million — made by a Fortune 50 company to the Dark Angels group. 

 

Brett explains the group's unique approach, which involves stealing vast amounts of data without encrypting files, and their preference for low-volume, high-impact attacks to evade media scrutiny. He also highlights essential cybersecurity measures, such as implementing two-factor authentication and adopting a zero-trust architecture to protect against such threats. 

 

Topics discussed:

  • How the Dark Angels group executed the largest ransomware payment in history, totaling $75 million.  
  • How, unlike typical ransomware attacks, the group stole data without encrypting files, exfiltrating approximately 100 terabytes of sensitive information.  
  • How their operational model is low-volume, focusing on individual companies to avoid media attention and maintain a low profile.  
  • The importance of basic IT hygiene practices, such as two-factor authentication, which are crucial for preventing significant data breaches and ransomware attacks.  
  • How implementing a zero-trust architecture can help organizations limit lateral movement and enhance overall cybersecurity defenses against threats.  
  •  

    Key Takeaways: 

    • Implement two-factor authentication to enhance security and reduce the risk of unauthorized access to sensitive corporate data.  
  • Monitor network traffic for anomalous behavior, especially large data transfers, to quickly identify potential data exfiltration attempts.  
  • Adopt a zero-trust architecture to limit lateral movement within your network and ensure users only access necessary resources.  
  • Limit user privileges, ensuring that users have only the access necessary for their roles.  
  • Stay informed about emerging ransomware trends and tactics to proactively adjust your cybersecurity strategies and defenses.   
  •  

    If you’re interested in Team Cymru’s latest research, download our “Voice of a Threat Hunter 2024” report here: https://www.team-cymru.com/voth2.0 

    ...more
    View all episodesView all episodes
    Download on the App Store

    Future of Threat IntelligenceBy Team Cymru

    • 4.5
    • 4.5
    • 4.5
    • 4.5
    • 4.5

    4.5

    11 ratings


    More shows like Future of Threat Intelligence

    View all
    Global News Podcast by BBC World Service

    Global News Podcast

    7,710 Listeners

    WSJ What’s News by The Wall Street Journal

    WSJ What’s News

    4,357 Listeners

    WSJ Tech News Briefing by The Wall Street Journal

    WSJ Tech News Briefing

    1,637 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    637 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,023 Listeners

    The Daily by The New York Times

    The Daily

    112,427 Listeners

    Click Here by Recorded Future News

    Click Here

    415 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,013 Listeners

    Talkin' About [Infosec] News, Powered by Black Hills Information Security by Black Hills Information Security

    Talkin' About [Infosec] News, Powered by Black Hills Information Security

    94 Listeners

    True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics by SPYSCAPE

    True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics

    1,963 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    137 Listeners

    Security Matters by CyberArk

    Security Matters

    22 Listeners

    Bloomberg Tech by Bloomberg

    Bloomberg Tech

    60 Listeners

    Microsoft Threat Intelligence Podcast by Microsoft

    Microsoft Threat Intelligence Podcast

    22 Listeners

    Better Offline by Cool Zone Media and iHeartPodcasts

    Better Offline

    548 Listeners