Episode #3
July 10, 2026
58 min 59 sec

Defenders: The Life of a Threat Researcher

Threat researchers work deep in the digital underground, mapping adversaries, exposing tactics, and turning fragments of intelligence into protection that actively stops attacks. Despite the impact of their work, the reality of what they do remains largely hidden from view.

In this episode of Masked Actors, Group-IB’s Gary Ruddell is joined by Anastasia Tikhonova, Global Threat Research Lead at Group-IB and author of the High-Tech Crime Trends report.

With over a decade spent tracking advanced persistent threat activity linked to nation-state actors, Anastasia pulls back the curtain on what it really means to operate on the front lines of cyber defence. From following evidence trails through the dark web to uncovering emerging threats before they strike, this is the inside story of the people tracking cybercriminals where they operate best: in the shadows.

By understanding who these actors are and how they operate, you can better anticipate threats and protect yourself in an increasingly hostile digital world.

Subscribe to learn more about Group-IB’s top 10 Masked Actors  – and stay one step ahead in the fight against cybercrime.

Hosts
gary-ruddell
Director, Community & Evangelism
Craig_Jones
former INTERPOL Director of Cybercrime
Guests
Anastasia Tikhonova
Global Threat Research Lead at Group-IB

Full transcript

arrow_drop_down

[00:03] Gary Ruddell: Cybercriminals are at their strongest when they remain on the scene. Shining a light on how they operate is the first step to proactively stopping attacks. But going from a single piece of evidence to a full case, and pulling back the darkness that hides the murky underworld, is a tough ask. Thankfully, cybersecurity experts aren’t deterred by getting their hands dirty. They burrow deep into the digital underground to hunt down adversaries, following evidence trails through the dark web to catch cybercriminals in the act.

Today, we’re talking about the hidden world of threat researchers. Our guest is Anastasia Tikhonova, Global Threat Research Lead at Group-IB and author of the High-Tech Crime Trends Report, the research that underpins many of the insights explored in this series. Over the last 12 years, she has tracked and analyzed advanced persistent threat activity linked to nation-state actors. Her team works at the forefront of cybercrime research, uncovering emerging trends and conducting in-depth malware analysis to help defenders stay one step ahead. Nastia, thanks for joining us.

[01:10] Anastasia Tikhonova: Thank you so much, Gary, for the introduction. It feels more valuable when somebody else describes you.

[01:20] Gary Ruddell: I know what you mean. So tell us, what made you gravitate towards a cybersecurity career?

[01:28] Anastasia Tikhonova: I would say it was part of a phase that happened to me. First of all, I started as an IT specialist, a developer, and my passion at that time was database development. I thought my career would be about making life easier for people by building applications. Then, in the last year of my university education, I was scrolling through job listings, looking for where I could be helpful, and I tried some challenges from an antivirus company.

At that time I knew something about cybersecurity from my courses, but mostly the basics: what you should or shouldn’t click, what a virus is, how it differs from a worm. That’s the baseline you get from education, nothing much deeper.

During my interview, I ended up being offered three positions in one day. Can you imagine? I was a bit confused. They first asked me about one position, and I said it sounded quite good, but I could only spend limited time because I was still studying. They said okay. Then a man opened the door and said he was looking for someone to support the company’s products. I said that sounded interesting, so I interviewed with him. Then, while I was sitting there reading documents again, a woman opened the door and said they were opening a new department and needed someone with a technical background and an understanding of threats, though it was kept a bit hidden what exactly they would be doing. I thought, wait a minute, this is another challenge for me. Someone from the HR department, sitting in the same office, said, “We have a girl sitting in the corner right now reading documents. Take her and see what she can do.”

I was a bit confused, but I ended up interviewing with the woman who became the leader of this new profession. After that I had a conversation with the CEO of the company, and that’s when I started to understand this was serious. I described everything I knew about cybersecurity at that point. They saw some potential, maybe. I couldn’t even tell you what I said at the time. But I really enjoyed discovering something new that I had never researched or even heard about. I would say it was fate.

[04:49] Gary Ruddell: Fate is certainly a good way to look at it. Three different job offers in one interview. That’s crazy.

[04:56] Anastasia Tikhonova: I wanted to give a normal answer, too. I studied for ten years, the whole time in cybersecurity. But everything I started to know at that point was practical. Through practice, I learned much more than through education. So to everyone listening to this podcast: please don’t be offended. You should still get an education. I still have a PhD, just not in cybersecurity.

[05:32] Craig Jones: You highlighted there that, back in the day, but even now, there are so many different roles within the cyber and information and communications technology world. It was the same for me in policing. When it came to us doing the cyber piece, it was a case of, “Do we want to do that? Don’t we want to do that?” And I said, “Well, I’ll have a go.” I had a forensic and digital background over my years, running and building teams, but no one was really jumping forward to do it. I thought, that sounds really interesting. That was 15 or 16 years ago now, and here I am sitting on a podcast. Who would have believed it?

[06:08] Anastasia Tikhonova: Nobody, true.

[06:11] Craig Jones: When I first got into the cybercrime world with law enforcement, it was a fairly new area for policing, certainly in the UK. We knew there were cybercriminals, and we knew they were causing harm online: network intrusions, data theft, ransomware was starting then as well. But where we were then and where we are now is a totally different space. Nastia, what was it like when you started? You’d gone into a brand-new role. How did that role develop, from there to where you are now?

[06:52] Anastasia Tikhonova: It has developed drastically. At that moment, I opened myself up to what we call the underground world, and that was intriguing. Imagine your neighborhood has a chat where people discuss what needs fixing in town or in your homes, and you go out and build something together. They do the same thing, but in the underground. They chat, describing who they will attack today, how they will withdraw money from ATMs, what solution they will use. They can even sell you that solution. It’s like a group chat, but somewhere nobody can predict where they start and where they end. I understood then that I should be there, learning from them.

I read a lot. I tried to use the same words. Think of Gen Z and Millennials: they have their own languages that separate cultures and ages. The same happens with cybercriminals. They build their own language, which isn’t tied to any era, and if you don’t understand it, you miss a lot of the stages of an attack, or where they’ll be next, or what they’ll do. So for me it was about educating myself with a new vocabulary. I went through all the forums where they communicate, how they communicate, and how they describe their work, so I could get on the same page as they were.

The other thing that helped me a lot was one investigation into a big group called Lurk. Their main goal was to obtain money from ordinary victims, people like us, not government targets. I read a lot of their closed channels: how they communicated with each other, what they would do, what illnesses they had, what they drank in the morning, where they were going next, what their girlfriends looked like, along with detailed descriptions of how exactly they worked in cyber. I thought, this is something I’d only see in a movie. But I started to touch it more and more deeply as the days went on. Craig, by the way, how was it for you when you first started investigating threats?

[09:40] Craig Jones: Same as you, we were setting up a whole brand-new team at the time, a cybercrime investigation team. All I had was my start date, the first of April, the start of the financial year. So I had to build it from scratch: what infrastructure we needed, what staff, how we’d recruit, what equipment. I borrowed with pride, I think is the best way to say it. I spoke to a lot of people who had already started doing this. I spoke to some hackers, to understand what motivated them and how they worked. And I spoke to law enforcement agencies around the world, including Europol and Interpol at the time.

We ended up with a couple of first investigations that came from the National Crime Agency, because I was working in a regional organized crime unit. One of the quick things we found was how important the research side was: having that deep level of research and working with the private sector. Once we got into investigations, the financial side became key, so I quickly brought in financial investigators, because that follow-the-money piece was phenomenal. And as cryptocurrencies came online, that changed the way we worked.

I spoke on another podcast recently about an investigation where we’d gone through the whole process and thought, let’s share this with some people. We arranged an event, and only 200 people attended. So, like yourself, you’re learning a new language and new TTPs. The team is being trained up as well. It’s quite exciting because you’re in a whole different space. Before, you’d be out following the criminals, building cases, doing witness interviews, interviewing suspects. This worked totally differently. And with some international investigations, you’d get a phone call at midnight saying, “Right, the person’s online now, we know where they are, get a team together, we’re going to arrest them.” You think, okay, off we go.

We almost built the processes in afterwards. I wouldn’t say we made it up as we went along, but for some things I had to make decisions I’d call lawfully audacious. We weren’t breaking the law, but there was no case law at the time. For example, in the UK, data is not property under the Theft Act, so we had to use the Computer Misuse Act. We had to be very careful about what we used and how we used it. We also built communities across law enforcement, the private sector, researchers, and financial investigators, and that’s still ongoing now.

[12:34] Anastasia Tikhonova: I believe more in community and in sharing data among all of them, to make this a safer space for everyone.

[12:42] Craig Jones: One of the things we say is that we’re creating communities to protect communities. From the defender side, our role is to protect. I want to protect my mum, my sister, my brother, my kids, my wife. That’s what it’s all about at the end of the day.

[13:01] Anastasia Tikhonova: True. Gary, what are your thoughts?

[13:04] Gary Ruddell: I wish the ransomware gangs out there thought like that: “Oh, I won’t hit that hospital, because my grandmother might need it next week.”

[13:12] Craig Jones: During COVID we heard that. There were a lot of attacks going on, and some groups said, “Oh no, we’re really good criminals, we wouldn’t attack a hospital.” Really? Okay, I don’t believe you. Some of the things they come out with are something else.

[13:32] Gary Ruddell: My background is in financial services: military intelligence first, then cyber within financial services. I don’t want to say financial services have it easy, because it’s obviously a very important sector. But banks have so much money to spend on good, complex IT infrastructure. I honestly don’t remember the last time a big bank got popped, a real one like Barclays, Santander, or HSBC. Even trying to log in as an employee is hard enough, never mind trying to hack in.

[14:14] Craig Jones: What we see now is scams, so it’s more the bank customers who are getting scammed. We saw a recent change in legislation in the UK about refunding fraud victims, on authorized push payment fraud, which is trying to push some of that responsibility back onto the banks, because they could do more to protect their customers. Again, it’s about finding the balance. At the end of the day, the criminals just want the money. “Show me the money.” As long as they can get it and get it out, that’s what they’re after.

Banks do make big profits, as do a lot of private-sector companies. But when someone loses their life savings, and in some countries that might be three or four thousand dollars, that’s a huge amount for anybody to lose. When that’s all you’ve got in the world and you lose it, it has a really big impact on an individual, or even a small company. We see small companies going under after ransomware attacks because they couldn’t stand up again afterwards. The harm these criminals cause in society and in business is massive. It’s real-world harm.

[15:30] Gary Ruddell: Nastia, you must have seen quite a few things across your career. Can you tell us about your career and experience so far?

[15:40] Anastasia Tikhonova: Sure. As I mentioned, I started as a normal analyst. At that point it wasn’t called threat intelligence. We were all threat researchers or threat analysts, and “intelligence” came as a term maybe five years later. I spent a lot of time investigating financial threats, mostly big groups active at the time, like Cobalt or Silence. At some point I understood there was something more beyond that. I already had enough of financial threats, and I wanted to move somewhere I could be more helpful.

I was a pusher, actually. I went to my CEO and said, “I know much more about the threats going on in the dark web. I know a lot about financial threats. Maybe there’s still something I don’t know, but I see something big going on.” He said that yes, we’re one of the top organizations that has stopped a lot of financial crime, but we know less about nation-state hackers. That was the second turning point in my career, where I drastically changed direction. I started to investigate APTs, and I built a team.

The first thing that team did is what we now call prediction, though we started doing it earlier than anybody else. To produce attacks, cybercriminals need to build infrastructure. Through specific fingerprinting, such as the tools they use or the registrar, we can tell that a specific malware will be used in the future, because we found these fingerprints through our scanning. We can alert our customers: we don’t know who they’ll attack or when, but we already see the infrastructure, so be aware that this group will attack someone in the future. And why you specifically? Because previously they attacked the same industry or the same country, or we see how they’ve changed their techniques, jumping from one victim to another. There’s a huge chance you’ll be the next victim.

We built a great team, and we changed how we present the threat itself. We decided to give more of a face to cybercriminals. It’s always some mystery: somebody is attacking me, but who? Was it a group, a person? We try to give our customers attribution: who exactly it was, why they’re doing it this way, what makes it possible for them, what the political context is between countries that explains why they attack.

My personal go-to group, and the people sitting with me on this podcast know me really well, is the North Korean hackers. I’ve said it several times, so please don’t judge me. I’m a fan. They’re technically great, and they’ve built a big ecosystem that is interesting to track. My goal to stop this threat is really somewhere inside me. I know it’s challenging, but we need to make our goals challenging, right? My challenge for the future is to find these specific hackers. I’ve built a tracking system on them, so I can see how they change their tactics.

After my financial-threat career, I had a nation-state hacker monitoring career. Then I became the technical head for the APAC region on the threat intelligence side. At Group-IB we believe in local presence with global expertise. We know about threats locally, how they attack in a specific country or region. Take the ransomware we mentioned: how attackers hit the APAC region will differ from how they hit the United States, because they’ll use different techniques, those countries use different defense measures, and the people attacking will be different affiliates. So people in the region need a threat landscape specific to it. I built a team that monitored APAC at the time. That helped me jump a little higher, and now I’m Global Research Lead. It’s about how we present our research globally, not only so customers understand what’s going on in their country and industry, but also how we spread information externally. Our readers, whether they’re C-level or an endpoint victim, should understand what’s happening, whether they should be scared right now or can postpone because they have other priorities. That’s what I’m trying to build. It might not sound like much, but I’d say it’s already a long way.

[22:02] Craig Jones: I like what you said about how we present that information. Historically, we think of hackers as hoodies, bedrooms, script kiddies: very dark, very mysterious. But you’ve just described North Korean hackers, who are state-sponsored groups with a whole country behind them. Those actors are different from script kiddies and bedroom hackers, but you still get those pictures of someone in a hoodie typing in presentations. Back in the day that was true to a degree. But with Scattered Spider, for example, you’ve got almost a hybrid model: youngsters being pulled into these groups, recruited, trained almost, and working their way up.

How we explain and predict that is the same as in policing. When a crime is committed, you arrest the person, done. Simple, isn’t it? But over the years we designed crime prevention into our communities. We spoke to the community: this is the best thing that will keep you safe from this particular group that’s breaking into houses, shops, or businesses at night. Put that in the cyber world and it’s still the same, but it’s the private sector doing a lot of that information sharing, and that comes at a cost. Governments don’t do it quite so much. We have national cybersecurity centres in a lot of countries, but they’re quite small compared with the billions spent on cybersecurity. That industry is huge and vast now. So you’ve gone from three possible jobs to doing global pieces of work on behalf of a really forward-leaning cybersecurity company, Group-IB. It’s interesting how you’ve come along that journey, and I’ve come along the police side, and you can see the crossovers.

[24:28] Gary Ruddell: What does a typical day look like for you, Nastia? Other than checking Slack and responding to emails.

[24:38] Anastasia Tikhonova: Why, you don’t like those parts? There’s a good part: in the morning, “Okay, whom should I reply to today?” I’d say I start with the news. The first thing I do is open X, formerly Twitter, to see what the community is talking about. Maybe something huge is happening and we need to be there to protect our customers and partners from the threat. I read and scroll even before my coffee, guys, even before breakfast. While I’m scrolling I make my coffee, so it’s okay.

Starting from the news, if nothing alarming is going on, we still have many resources where we obtain our data: new top threats, active groups. We try to understand the threat landscape in each region, so I dig deeper, or motivate the team to dig deeper. To be frank, from a technical perspective, not every threat I judge as huge needs a lot of time. For someone else it might. I need to separate why it’s necessary to jump on something right now and why it’s not. It’s like vulnerabilities. Zero-days happen maybe twice a quarter, and they’re still dangerous, but ordinary vulnerabilities are used day by day, and if you’re not protecting against those, that’s a problem for you. The differentiation is what matters.

For now it’s more of a manager position. I’m an influencer and motivator for what we’ll investigate, whether because an industry or a customer is interested, or because I see big potential in where a threat can go and spread. Detection and investigation come down to understanding specifically, not just “Guys, this is a big threat, we’re jumping in,” but why. The whole TTP: how the landscape is changing, where they’ll go in the future, what possibilities are opening up for the criminals.

[27:22] Gary Ruddell: Very interesting. You mentioned investigations. When you start a new investigation, how does it work? And afterwards I’d be keen to hear Craig’s side, the law enforcement side.

[27:38] Anastasia Tikhonova: There are several steps. First, I work out which questions we need to answer. We believe that cyber and fraud are no longer separate: when money moves, something is happening technically in cyber. Malware was built, infrastructure was spread. Cyber comes before the fraud. When somebody builds malware, we need to understand how it will be monetized, where it will spread, how many affiliates there are, and whether they work separately or as one big system. So I built a research group that sits together with a cyber-fraud fusion center, and we navigate the threat together.

Take Operation Rams, which Craig and I worked on not long ago. We investigated one Algerian threat actor, known as Sniper Dz, though he has several names, as we found out later. A threat intelligence team investigated where this phishing-as-a-service was offered and how it was sold. It was actually free: any affiliate could go there, obtain the phishing kits, and start spreading them. There was support for them, in different languages, Arabic and French for example, spread across different groups. We looked at how they communicated and where they built infrastructure. We answered how big the network infrastructure was, and we saw the connections and the dots. From the first time we detected it in 2024, we went back, I believe to 2018, if I remember correctly. We tracked all the dots and all the changes of names.

An investigation team worked to establish who was behind those names and how they were connected: whether they spread through social media or the dark web, how they communicated, how they changed names. The timeline shifts. For example, they supported several languages, but in 2020 they decided they didn’t need Hebrew or Spanish because there wasn’t much money in those regions. So we saw how the group changed. We normally structure everything as a report with all the evidence we have. The investigation team works closely with law enforcement: Interpol, Afripol, Europol, all of them. This specific case was on Interpol’s shoulders. We shared all the malicious infrastructure as we saw it, and all the connections of the nicknames, with Interpol. Craig, can you share a little more about what happens with the reports you receive from vendors?

[31:08] Craig Jones: Stepping back, when I started at Interpol in 2019, what we began building were regional operations desks: how could we coordinate operations across our 196 member countries? We broke that down into regions: Africa, the Middle East and North Africa, Asia, Europol already doing Europe, and Latin America for South America. The Africa desk was the first. First of all we had to get funding, because you think law enforcement could do all this, but we need funding to start building teams. We built specific teams in Africa to start with, built a framework, then replicated that model in the Middle East and North Africa region. We’d have a main coordinator sitting in Singapore who would coordinate that region and work directly with those countries.

We do it under prevention, detection, investigation, and disruption. We look at the main crime types we’re seeing, and there might be a cybercrime threat report for the region. Group-IB provided a lot of information to those Interpol reports. We work with the police and the private sector to produce a threat report that identifies the threats and what will be the highest harm and impact. In the Middle East region, we first got the teams together and onto the Interpol platforms. We have secure platforms for knowledge exchange, both non-operational and operational. The way we share data is controlled under our rules on processing data, which is really dull and boring, but it underpins all the work we do because we know what we can and can’t share. It also lets us work directly with the private sector so they can share information.

In this operation, about 13 countries were involved. I think around 200-odd individuals were arrested and over 300 suspects identified. What happens then is we take all the information, produce cyber activity reports, and give them to the member countries to act on. They work directly with the private sector. It’s not always an arrest. We might take down malicious infrastructure, using legislation in that country. If the legislation isn’t there, for example if it’s hosted by an ISP, we get it taken down under the ISP’s terms and conditions: “Hang on, this is bad stuff you’re hosting. Get it taken down.”

This was the first operation that this region carried out really successfully, building on the framework we put in place: the operational data sets, and making sure there’s a two-way flow of information. Law enforcement can be criticized, rightly or wrongly, when it works with the private sector: “We give you all this data, we don’t know what happens with it.” One of our roles at Interpol was to highlight where this is a joint approach in which we can disrupt the criminals, arrest them, and quite often get them locked up. We can also get funds back for people, or identify further potential victims who may not even know they’ve been victims, because it might be data they weren’t aware of, or their computers were taken over without their knowing. We can push all of this directly out to the countries, and that’s where the strong prevention piece comes in that Interpol can do with the private sector. But the timeline is three or four years at times for some of these operations, or for building the desks out. Once you’ve established the model, you can keep it going over the years, so long as the countries prioritize it.

[35:07] Gary Ruddell: I want to see Nastia on a ride-along, bulletproof vest, helmet, doing an arrest. I’d pay good money to see that.

[35:16] Anastasia Tikhonova: They always hide the faces of the people who do it. So even if it was me, you’d never know.

[35:26] Gary Ruddell: That’s one way to keep yourself in a job. I’m going to use the dreaded two-letter word: do you use AI in any of this process?

[35:36] Anastasia Tikhonova: Okay, let me ask the opposite question, Gary. The first time you touched AI, what did you do? Can you remember?

[35:44] Gary Ruddell: Probably when ChatGPT launched. Going into ChatGPT and asking it to summarize things, or write an email responding to this person. That’s probably all it was.

[36:01] Anastasia Tikhonova: I was first amused by AI, I guess also with ChatGPT. I visited a museum, to be frank the Rijksmuseum in Amsterdam, and I saw an older man, 65-plus, take a picture of a painting and ask ChatGPT for the whole history of it. He sat there looking at the picture and reading everything. He didn’t need a guided tour or anyone to answer his questions. He did it by himself. I thought, huh, this is how we can use AI. But what if we use it in threat intelligence, where it can be a good hand, and where it can be a bad hand?

We can use it to give short knowledge about a threat, like the ransomware or Scattered Spider we mentioned. Maybe I’m not deeply involved in the Scattered Spider investigation, but I want to understand whether it’s a real threat and what I should know about it. Our premium AI in our threat intelligence product is trained on the information we know about the groups, the dark web, everything we’ve researched. It gives a short answer with relevant information about what’s going on, where you can search for them, the main tactics they use, and what you should be aware of. That’s the first way it helps.

Another is connecting dots. When you investigate infrastructure, you can see the similarities between two domains, for example: is there the same registrar, was it used by the same person, are there previously suspicious IPs connected to it. It can do a first round of scraping for you, which is life-changing because it makes you faster at investigating. Still, I doubt AI can write whole reports predicting what will happen in the future. I’d rather reread what it writes, and imagine the future, because either the Terminator will come and attack us or something like it. Is that real? I believe it’s less real for now. But I’d like to recheck it. For first-pass scraping and search, and for giving you a first understanding of the threat, it does great. That’s why I’ll use it, for sure.

[38:47] Craig Jones: I recently used AI. I was staying with my mum, and in one of the rooms we have a lot of our great-grandfather’s belongings. He was a captain with White Star Line. I took a couple of pictures of things and interacted with the AI, and it was phenomenal, the information it pulled out. We had a family story that our ancestor died on a White Star liner in 1916. There was a fire on board, he went down to help, and a beam came down and killed him. My grandmother and her mother were waiting at the dock in Liverpool when the ship came in, and the first officer came off and said, “I’m so sorry, the captain has died on board.” The AI came up with all of that, and I was just like, wow. That was a story we’d had in our family for years.

It started me thinking: how much information is out there, and how do you analyze it? I took a picture that included HMS Guardian, one of my old ships in the Navy, with a little squadron. The AI started making a link, saying he could have been serving on HMS Guardian. No, he wasn’t. It was nothing to do with him. It made some assumptions based on the information it had, but they were incorrect. So, coming back to the human in the loop, some of that knowledge is well worth having, but you have to check it. That was my recent experience. It was quite interesting how it spoke about it and the stories it told me.

[40:30] Anastasia Tikhonova: I’m a bit famous for several APT investigations I’ve done. On the last one, I investigated an actor who called himself Cyber Saga, who was actually one of the North Korean hackers. I’m sorry, guys, of course I’ll talk about them, they’re a part of my life. What amazed me about this investigation was that we found an archive where they described all the parts of their work step by step. For example: “Today I will go and try to interview with companies to get the insider job.” They described how to build the code to get the work, what tools they use, how they speak to each other, where they send all the documents, and how they build fake, synthetic personas.

That helped us separate them from other fake workers, which is a popular topic right now. They make it an ecosystem with layers: ordinary IT workers, accountants who build the fake persona itself, send over all the access, and send the money, and bosses sitting overseas, maybe in another country, who guide them and watch how they work. They track you through the computer to see whether you do your fake work well. That’s a whole interesting level for me to investigate. It isn’t always connected to the hackers themselves, but there’s a possibility it is, because they’re in a handshake with the other part of the umbrella, the people who send the malware inside.

As Gary mentioned at the start, I was one of the authors of our High-Tech Crime Trends Report. If you haven’t read it, and don’t know what we’re expecting this year, please go back and read our reports, because I’m proud of myself: I said this would be a year of supply chain attacks. Seven months in, several times a week we hear about a new supply chain attack. This is what we predicted. We know who can do it, how they do it, and what steps you should take to protect yourself. Please look at that work if you haven’t yet.

[43:33] Gary Ruddell: And how do you get inside these groups, infiltrate these organizations and online communities?

[43:41] Anastasia Tikhonova: I call it social engineering, but you’re doing it to a person who is great at social engineering victims themselves. We try to feel like them, speak like them, communicate in the same places and at the same times. Of course, we have limitations. We would never go there and say, “I have a customer who is interested; you say you have access to some electronics company, is it this specific one?” No, that’s illegal. Guys, please don’t ask such questions. We do other things. For example: “I’m working as an initial access broker. I’m struggling with the latest tools. Maybe you have advice on how I can make it work.” Or: “I saw your response, where you describe some steps. I tried to reproduce them, but they didn’t work well for me. Can you make a step-by-step video guide?”

It depends on the situation. There are different cases where we can try to obtain more information about how exactly they work, so we can build procedures and detections, and steps to protect our customers, because we know this specific group uses these tools, or this scraping, or these kinds of vulnerabilities. In some cases we need this additional information. That’s why we hide there and try to obtain as much as possible to build better defenses. I know it’s a gray zone. Any tips for vendors on doing it better?

[45:50] Craig Jones: The vendors have a hard job, and in some ways a good job. Obviously vendors are making money, but the good ones give back. Vendors are part of Interpol’s Gateway project, where they share information and data. They’re part of the Atlas project, hosted by the World Economic Forum, where vendors sit down together, do joint research, and identify cybercriminals and infrastructure. They then share that out through channels such as Interpol. There’s quite a community out there that people are probably not aware of.

Sometimes there’s a flood of information as well. Vendors always want to stand out, and some vendors do that better than others. And the word AI comes up all the time at the moment. One of the questions I ask vendors is: what do you mean by AI? How do you use it? Where’s the benefit? How can you demonstrate clear benefits, rather than saying, “This is all AI-powered, and we have this AI SOC”? Okay, that’s really interesting, but what does it actually mean? So vendor storytelling, and being able to demonstrate credibility by supporting law enforcement or giving back to the community, is really important. And Group-IB are a company that does that time and time again.

[47:23] Gary Ruddell: It’s funny, isn’t it? The cost of controls these days. I come from the financial sector doing cyber, and they spend millions and millions on cybersecurity, intelligence, and endpoint detection across thousands, sometimes tens of thousands, of servers. Part of me wonders whether it would actually be cheaper to go back to physical money and have guns and bodyguards. If you’re going to rob a bank, you might die. At the moment, online there’s no real risk. You’re living somewhere without good law enforcement that might take action against you, or you’re operating at a low level with pseudonyms, VPNs, and proxies. It’s a very small percentage that gets prosecuted. In the physical world, if you rob a bank with a gun, the chances are maybe 50-50.

[48:24] Craig Jones: If you look at crime statistics for developed nations that heavily use digital infrastructure, I think there’s a correlation between reported physical crime going down and online crime going up. But what underpins those online crimes are inherent vulnerabilities in networks, systems, infrastructure, and software. It’s not about pointing fingers. Think about why cars are safer now: cars got faster, so brakes had to improve because we kept having accidents; we added safety features like seatbelts. A lot of this was retrofitted and evolved over many years. The cyber journey is a very small snapshot of time, the amount of bad code out there is phenomenal, and you can’t fix all of it. But you can understand what you’re deploying in your company and what your staff are using, and make sure you can protect the business. If you do get attacked, how are you resilient? What’s the business continuity plan that will get you up and running again? That’s really important.

We haven’t eliminated physical crime or online crime, realistically. There was always a thought, when cybercrime emerged, that we could fix it with technology. I think technology might be the root of it to a degree as well.

[50:05] Gary Ruddell: I think until you have to verify your identity to buy a domain, nothing will be a game changer. To open a bank account, you have to scan your passport through an app or go into a branch. Meanwhile, I can buy domain names left, right, and center. I could buy anastasiatikhonova.com today, and you could do nothing about it. It doesn’t feel right. That’s a huge gap we need to plug, because it would change the whole threat landscape.

[50:40] Craig Jones: It comes back to business process and infrastructure. Coming back to Nastia’s point about the predictiveness of cybercrime: we could predict that someone has just bought a whole range of domains. Who are they? Why have they bought them? Or they’ve set up a load of businesses in the UK, because it’s quite easy to set up a company there. Now there’s different legislation coming in. But it’s about criminal groups understanding how to run a criminal enterprise and which tools allow them to do that effectively, tools you can use in a normal business too. It’s like driving your car: you could drive it to go shopping, or you could drive it to rob a bank. One is going to be worse than the other.

[51:35] Gary Ruddell: Nastia, as Global Head of Threat Research, talk us through the process of turning intelligence fragments into something defenders can actually act on.

[51:47] Anastasia Tikhonova: All the intelligence we produce, we try to give credibility. Today I can go on the internet and say publicly, “I will attack Gary today,” and anyone can parse and repeat that, and it starts to raise a lot of alarms. But is it relevant as a threat? What’s behind this phrase? Am I a real attacker? Did I do previous attacks? If so, what did I use, what is the likelihood, and what will the kill chain be? That’s what we try to provide in all our descriptions of what’s happening on the dark web, with hacktivists, APTs, and financial threats.

First, we look at whether there are previous activities, so we can give more value to customers, partners, and everyone who reads our material. Each message from the dark web has a specific readability weight: do we believe this person is really conducting attacks or not? Each attack write-up includes recommendations: what exactly they do and where you should look to be protected. Why? Because we saw the person or group take specific steps in their TTPs. We describe it deeply, normally using the MITRE ATT&CK matrix, so you understand the initial access, the privilege escalation, and the other parts, with the specific procedures and tools used. Sometimes we go further and engage with the person doing the attack: how exactly they do their social engineering to obtain more data, or obtaining the builder of the ransomware to understand how the solution works.

Consider the difference between two alerts. One says, “I’ll attack Gary.” The other describes how the attack will likely go, why you’ll be a target, where the attackers will be in the next moments, and what you can do to find and block them before they attack. We mostly share the second kind. That’s how we work.

[54:39] Gary Ruddell: Thanks, Nastia. What do you think is next for threat intelligence? What does the future look like?

[54:44] Anastasia Tikhonova: The definition of threat intelligence is quite broad right now, but what we definitely see, as I mentioned, is that the line between cyber and fraud is blurred. We believe there shouldn’t be separate teams sitting there not communicating. We’ve seen a lot of cases in the companies we support. We say, “Can you look at this scam campaign happening right now? Our intelligence detected it.” They say, “From the threat intelligence perspective, we blocked it, that’s it.” But there may be fraud analysts who could investigate. Maybe money is already moving from victims. They’re more interested in that, so they block it from the fraud perspective. And they’re not communicating, not sharing platform access, in some cases not even sharing data. Even one simple email between teams in a company is really hard to get.

We believe the blur means they should start working together and sharing everything they obtain. It’s a whole circle: how they specifically attack and what they obtain. I think Craig has similar thoughts. What do you think?

[56:13] Craig Jones: In law enforcement we often see three silos: financial crime, cybercrime, and crimes against children. But when you look behind them, it’s about how these crimes are facilitated. What can we prioritize to prevent any of them? That’s the first point. Then detect, then investigate, then disrupt. Bring those teams closer together, and work more effectively with the private sector. I think some of this will become more automated as we move forward with AI and other things.

If we go forward 10 or 20 years, there are things like the UN Cybercrime Convention, the first such convention in over 20 years, specifically on cybercrime. How can we implement that effectively? A lot of that has to be implemented through capacity and capability building in countries, because we cooperate in a very patchwork way at the moment, with perhaps-and-perhaps-nots, and that will continue. That’s for me why organizations such as Interpol are really important, and why marrying that up with the private sector matters. The private sector works directly with law enforcement agencies, and with other partners, who might also be their competitors. Working together, you can bring down cybercrime, raise the cost for cybercriminals, and improve the safety of our communities. That’s where I see it going.

[57:51] Gary Ruddell: I love it. Nastia, that’s about all we have time for. Thanks so much for taking the time out of your evening to join us. I look forward to speaking to you again.

[58:02] Anastasia Tikhonova: Thank you so much for having me. I hope you enjoyed the podcast. If you still have questions about the role, you can follow our LinkedIn accounts, where we share interesting cases. Our blogs and reports also share exact examples of how we investigate.

[58:22] Craig Jones: Thanks, Nastia. Have a good evening. Thanks for joining us so late in your time zone. That’s the joy of these global join-ups: there’s always a time that’s late or early for someone.

[58:34] Anastasia Tikhonova: I still enjoy my work, so no problem for me.

[58:42] Gary Ruddell: Your data is valuable and it’s under attack. But for every threat actor working in the shadows, there’s someone who’s made it their life’s work to understand them and stop them. Who are these people protecting our most valuable data from falling into the wrong hands? Who are the defenders?