Go back

W3LL runs dry.

30m 18s

W3LL runs dry.

The briefing covers major cybersecurity developments from April 13, 2026. Law enforcement, led by the FBI, disrupted the "W3LL" phishing ring responsible for over $20 million in fraud by seizing its domain and marketplace. In policy, the proposed 2027 U.S. federal budget would reduce civilian cybersecurity spending, potentially weakening defenses amid rising threats. Several cyber incidents were highlighted: the Handela group claimed an attack on UAE infrastructure; a phishing campaign targeted developers through Slack, linked to North Korean actors; OpenAI was affected by a supply chain attack via tainted npm packages; a critical flaw in the Maremo Python notebook was exploited within hours; hackers threatened Rockstar Games with a data leak; and Japanese firm NYK reported unauthorized access to its systems. In an interview, Justin Kohler of Specter Ops explained identity attack path management, where attackers use compromised identities to gain broader access, and tools like BloodHound help visualize and secure these paths. The business segment noted funding rounds, including $250 million for 10X AI, and acquisitions like Fortra's purchase of Zero-Point Security.

Transcription

4353 Words, 25908 Characters

English
[MUSIC] You're listening to the CyberWire network, powered by N2K. [MUSIC] Today's sponsor, Rapid7, has an irresistible invitation for you, SISOs and security practitioners out there, a free, two-day virtual summit, the subject, preemptive security. Join the Global Cybersecurity Summit on May 12 and 13 from wherever you like. A-list speakers will show you how organizations are disrupting attacks before they can blow towards your day. You'll see how exposure management, MDR and AI together let you make the decisive move. Registration is open at rapid7.britetalk.com. [MUSIC] [MUSIC] The FBI disrupts a multi-million dollar fishing ring. A North Korea link supply chain attack hits open AI. Developers face a slack fishing campaign. A critical Python notebook flaw is exploited in hours. Shiny Hunters target rockstar games. A Japanese shipping firm reports a breach. Hacking the cybersecurity winners and losers in Trump's 2027 budget. Plus a claimed cyber attack on UAE infrastructure. We got our Monday business breakdown. Our guest is Justin Kohler, Chief Product Officer at Spector Ops, discussing identity attack path management. And crack downs at home, push scam networks abroad. [MUSIC] It's Monday, April 13th, 2026. I'm Dave Bittner and this is your cyber wire in tell briefing. [MUSIC] [MUSIC] Thanks for joining us here today. It's great as always to have you with us. Happy Monday. US and Indonesian law enforcement have dismantled well, a fishing operation linked to more than $20 million in fraud worldwide. Well, we note is spelled W3LL because of course it is. Led by the FBI's Atlanta Field Office, the takedown targeted the well fishing kit, which allowed criminals to spoof login pages and steal credentials. The kit sold for about $500 through the member's only well store, active from 2019 to 2023. And investigators believe the marketplace enabled the sale of over 25,000 compromised accounts. Activity continued after the store's closure via encrypted messaging apps with more than 17,000 victims targeted between 2023 and 2025. The FBI seized the well.store domain and identified the suspected developer as GL, researchers at Group IB previously described well as a full business email compromise ecosystem, supporting attacks across the fishing kill chain. The Trump administration's proposed 2027 budget would reduce civilian federal cybersecurity spending from $12.455 billion in 2026 to $12.228 billion of decline of about $227 million with uneven impacts across agencies. The Department of Justice and State Department would see the largest increases alongside smaller gains at transportation, commerce, housing and urban development and energy. Major cuts would fall on the Department of Homeland Security, largely affecting SISA, as well as the Department of Veteran Affairs and the National Science Foundation, Health and Human Services and Treasury. Notably, cybersecurity funding for the SEC and FCC would drop to zero under the proposal. The alone could lose $707 million and hundreds of positions, raising concerns about reduced collaboration with the private sector. Experts warned that lower federal cyber investment amid rising nation state and criminal threats may increase long-term national risk and weaken public private defense partnerships. According to Iranian news sources, the Handela Hacking Group claims responsibility for a cyber attack targeting three UAE institutions, the Dubai Courts Authority, Dubai Land Authority and Dubai Roads and Transport Authority. The group says it destroyed six petabytes of data and X-Fill traded 149 terabytes of sensitive documents, causing reported disruptions across Dubai's legal and infrastructure systems. Handela framed the operation as political retaliation and warned of further action. The claims, if accurate, suggest a significant challenge to the UAE's critical infrastructure cybersecurity posture. Again, we emphasize these claims have not yet been independently verified. The open source security foundation is warning of a fishing campaign targeting software developers through the two-do group Slack workspace, attackers impersonate Linux Foundation leaders, and promote a supposed invite only artificial intelligence tool to lure victims. Pargets are redirected through a fake Google workspace style page that requests an email, access code, and installation of a malicious root certificate, enabling attackers to monitor encrypted traffic and steal data. The attack varies by platform. On Mac OS, victims are prompted to run a file called GAPI, potentially enabling full system compromise. On Windows, users are urged to trust the fake certificate. Researchers note similarities to recent campaigns against node.js developers, which Mandiant has linked to North Korean state-sponsored actors. An SSF advises developers never to install certificates from unsolicited links and to enable multi-factor authentication. OpenAI says it was affected by the recent Axios supply chain attack linked by researchers to North Korean hackers. Attackers compromised a maintainer's NPM account and briefly distributed malicious Axios packages containing a cross-platform remote access trojan. A GitHub actions workflow used in OpenAI's Mac OS app signing process executed the tainted version exposing signing materials. OpenAI believes its certificate was not compromised, but revoked and rotated it as a precaution. Researchers observed infections on at least 135 machines. Researchers began exploiting a critical vulnerability in the Maremo open source Python notebook platform within 10 hours of its disclosure. The flaw rated 9.3 by GitHub allows unauthenticated remote code execution through the exposed terminal WS WebSocket endpoint. Researchers at SISDIG observed attackers quickly validating access, conducting reconnaissance and extracting credentials from.env files and SSH-related locations in under 3 minutes. The vulnerability affects multiple versions, particularly deployments exposed on shared networks in edit mode. The attackers appeared to prioritize credential theft rather than persistence or crypto mining. Maremo released an updated version to address the issue and advised users to upgrade immediately, restrict endpoint access, monitor connections, and rotate potentially exposed secrets. Hackers claiming to be the shiny hunters group say they breached rockstar games by accessing servers hosted by a third party cloud provider and threatened to release stolen data unless paid a ransom. Rockstar confirmed that a limited amount of non-material company information was accessed, but said the incident had no impact on its operations or players. The group previously linked to breaches including ticket master claims it will publish the data after unmet demands. The incident marks Rockstar's second major cyber attack in three years following a 2023 breach tied to a lapsus member that exposed early grand theft auto-6 development footage. Japanese shipping company Nipon Yusen Kabushiki Kaisha reported unauthorized access to a marine fuel procurement system detected on March 24th, resulting in the possible ex-filtration of data, including personal information. The company isolated the affected system and suspended its use, restoring operations on March 27th. NYK notified regulators and police and launched an internal investigation. It said there's no evidence of ransomware activity, financial demands, or secondary damage linked to the incident so far. It's Monday and that means we have our business breakdown. Cybersecurity firms announced multiple funding rounds and acquisitions last week. led by 10X AI raising $250 million in series B funding to expand hiring partnerships, EMEA operations, and its artificial intelligence security operations platform. Depth first secured $80 million to grow research and enterprise adoption while Alcatraz and Link Security each raised $50 million to support expansion and product development. Additional early stage funding went to Trent AI, Huskies, and Test of Things. In mergers and acquisitions activity, Fortra acquired zero-point security to expand offensive security training capabilities while EFACS acquired priority one IT to strengthen health care sector technical services. Be sure to check out our regular business briefing which publishes Wednesday on our website its part of CyberWire Pro. Coming up after the break my conversation with Justin Kohler, Chief Product Officer at Specter Ops, we're discussing identity attack path management and crackdowns at home push scam networks abroad. Stay with us. And now a word from our sponsor, Arcova, formerly Morgan Franklin Cyber. Arcova is a global cybersecurity and AI consulting firm built by practitioners who've been in the seat. They work directly with enterprise teams to solve complex security challenges building secure by design programs that hold up as technology and threats evolve. From focused engagements to long-term partnership, Arcova delivers outcomes that endure because no one should navigate complexity alone. Learn why leading global enterprises trust Arcova at www.arcova.com that's arcova.com No, it's not your imagination. Risk and regulation really are ramping up and these days customers expect proof of security before they'll even do business. That's where Vanta comes in. Vanta automates your compliance process and brings compliance, risk and customer trust together on one AI powered platform. So whether you're getting ready for a sock to or managing an enterprise governance risk and compliance program, Vanta helps keep you secure and keeps your deals moving. Companies like ramp and riders spend 82% less time on audits with Vanta. That means less time chasing paperwork and more time focused on growth. For me it comes down to this. Over 10,000 companies from startups to large enterprises trust Vanta to help prove their security. Get started at Vanta.com/Cyber. Justin Kohler is chief product officer at Spector Ops. I recently got together with him at the RSA C-2026 conference for this sponsored industry voices interview discussing identity attack path management. I think the the interesting thing on the AI side is we are seeing what we call nation state level tradecraft come down to the masses, right? I'd you know like it's really easy for us to launch really advanced attacks. Now it's these kind of easy for a lot of people. I think the other fear of AI is not just launching super advanced attacks but a lot of mediocre attacks and just starting a fire over here so that people you know get distracted. The reason why that's relevant to us in bloodhound is you're not going to really be able to keep up with this from a detection and response scenario. I mean maybe you can throw another AI agent and have them get into a race condition and race each other but from our perspective you need to shut the door. You need to shut down the opportunity because I think people know nobody today wants to look at another alert they want to make the problem go away. Well thanks for joining us once again here we are on the floor at RSA C-2026 and it is my pleasure to be joined by Justin Kohler. He is the chief product officer at Spector Ops Justin. Thanks so much for joining us. Yeah pleasure to be here just to the home of the halls is you know getting over it. Before we dig in House the show been for you so far. Awesome it's been a blur. I'm really excited but yeah it's crazier every year. Absolutely. I wanted to dig into some of the things that I've been hearing coming out of Spector Ops this week and recently this whole idea of identity attack path management I want to make sure I get that right. Can we dig into that? What is that and why does it matter? Yeah so we kind of realized that we were doing this for the last decade and then we put a name to it. So if you don't know Spector Ops we got our history started with penetration testing and red teaming and the way that we would accomplish our objective we start we stop throwing exploits and just taking over boxes we usually took out took over an identity and historically that was an act of directory because that's where people had their identities but as organizations have evolved their identities and more hybrid environments so like it could be enter ID or AWS or GitHub or you name it there's identities everywhere and if we can take control over those identities not only can we operate as them but we can hide under the radar if that makes any sense so we just use your permissions against you and that's what we mean by an identity attack path. Basically how can I turn my initial access victim so you might click on the wrong link or whatever could be a non-human identity we take over from a repo and then turn that into more and more access and importantly it's not about the initial identity we take over it's about how I can cascade that into like control over my account at least to control a rear account leads to a control over an admin account and then I can do whatever I want so that's what an identity attack path is. Help me can we dig into some of the details of how that plays out in the real world. Can you walk me through if if I start out with I don't know I purchased something from an initial access broker or something to get into a system. Yep. What's my plan then for lateral movement through someone's organization? Yeah so you read about it a lot I mean there was a really cool story about from Google two weeks ago now where they had some initial access into a GitHub repository and through chaining permissions and GitHub they were actually able to take over the CICD pipeline and AWS and then route it through AWS to take over the AWS account and all the S3 so basically like and you see that more and more I mean fishing is getting better but also fishing controls are getting better so now it's like you mentioned like initial access brokers you just need somebody to like set the beacon early or or or give you a way in and then we just route through all the controls I'll give you an example from from way back when in active directory if you land an active directory and if you ask the directory for all the information it just gives you all that information that's how it functions that's why we like these attack paths are so hard because you can't patch them out like there's nothing to patch this is how the system functions so we get basically we get the the the map of your environment by just asking the question and it's just a matter of time of routing through all those misconfigurations you put in over the last 20 years and it's not just active directory I mean it's every cloud system they're so complex and nobody can make sense of this in their head at least not without visualizing that's where bloodhound comes in that's probably like the most popular way that people understand attack paths I mean it's used in 95% of penetration tests and bloodhound enterprises now you know helping enterprise customers handle that at scale let's talk about bloodhound yeah how does that come into play yeah people are using it in regard to open graph yeah yeah so bloodhound actually so again a little bit history here we created bloodhound because we were just penetration testers and red teamers and we we wanted a faster way of doing our job and instead of storing all these you know this cascading permissions and identities instead of storing at all in Excel we just threw it in a graph database and created bloodhound so we basically created Google Maps for attacking an organization and then that was awesome but then we created another problem and it's like well now we can find all these attack paths what can we do to shut them down it's like well we just break things we don't know how to do that so then we worked for like four or five years to figure out we would solve that problem bloodhound enterprise kind of flips that on its head and says okay forget about all these attack paths let's focus on your most critical assets understand all the paths that could lead to them and it's shut them down one by one so think of it like I'm gonna wall off a city I understand all the roads that will go into that city I'm just gonna walk them off and that and that sounds potentially esoteric and bad but what that really is doing is just separating your unprivileged identities from your privilege identities so it's basically just giving you the visibility to do the thing that we've been saying we should do for 20 years you know people have said like Active Directory should have shipped with bloodhound I think any identity system should ship with bloodhound open graph is our pivot not not a pivot but just a an opening of the aperture so we used to be always focused in Active Directory and enter ID in a Microsoft centric world which is good because you know again that's kind of where everybody started but we have AWS we have GCP so last week we announced our first open graph extensions for new bloodhound enterprise with Jamf Octa and GitHub so it's really interesting we'd be and attacking those systems for years, and now we can show everybody what we see when we land on the inside. So. >> When you save visibility, what are we talking about? What are the customers get to see? >> So you, let's say as an admin, as an identity team, or as a security professional, there's all these configurations that you're making, right? And in isolation, maybe they look benign. So think of like a user access request. I need access to this resource. Cool, here you go. And then more and then more and then more. We show you the culmination of that. So you didn't realize that that permission you granted four years ago to this help desk user, or whatever, actually ends up connecting every local alleged identity in your environment to take over the entire environment. I mean, it's a bunch of cascading. It's like the domino meme. It's like you start this thing and then you take over the organization. That's exactly what we're showing. So it can be really eye-opening for people. I actually had this funny blog post that I created when we first launched the product. It was, is everybody this bad? 'Cause I kept getting that question. 'Cause they would deploy and they'd be like, "Oh my gosh." "Oh, I see, sure." And I was like, "Tilly's telling me it's not just us." Yeah, and I was like, "Yes, it is." And that's why I think a lot of security. I mean, let's pick on, not pick on the C-SOS, but give them some credit to their fear. They're like, we're living in fear of getting punched in the face. So it's just a matter of time. And I don't know where it's gonna come from. And I can answer that question. I can map your next breach. I can show you exactly how it's happening. And then I can show you how to fix it more importantly. So, and the numbers are against us. I mean, the attack paths are usually measured in the millions, if not billions. But the good thing is, again, the different approach we have is if you're focusing on your critical assets, we're really only talking about maybe 10 to 12 different roads in. And so you can shut off millions of attack paths if you know where to focus. So we're here at RSA C-2026, which means we would be-- AI. [LAUGHTER] You saw me coming from a mile ago. Yeah, yeah. Oh, yeah. Yeah. So? Yeah. So we see AI in a couple of different ways as spectraops and it blow down. So number one, AI has to use identity in some form or fashion. So it's either going to be provisioned a specific identity that it uses for its role or it's going to assume the user's identity to accomplish the objective. The cool thing here is we have that mapped already. So if you're provisioning identity, we do not discern between AI identity or user identity. They are all just identities to us. So if we can use an AI identity or a non-human identity or a user identity to attack the organization, we're going to show you the same thing. I think the interesting thing on the AI side is we are seeing what we call nation-state level trade craft come down to the masses. It's really easy for us to launch really advanced attacks. Now it's kind of easy for a lot of people. I think the other fear of AI is not just launching super advanced attacks, but a lot of mediocre attacks and just starting a fire over here so that people get distracted. I mean, maybe you can throw another AI agent and have them get no race condition and race each other. But from our perspective, you need to shut the door. You need to shut down the opportunity because I think nobody today wants to look at another alert. They want to make the problem go away. And that's where we can help a lot of people invent throwing a lot of detection focused workflows on this problem, but it's saddling too much of the burden. We need to remove it and make detection more effective, if that makes any sense. How does the background of your organization, your pedigree, the history of, as you say, pen testing? Yeah. How does that give you all a unique view, a unique lens on all of these problems? I would say we're very lucky in that sense. I mean, we work with a lot of very large, very interesting organizations, we're the red team for OpenAI and Palantir. So we get exposed to a lot of different new problems. And I think that's the way that we think as a company. We don't think, like, we don't think as a product company trying to create a product to sell a product. We were like, we're attacking organizations and we're getting in every time. How can we stop ourselves? So, because everybody was asking that. Yeah, it's like, I mean, it's frustrating. I mean, to a certain extent, we almost felt like we were doing our clients a disservice. We'd come in and kick them in the face. And then, you know, the next year, we'd come in and kick them in the face again. And it's like, well, this isn't helping you. Let's, how can we actually help you solve this problem? And so that's why we created a product enterprise. Well, Justin Collar is Chief Product Officer at SpectorOps. Justin, thanks so much for joining us. Thank you. There's a lot more to this conversation than we have time to share here. So please check out the full unedited interview. You can find a link to that in our show notes. (upbeat music) Most environments trust far more than they should and attackers know it. Threat locker solves that by enforcing default and eye at the point of execution. With Threat locker allow listing, you stop unknown executables cold. With ring fencing, you control how trusted applications behave. And with Threat locker DAC, defense against configurations, you get real assurance that your environment is free of misconfigurations and clear visibility into whether you meet compliant standards. Threat locker is the simplest way to enforce zero trust principles without the operational pain. It's powerful protection that gives CISO's real visibility, real control, and real peace of mind. Threat locker makes zero trust attainable, even for small security teams. CY thousands of organizations choose Threat locker to minimize alert fatigue, stop ransomware at the source, and regain control over their environments. Schedule your demo at Threat locker.com/N2K today. (upbeat music) When it comes to mobile application security, good enough is a risk. A recent survey shows that 72% of organizations reported at least one mobile application security incident last year, and 92% of responders reported Threat levels have increased in the past two years. Guard Square delivers the highest level of security for your mobile apps without compromising performance, time to market, or user experience. Discover How Guard Square provides industry leading security for your Android and iOS apps at www.guardsquare.com. (upbeat music) And finally, in a piece for wired, Lily Hay Newman reports that governments keep trying to shut down industrial-scale scam compounds across Southeast Asia, but the operations often linked to Chinese organized crime and forced labor continue to thrive with stubborn efficiency. The FBI says Americans alone reported $17.7 billion in cyber-enabled scam losses last year, likely an undercount. US officials argue a key obstacle is uneven cooperation from China, which has cracked down on scams, targeting its own citizens, while foreign victims remain fair game. Researchers say that approach has quietly encouraged syndicates to pivot toward Americans and other international targets. Meanwhile, the United Nations notes scam centers are expanding their multilingual workforces to match their global ambitions. Analysts compare the dynamic to squeezing a balloon. Pressure in one place simply bulges elsewhere. The result is a familiar pattern in cyber crime diplomacy. Everyone agrees scams are bad, just preferably someone else's problem first. (upbeat music) And that's the cyber wire for links to all of today's stories. Check out our daily briefing at the cyberwire.com. Don't forget to check out the Grumpy Old Geeks Podcast where I contribute to a regular segment on Jason and Brian's show every week. You can find Grumpy Old Geeks where all the fine podcasts are listed. We'd love to know what do you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cyber security. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to [email protected]. N2K's lead producer is Liz Stokes, were mixed by Tray Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazis. Our executive producer is Jennifer Ibn, Peter Kilpia's our publisher and I'm Dave Vittner. Thanks for listening. We'll see you back here tomorrow. (upbeat music) (upbeat music) (upbeat music)

Podcast Summary

Key Points:

  1. The FBI dismantled the "W3LL" phishing operation linked to over $20 million in fraud, seizing its domain and disrupting a credential-stealing kit.
  2. A proposed U.S. federal budget for 2027 would cut civilian cybersecurity funding, raising concerns about national risk and public-private defense partnerships.
  3. Multiple cyber incidents were reported
  4. Justin Kohler of Specter Ops discussed identity attack path management, emphasizing how attackers leverage identity permissions for lateral movement and the role of tools like BloodHound in visualizing and mitigating these paths.
  5. Recent cybersecurity business activity included significant funding rounds for firms like 10X AI and Depth First, and acquisitions such as Fortra's purchase of Zero-Point Security.

Summary:

The briefing covers major cybersecurity developments from April 13, 2026. Law enforcement, led by the FBI, disrupted the "W3LL" phishing ring responsible for over $20 million in fraud by seizing its domain and marketplace. S.

federal budget would reduce civilian cybersecurity spending, potentially weakening defenses amid rising threats. Several cyber incidents were highlighted: the Handela group claimed an attack on UAE infrastructure; a phishing campaign targeted developers through Slack, linked to North Korean actors; OpenAI was affected by a supply chain attack via tainted npm packages; a critical flaw in the Maremo Python notebook was exploited within hours; hackers threatened Rockstar Games with a data leak; and Japanese firm NYK reported unauthorized access to its systems. In an interview, Justin Kohler of Specter Ops explained identity attack path management, where attackers use compromised identities to gain broader access, and tools like BloodHound help visualize and secure these paths.

The business segment noted funding rounds, including $250 million for 10X AI, and acquisitions like Fortra's purchase of Zero-Point Security.

FAQs

The FBI, along with Indonesian law enforcement, dismantled the W3LL phishing operation, which was linked to over $20 million in fraud worldwide. They seized the w3ll.store domain and identified the suspected developer, disrupting a kit that allowed criminals to spoof login pages and steal credentials.

The proposed 2027 budget would reduce civilian federal cybersecurity spending by about $227 million, with uneven impacts across agencies. Major cuts would affect the Department of Homeland Security, while funding for the SEC and FCC would drop to zero, raising concerns about reduced collaboration with the private sector.

The Handela Hacking Group claims responsibility for a cyber attack targeting three UAE institutions, allegedly destroying six petabytes of data and exfiltrating 149 terabytes of sensitive documents. These claims, if accurate, suggest a significant challenge to the UAE's critical infrastructure cybersecurity, though they have not been independently verified.

A phishing campaign targets software developers through the TODO Group Slack workspace, where attackers impersonate Linux Foundation leaders to promote a fake AI tool. Victims are redirected to a malicious page that requests email, access code, and installation of a root certificate, enabling traffic monitoring and data theft, with similarities to North Korean-linked campaigns.

OpenAI was affected by the Axios supply chain attack linked to North Korean hackers, where malicious packages contained a remote access trojan. A GitHub Actions workflow in OpenAI's macOS app signing process executed the tainted version, but OpenAI believes its certificate was not compromised and revoked it as a precaution.

A critical vulnerability in the Maremo open-source Python notebook platform, rated 9.3, allows unauthenticated remote code execution via an exposed WebSocket endpoint. Attackers exploited it within 10 hours of disclosure, focusing on credential theft, and Maremo released an update advising users to upgrade and restrict access.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.