**SPEAKER_1** (0:00)
This message comes from US. Bank. Simplify how you do business with Business Essentials, a powerful combination of no monthly maintenance fee checking and card payment processing. Deposit products are offered by US. Bank National Association, member FDIC.
**Erika Beras** (0:16)
This is Planet Money from NPR.
On Friday, if all goes according to plan, representatives from the US and Iran will meet in Geneva to sign another 60-day C-SPIRE agreement. But the two sides still have not come to an agreement on what's been at the heart of this war and decades of conflict, Iran's development of nuclear weapons. Right.
**Nick Fountain** (0:43)
This conflict has been on again, off again for years. And while the most recent iteration has been very violent with bombs and blockades, there is a whole other, almost entirely invisible war that the US and allies have been waging with Iran, using cyber espionage, or more accurately cyber sabotage. You know, computer viruses, malware.
Recently, we heard a story about a piece of malware that might have been used in this invisible war that was diabolically cunning. Because it exploited weaknesses in computers, yes, but also maybe in the human psyche. The more I think about it, the more I think this must have driven people insane. But it also might have saved the world from nuclear destruction.
**Erika Beras** (1:33)
We heard about this hack from someone whose job it is to identify computer hacks that could be a threat to all of us.
**Nick Fountain** (1:40)
What's your name? What do you do?
**Juan Andres Guerrero Saade** (1:42)
My name is Juan Andres Guerrero Saade, which is why everybody calls me Jags.
**Erika Beras** (1:49)
JAGS, JAGS. His initials are shorter and cooler.
**Nick Fountain** (1:53)
Yeah. Actually, he is a pretty cool guy. He's got a faux hawk, sleeves of tattoos. He was on track to go get a PhD in philosophy, but now?
**Juan Andres Guerrero Saade** (2:01)
I'm a security researcher, who I think would be the simplest term. I think some folks would say cyberpaleontologist.
**Erika Beras** (2:08)
Cyberpaleontologist. Like he digs for the remnants of cyberattacks.
The Sentinel-1, it helps big companies like Samsung and the Golden State Warriors and the government protect their computers and networks.
**Nick Fountain** (2:24)
Hacking is a whole industry, and defending against hacks is this whole other industry.
JAGS just so happens to have the raddest job of all, which is dusting off old malware files buried deep on servers and reverse engineering how hackers got into systems in the first place, and what they did when they got there.
So we can figure out how to defend against similar attacks in the future.
**Erika Beras** (2:50)
JAGS is a big deal. There are actually a couple of pieces in the International Spy Museum in DC based on his cyber-paleontology work.
**Nick Fountain** (3:01)
This is a little crude, but in the Jurassic Park movie, which paleontologist are you?
**Juan Andres Guerrero Saade** (3:07)
As long as you don't immediately default to Jeff Goldblum.
**Nick Fountain** (3:11)
I was going to go Jeff Goldblum. But I think that he is like a chaos theory mathematician.
**Juan Andres Guerrero Saade** (3:16)
Which I think fits the bill, right? What the hell do I actually know about paleontology?
**Nick Fountain** (3:21)
Right.
**Erika Beras** (3:21)
We met up with JAGS because we wanted to get a peek into the invisible war, because JAGS has made a stunning discovery of a highly specialized, highly sophisticated cyber weapon.
**Nick Fountain** (3:34)
Often, these weapons don't even get detected. If they do, it's not usually until years later, when someone like JAGS comes across an old fragment and tries to reconstruct what top secret mission the weapon was designed to carry out.
**Erika Beras** (3:48)
For JAGS, the fragment he found wasn't even a piece of code. It was just six words. It came from a leaked list of malware from the NSA.
**Nick Fountain** (3:59)
Yeah, the list came from this tool the NSA had. Meant to help NSA operators while they were hacking into some computer in enemy territory, figure out whether some other hacker was already there. And if so, whether they were friends or foes.
**Juan Andres Guerrero Saade** (4:16)
Essentially, it will run all these checks and it's gonna give the operators, it's gonna give a list of instructions of saying, hey, look, suspicious thing here. We don't know what that is.
Known malware, pull back.
**Nick Fountain** (4:29)
Like little warning signs. And this was a budding cyber-paleontologists dream.
Each piece of malware on that list had the potential to teach you so much about how the world's top hackers were getting the job done. And maybe one would turn out to be an incredibly sophisticated cyber weapon.
24 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000773027801