Topics: Technology
**David Moulton** (0:02)
You're listening to the CyberWire Network, powered by N2K.
**Tom Fakterman** (0:14)
Cyber attacks can really come from anywhere. Now even applications that we think are totally legitimate may be abused by an attacker to get what they want.
And that is why it is so important that we keep learning about new advances in cybersecurity and new techniques that threat actors use in attempts to gain a hold of our networks.
**David Moulton** (0:45)
Welcome to Threat Vector, the Palo Alto Networks podcast, where we discuss pressing cybersecurity threats and resilience and uncover insights into the latest industry trends. I'm your host, David Moulton, Senior Director of Thought Leadership for Unit 42
And today I'm joined by Tom Vakterman, Senior Threat Researcher and Daniel Frank, Threat Research Team Lead at Palo Alto Networks. Tom has a strong background in cyber threat intelligence, malware analysis, and network forensics, with experience spanning both private sector and Israeli military service. His work at Cyber Reason and now at Palo Alto Networks has uncovered some of the most advanced cyber espionage campaigns in recent years, ranging from attacks on telecommunication infrastructure to abusive cloud platforms in the Middle East. Daniel brings over a decade of experience in malware research and threat detection with a career that includes senior research roles at Cyber Reason, F5 Networks, RSA Security, and now Palo Alto Networks. He also holds a patent for detecting fraudulent activity from compromised devices, just one of the many ways he's contributed to building a stronger defense against sophisticated threat actors. Today, we're going to talk about a pressing and emerging risk, the abuse of software development platforms by both cyber criminals and nation-state adversaries. As development tools like IEDs, low-code platforms and public code repositories become more powerful and interconnected, attackers are finding creative ways to exploit them, often bypassing traditional detection mechanisms. This includes a recent case involving a Chinese APT group that used Visual Code Studio to deploy malware within a development environment, a campaign uncovered by our guest today. For organizations with CICD pipelines, development teams or third-party coder integrations, this episode shines a light on a growing blind spot. If attackers can exploit the very tools your developers trust every day, it's time to rethink how we secure our development infrastructure.
So Tom, set us up, why are low-code, no-code environments becoming so popular for developers?
**Tom Fakterman** (2:57)
That's a good question. So I would say that now with the rise of AI and everything, you see that a lot and more and more people don't need or want to know how to actually code to do all the stuff that they want to do in their day-to-day work. And that's exactly what low-code platforms gives the user, the ability to create sophisticated automations without needing to know how to program.
**David Moulton** (3:25)
Yeah. So it sounds like it speeds you along and it allows somebody with less skills to make something incredible quickly, but you don't have that foundational understanding, which can be a risk if you don't know what you're doing.
**Tom Fakterman** (3:36)
Exactly.
**David Moulton** (3:37)
So, Daniel, let me take it over to you. What's behind this rise and the abuse of software development platforms like VS Code, low-code environments and even code repositories?
**Daniel Frank** (3:49)
Well, for a start, we know that Threat Actors are always looking for new ways to infect users, right? They keep adapting to the current landscape. So, what we've noticed over the last year or so, that the abuse of IDEs has increased, like significantly increased, right? So, it's part of our day-to-day job, like Tom, I, and the rest of the team. So, we hunt for these instances, we try to find things that are kind of flying under the radar, like new techniques, for example. So, and about a year ago, we started noticing more and more incidents where threat actors abuse legitimate software development platforms like Visual Studio and others as well, to carry out all of these hacking operations. Now, that got us intrigued. I mean, and one of the first questions that came to our mind was, like, abusing legitimate software is not a new thing eventually, but why focus specifically on software development?
Well, there could be a number of reasons. And so, A, you want to target developers in an organization, right? And B, software development platforms usually enjoy these really high privileges within systems, and they have access to source code and other sensitive information. And above all, they're legitimate, right?
And we are seeing more and more of these attacks against technology companies and R&D of tech and also cryptocurrency firms by nation-state threat actors. And it's mostly for intellectual property and espionage, but also some threat actors are conducting these modern money heists. And the case of North Korean cyber warfare program is a perfect example for that. So as we all know, North Korea, you know, they're under these crushing international embargoes and sanctions, and they have to work really hard to bypass these limitations. Now, what we are seeing is more and more of these North Korean threat actors targeting software developers in leading Western technology and crypto organizations. And with the intention of infiltrating these institutions.
14 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID