Beginning in 2023, a loosely organized group of teenagers and young adults shifted their focus from SIM swapping and fraud to multi-faceted extortion. Navigating corporate networks and working their way through the ransomware affiliate ecosystem, they highlighted a weakness in modern remote work environments: human verification. They talked their way into the networks of major corporations, innovatively exfiltrated critical data, and demonstrated that some audacious abuse of administrative credentials goes completely unnoticed.
This talk will examine the lasting impact UNC3944 had on cybercrime and what organizations can do to prepare for fast paced attacks that can reach any application or service of value.