← All talks

Dezinformatsia: Russian Active Measures In The 2020s - Will Thomas

BSides Basingstoke35:44158 viewsPublished 2024-09Watch on YouTube ↗
Speakers
Tags
StyleTalk
Show transcript [en]

appreciate it uh yeah absolutely this is a talk that I've been putting together on some stuff that I've been interested in over the last couple years uh I I generally focus on cyber crime uh more of a cyber crime researcher and focus on ransomware and my day job and that but uh from studying you know where these cyber criminals come from and Russia and I kind of got more a little bit more interested in some of the state sponsor stuffs and the disinformation related stuff so this is more of a passion project really than some of my foral research I do for work but it's still it's all joined together it's all cyber at the end of the day right so uh yeah

so I'm going to be talking about Des infia which is Russian ESPN and Russian political Warfare basically in the 2020s um but at the end of the day let's to start off the talk let's think about what information Warfare and disinformation actually is basically you want to generate kind of a story and a narrative and put that in front of people and get them to think about it and influence their behaviors and decisions that's one of the main reasons that states and and entities actually perform these types of attacks against their adversaries right um and in today's Global landscape we have you know people from anywhere in the world small towns and cities and things are

influenced by things happening globally so you may see you know protests outside of your local Town Hall about stuff going on thousands of miles away in in Israel and Gaza or or in Ukraine or Taiwan or whatever whatever the today's topic is people are already kind of riled up and protesting about it even though it actually doesn't really impact them that much on a day-to-day basis right um but that's you know why these disinformation campaigns are so effective um and yeah at the end of the day you want to be able to influence your Target's decision- making and you put those messages out that's the main reason why they do this so let's think about the four DS of

Russian disinformation what they do is they start with by anytime something sort of accuses Russia of something or or Russian people of some or or the the oligarchs or Putin himself the first thing they're always going to do is they're going to dismiss it they're going to say no it's not true it's fake deny deny deny always works at the end of the day because they never admitted it right then they actually start to distort the truth they start to come up with alternative narratives and say well we know it's not true this is a potential reason of why something happened right kind of twist the things and want to lead people down that path

and then they start to detract from it they start to pick apart the opposition's arguments and what the opposition are trying to say uh and basically discredit them and eventually at the end of at the final step they'll start to dismay them they'll start attacking the people that are making these accusations uh in the final step this are kind of the traditional Russian and this information Playbook right um and one of you know this is a cyber security conference not a political or you know government sort of related conference so we're going to be looking at a lot of cyber event of cyber operations and how cyber security and cyber attacks kind of fit into this

whole larger broader disinformation or political campaigns um and we're going to look at the three you know three main agencies of Russia um that actually perform these kinds of things have we got anyone here today that works for one of these agencies got couple guys over there so keep keep a look out for those guys um um and then we've also got the activist groups these are kinds of groups that you may have heard of in the news maybe some of your organizations have been targeted by them or maybe you're working maybe you just like to hang out on Telegram and see the news pop up and things so uh you know these are kind of like pro- Russia patriotic

hackers in a way but most of the time they're going to be kind of state encouraged State uh you know State permitted or maybe even just directly state sponsored as well we've also got mercenaries we've kind of private companies running this kind of stuff as well companies based out of Moscow St Petersburg that you know they kind of used to be an advertising agency and now they've turned into spamming uh you know Facebook and Twitter with all sorts of fake ads and fake news articles and things as well um so the main theme of this talk is to thinking about what they're doing what Russia's been doing in the 2020s let's take a little step back and look

at what they did in the last decade um one of the main events really was 2014 the invasion of Crimea the shooting down of MH mh17 the jet over Ukraine by guu operatives you know in eastern Ukraine and the Russians trying to blame it on the ukrainians and trying to scapegoat them into something that they they did as well um and then we fast forward a little bit to 2017 you've got French election medling you've got campaigns in there trying to discredit the main the current French government and trying to push the rightwing party Marine Leen and all that um and then we actually think back uh fast for 2018 quite a lot going on quite a busy year um we had the we

had the uh saring gas attacks in Syria with you know alassad uh launching reportedly launching these you know chemical weapons against his own people and then Russia was trying to push Russia Today and all these Russian news outlets were trying to blame the UN white helmets for it and saying it was an MI6 on the cover operation or something like that um and then we also had the soas cre power poisonings in SSB down the road couple of guu guys came along and poisoned to the uh you know the the defectors that are living in the UK um and all sorts of campaigns surrounded that as well uh and then um 2019 uh a very interesting campaign kind

of started where they began to push antiva antiv vaccination conspiracy theories saying that vaccines caused all sorts of mental mental deficiencies in babies and all this kind of stuff this was even way before Co even kicked off and it was causing protests and RS and things in Ukraine um even back then so you know and then thinking about so kind of leading on to what's coming up in 2020 right we could kind of see oh this is the way things are going um the UK itself we've actually had our first share of Russian disinformation campaigns and intelligence LED you know in operations against us uh 2014 the Scottish independence referendum there was all sorts of Russian activity trying

to you know encourage people to vote to leave Scotland trying to weaken UK U that's sort of like Russ that was Russia's interest in doing that um you know up to the Scottish people at the end of the day they did it was a was a vote for them but you know the Russians were trying to encourage it for a reason right um we had the 2016 brexit referendum again they were kind of successful in that because we did actually leave the EU we had them trying to uh you know discredit uh politicians and people running the the European Union we had um all sorts of manuals and trade deals and things there quite a big

uh case of where Britain's trade deal with the US the sort of the leak a leak was made to Reddit you had you know a UK politician Jeremy Corbin sharing these leaks these are actually kind of Taken and fished from politicians and leaked to Reddit intentially by a Russian disinformation campaign so they're kind of slowly quietly influencing us without many of us realizing right it right um and coming fast forward into the 2020s what we're actually doing what they're doing today um they've been you know we had the covid-19 pandemic everyone you know we can all remember what that was like and they were all doing all sorts of things trying to discredit uh you know Western vaccines

or trying to blame the US for starting the pandemic all this kind of stuff was going on not to say that the US wasn't doing their own dis information campaigns but you know just to be good to be aware of what the adversaries are doing as well right um we had the 2020 end of 2020 was the US presidential election 2021 we had January 6th right we had all the kind of stop the steal stop the vote stop the you know just kind of discrediting democracy that again was all boosted and perpetrated by a lot of Russia link disinformation campaigns and in 2022 and 2023 obviously starting in February we had the invasion of Ukraine you they've been very much

focused and tied up in that for a long period of time um and that's where a lot of their focus has been and this year well this year it's you know it's the basically the global election cycle as well as the US U we've got the this 2024 is actually the record for the most number of democratic elections in in history really so you know we've had India we've had France so far UK you know kiss one as many of us are aware um and then we like the big one really at the end of the year is the US election so do be prepared to see a lot of ramping up of targeting intrusions big

breaches this kind of stuff going on um because it's you know it's within their interest to do so let's think let's think back to how like cyber attacks and cyber intrusions have you know supported their campaigns in the last decade in 2014 we saw a very big impactful attack targeting Ukrainian presidential election we had the actual election systems that count the votes back in 2014 was breached by the Russian intelligence and they actually tried to influence and recap the numbers and then on the day that the president was being cool they actually on on Russian media they actually named a different guy who actually won so everyone in Ukraine was confused of why the Russians were saying

that this character won when actually you know the person who actually won was different fortunately the ukrainians caught this one um but you know this is exactly the type of thing they're trying to do to democratic institutions and countries around the world right um we saw this again in 2016 they tried to go for the DNC the Democratic National uh committee uh you know the actual party that run you know the Dem so we had a breach of by the Gru and the SDR also known as FY bear and cozy bear and then we also had the breach of the world anti anti-doping agency as well so wader um this was around the same time that

Russia was about to be banned from being participating in the Olympics so they decided to basically breach that organization wad uh to basically discredit athletes from other countries as well the US and the UK had athletes had their medical records leaked as well as kind of Revenge or whatever you want to call it really just to try and they always like to do this thing where they try to level the playing field and accuse others of it you know it's like I'm like when I come back to beginning of the talk when I was talking about how they you know deny they distract the dismay all this kind of stuff that's exactly part of this Playbook and it's

the same with the when they went after the opcw you know their Ally Syria was being accused of this uh chemical weapons attack so they actually went after the investigating organization that was basically looking into this chem chemical weapon weapons attack they sto a load of documents and began to leak them and all this kind of like water Bouy whataboutism saying look at these what other these what look at what these other countries are doing it's not you know it's not so bad um and let's have a look let's think about what there so that was last decade what are they actually doing in the 2020s so far you know we're nearly halfway through we're at the sort of the

middle of 2024 right um so let's actually try and think about what they're going to do in the next 5 years as well so far they've been very very heavily focused on Ukraine they've been very focused on the US and NATO these are the kind of the three institutions that they want to basically spend most of their time targeting bringing it down um and ever since the kind of beginning of uh the war in Ukraine 2022 we've seen a lot more activism a lot more how pro-russian activist groups are getting involved with uh you know dos attacks and and all sorts of things which I'm going to get into more later um but it's been very

interesting to see see how this component has been really a big part of their you know modern day current operations a lot to do with telegram which as we know is a Russian controlled you know social media platform um another interesting thing to keep an eye on uh I've only got one slide on this really but the the Russian Russian activity in Africa many of us may kind of you know we may dismiss this as maybe we don't have too much of a focus or interest in what's going on in Africa but the Russians absolutely do um some of you may be unaware but we actually send a lot of foreign aids to Africa right uh we send you know the Us

and other Western countries we've sent up to a hundred billion US dollars in Aid and sending vaccines and things and the Russians have been absolutely discrediting that and spreading all sorts of conspiracy theories and all that that money is basically just going up in smoke because the people in the ground people in the in the continent in Africa are just not you know they basically distrust Western pharmaceutical companies not so all that money is wasted and the power of disinformation things as well um so now I'm going to talk about what all the different groups are doing you know I mentioned about Gru and the SV and the FSB I'm going to talk a little bit about what each group has

been doing just to kind of get a sense of how these operations work and and and how these different entities interact with these things um you can't teach an old worm New Tricks so sand worm is gr based apt group Advanced position threat group they've been around you know as long as cyber's been around recently uh basically they've been launching dos launching dos attacks against Georgia back in the day um but you know they're most well known for not Peter in Destroyer one and two uh the Olympic Destroyer big destructive cyber attacks that if you ever want to think about how one country May launch cyber basically launch cyber warfare this is your unit that does it um they've been very

interesting with related to participating disinformation campaigns as well as doing typical destructive U things uh they've also kind of Taken on things such as uh you know posing as Anonymous Poland or creating personas such as gu gucer 2.0 sand Worman and ap28 fancy bear kind of been working together spear fishing leaking documents and more recently they've been creating these haist telegram personas um which has been very interesting talk a bit more about those in a bit as well um the Cyber Army of Russia reborn um anyone here put your hand up have you heard of these guys one or two uh this is a really interesting one of these activist personas on telegram that I've

been talking about uh because they have been one of the groups that are launching these destructive attacks and then announcing them on telegram so for one example they were targeting the industrial control systems of water and waste management plants in the US um posting that video of them interacting with the human machine interface turning things off turning uh you turning up the temperature or whatever causing things to shut down and posting a video of them doing it and claiming responsibility for it um these aren't like huge you know cities and things you're not talking about going after New York or LA or something like that but these are these are cities and and municipalities in the

US so we're kind of seeing uh you know Gru operations posing as activists using destructive attacks on the US and claiming it publicly this is kind of a pretty big evolution of attacks right we haven't really seen this before until this year and this is a pretty interesting operation that would you know almost is kind of going to I kind of predict this is going to be the new normal we're going to see a lot more of these destructive attacks Claim by activist groups and Russia's just kind of going to be like well it's patriotic hacks we can't control them they could if they have free will can do what they want right um another example is how a

another Gru linked group was actually using cyber crime forums as a front to launch a kind of uh sort of chaos and and spread around a data leak uh on some of those forums it was kind of in conjunction with at the start of the war in January 2022 we had a load of destructive attacks that Target the Ukrainian government entities those government websites had uh defacement pages posted up on them um they were like some of them were written in Polish and Romanian and and and Russian and basically again trying to obate where the origin of it was but at the end of the day it's not too hard to figure out because uh they then went on to take

those defacements and then they created a Persona on the cyber crime Forum called ra gra forums and they were posting uh adverts to sell data they got from Le leap stuff from databases and things from Ukrainian government services and nothing else this thre actor had no history of doing anything else before they were basically an invented Persona just for this operation right definitely smells of um you know kind of state U State related activity to me um and this was kind of proven because the US Department of State put out basically a reward for justice if you have you know 5 million you get $5 million if you provide them with information about this chat called Alan

stal who is related to this campaign he's a g related threat actor who basically perpetrated this is what they say um another threat group that's been heavily targeting on the UK us and uh various institutions and universities and academics think tanks and researches and things universities so if you are you know part of one of these organizations this is definitely the type of threat act you should be worried about because they do pretty pretty basic fishing attacks but it's very highly targeted they craft these things they think about the individual they go after their personal email addresses because most of the what corporate stuff is going to be protected by an email Gateway right but it's not too hard to

figure out what the personal address in many cases is um they they often invent personas they often use like a multi-p Persona approach to go after their target where they have a conversation uh between each other in an email thread and then they bring in their target into that conversation they send them a PDF with a link a lot of times it's going to be like a for it's going to be like a conference invite so if anyone here got an email saying to come to this conference double check that make sure the uh you know the Ascender address wasn't like Ru or something um but this group what their aim is is to get into your email inbox

and then download all that data and then sometimes they use it to launching for follow-up attacks against your network of individuals your network or contact sorry uh impersonate you send emails to them eventually they get into the the ultimate Target um and then they actually will then steal that information use it for political intelligence that kind of stuff snage and in the other cases they have also used it for sort of created a league site they actually created a league site called um something like a very British coup and it was it all to do about the brexit campaign how it's failed how there was a group that was there was a group of UK politicians and and Senior

intelligence officials that wanted to hijack the government and do brexit properly or something like that it's just a classic you know kind of madeup conspiracy theory pushed by Russian disinformation campaigns as usual um Ghost Writer this is another interesting group allegedly they're part of the B Russian KGB which is interesting because bellarus has kind of become this little vassel state next to Russia and just doing everything they say um but they they are actually known for launching their own campaigns and they have actually been sort of intelligence and spnr campaigns coming out of bellus which has been pretty interesting to track and they're quite unique what they actually like to do is break into the web panels of websites

especially particularly news websites and then they will actually publish their own articles using the trust that that News website has established they mostly target like laia Lithuania and Poland um and then push sort of anti-nato anti-us kind of Articles and things and say that they're getting them to recruit people to fight in war in Ukraine or whatever um generate some of that resentment towards the West um but it's a particularly interesting campaign of how they do that right um there's there's also been examples of where B Russian TV like General the general news broadcasts will actually site the telegram Channel where the leaps are coming from from this group so you've got you've got the state

sponsored news shows citing these telegram things these telegram posts as the source so it's kind of interesting how the the intelligence Services these invented personas and these things and and the actual news organizations all working together um so coming back to Dos probably some of you have read about the news with these dos attacks quite notable ones was Microsoft and open AI Netflix Twitter they've all been dos offline for for a certain period of time um and if you actually look on Telegram and look at some of these uh claim and things you'll hear about you'll hear about how they they took down this massive company's website it's all over the news and bleeping computer and

whatever um they only did it for like you know maybe 5 10 minutes 15 minutes tops but again makes Headline News BBC is on about it it's in it's on the TV news as well um but all they did was really a small deed off the T but it's still it's not like the it's more like a it's more like kind of graffiti kind of a vandalism but it's still has the effect on the population right that there this massive Cyber attack has happened they don't really know what Cyber attack is but they still feel like they're being attacked and you know the government's doing something wrong or they the threats out there and we should

be worried that kind of stuff it's pretty interesting to look into how how this the what actually triggers these groups to launch these attacks and why what did what did that country or what did that Target do to attract the attention of these dos groups did did that company say something about Russia did they uh recently disconnect Russia from the cloud which Microsoft just did um you know some of the Microsoft was recently breached by the svr the midnight blizzard threat group you know a couple of weeks before they actually disconnected Russia Russian companies and things from M365 maybe there's a correlation there right same thing with these dos groups and things so a recent

example was uh in Romania they you know last couple of weeks these groups have begun targeting Romanian government websites portals civil services just generating General chaos for that country uh only after Romania claimed to share the the Patriot air defense missile system with Ukraine right so there's certain things that countries do that then suddenly attacks all these attracts all these DS groups to come after them um another way that you know government state sponsor groups use is that they use uh DS groups to silence the Kremlin critics they will actually uh there got these Independent Media Outlets that are pro articles written by uh you know Russian citizens and things but um but critical of of the Russian

government uh whenever they post something they suddenly get a huge wage of de do attacks attacking their website we can probably guess and figure out who's doing that but uh another interesting thing that they'll do is they will some of these websites they survive in their donations so things like patreon or or whatever um Medusa actually came out and said that their donation subscription website or the donation platform recently terminated their account because the bank said that stolen credit cards were being used to to donate to them and eventually just terminated their whole account so they're coming up with all sorts of tactics to silence people um if we think back to 2010s what were the some of the

things that they were going after they were um you know depicting Ukraine as corrupt they were basically discrediting NATO the EU all this kind of alliances and things that kind of cut Russia out of it um they you know they very much don't like that and that's the times of types of organizations they going after um doppelganger is another interesting disinformation campaign this is where uh when you actually think about more sort of traditional disinformation campaign social media bot Nets this kind of stuff and including of the generating our websites fake news articles spreading to people on social media um getting them to share it as well and getting them to believe these kind of conspiracy theories and fake

news articles um one of the ways that doppelgang was doing this was they would uh register a a domain and clone the website of trusted US News companies so you've got Guardian uh even NATO's website itself they would clone the website push sort of a fake press release and see see those get spread around as well pretty interesting tactic um pretty effective um another interesting thing to note here is that doppelganger was actually connected to a Moscow based advertising company called argon LS there's a really interesting research report out there if you want to go and figure out how they actually made those connections but again it kind of come back to my point of how these

mercenaries these private companies are getting involved in uh sort of what what the Russian government up to these days another just another example of hijacking trust we've got these fake video pretending to be from the BBC citing Belling cat as a source um everyone here heard of Belling cat at all see some heads nodding hands up um definitely anti-russian researchers that uh figure out how the Gru and how the FSB launching these kind of large broader campaigns you know the poisonings and things in Salsbury or the shooting down of mh17 they kind of figure these things out through research and connecting identities together publish these reports um and the KREM does not like that at

all um so they've kind of built up you know Among Us everyone in this room if we read something about Bing C we're generally going to believe it because we know we think those researchers are credible right so that's the kind of thing that's the kind of thing they're hijacking just to be you should all be aware of it when you're reading sort of outrageous claims and you see these claims are coming from someone what is actually has that organization actually officially said that and linked it themselves right cuz anyone could just say this guy said it but did the guy actually say it right um another interesting way that they did that was they had these Instagram and and Tik Tok

videos where they would actually there's a platform called Cameo where you can pay a celebrity you know 50 100 bucks get them to say whatever they want get them to say whatever you want and and then they record it add these kind of like captions and things to it and they share it around social media and all of it was about like anti- Ukraine zinsky super corrupt all this kind of stuff that can probably imagine but interesting tactic hijacking the kind of reputation that these F celebrities have their fans if they hear them saying it they kind of genuinely believe it right that's kind of how these things works even if it's just subconsciously as

well um very very recently I think last week the FBI Department of Justice put out this advisory with the Dutch authorities as well Dutch intelligence they actually managed to find a social media botnet that has been enhanced with ai ai is definitely you know Buzz word keyword of the year but uh this is pretty interesting how they were doing this one because what they did was they were generating soft puppet accounts forers using AI generated images AI generated text and they were getting them to reply to conversations on social media on Twitter um forly formerly Twitter now known as X but they were um replying to people replying to us politicians with sort of deep fake

videos as well so there's all sorts of ways they're leveraging defects and Ai and generation and things and they just had an entire platform to do this automatically for them they just click a few buttons these things are created and they just start spinning up their you know conspiracy theory stuff so pretty interesting pretty difficult to stop because each one imagine each one you have to try and break it down and discredit those claims and prove that they're wrong you can't really keep up with the amount of Fates that are coming out with stuff like this right um something a little bit different not 100% cyber but uh satellite signal hijacking is anyone here heard or seen had their TVs

hijacked recently to play the Russian Victory Day parades um basically in you know in May around the time of the Russian Victory Day parades and things they decided to overpower all the TV broadcasting stations and play the actual uh parades that are going on like Moscow and red square in front of the Kremlin uh decided to basically overpower the legitimate TVs uh signals and and play that instead which is pretty interesting because the way satellites satellite Communications work is Whoever has the biggest signal wins so maybe this is the kind of thing we might see in the future more this is the kind of you know if they're willing to do this against International targets outside of Ukraine

what else are they really willing to do right um you've got the French you got the Paris Olympics 2024 Paris Olympics coming up maybe this just kind of rehearsal for something they're going to pull in that who knows um you know they've been going on about how they're going to Target it and we may see something like this right so if you're involved in that be prepared is all I can say um this is a really interesting one as well is Russia's crypto thugs to hire so the way that the way that the guu has been operating recently you may have heard about uh men being arrested for aren and physical violence and things against all sorts of companies in

different countries well some researchers at The Insider managed to figure out that uh they were have actually been contacting criminals over telegram paying them 400 to 2,000 in ethereum and getting them to basically carry out attacks of violence so maybe in the cyber crime underground you've heard of like violence as a service you can pay someone $100 $1,000 to throw a brick for someone's window it's kind of like that but on a state sponsored terrorism level it's a pretty concerning Trend which we may see more of in the future because of how simple it is to scale up right anyone from country can now pay someone to do terrorist attacks for them semi anonymously right pretty

interesting scary stuff um so what actually happens in Russia this is kind of like where this talk takes a little bit of a detour from the campaigns that they're doing against the rest of the world but how do they protect themselves from those campaigns against them well you have two main organizations that kind of do that you've got roscor am I'm saying that right Ros rosc um and then you've also got the FSB as well they're kind of part of the ministry of communications and you got the Federal Security Service as well very much sort of technological organizations they monitor telecommunications they monitor social media they monitor just general internet traffic as well and the way they do that

is uh through the one of the f one of one of the things that the FSB does is they have kind of these little black boxes they go into the telecom's companies force them to install them and if they don't you know they get fined or the CEO gets arrested or something is you don't really have a choice in this kind of stuff right um and then one of the ways that Ros Ros comad does it is they issue fines they arrest people and they also push false narratives and fake press releases and go on Russia today and have an interview and just view a load of nonsense um another interesting thing is what the uh is what the law enforcement

and court systems do they actually basically Outsource some of their research to De anonymizing people to these platforms so maybe in if you work in Cy you working threaten H you may use something like recorded future or multigo there's kind of like these Russian versions of it so you've got something called Insider The Insider platform for telegram and you've got laos's demon as well and these basically are deanonymization tools they're plugged into all of the data breaches and O tools related to the Russian platforms such as uh you know you've got telegram V contact and live Journal things as well right they're pretty interesting um and sometimes you'll actually see these screenshots from these platforms appear in court

documents as well um pretty interesting to me um and how does how does Russia protect its citizens from you know foreign States and foreign disinformation Camp campaigns against them well what they've recently been doing is basically banning all Western social media in a way they created the Russian some Russian developers who used to write Wikipedia in Russian they basically split off from the official Wikipedia and created their own one called Ru Wiki um and you know basically the first thing they did was go back and censor all of the things to do with you know World War II and Stalin executing people you know all sorts of crazy stuff really and and just rewriting history and then

Banning the original uh Wikipedia um recently last week or a couple weeks ago YouTube has been uh banned as well throttled in Russia and they've created their own version uh company associated with Russia Today created their own version called platformer um and then you've also got recent B or VPN and void as well so you can no longer connect outside of Russia really and and visit the foreign website so they're basically turning into North Korea and Putin was just there in North Korea so maybe he got a few ideas right um yeah lots of interesting stuff um so what does the Kremlin say that they do this they do this to stop the spread of

misinformation they do it to stop the spread of fraud they say some of the justifications of this um and they also say to stop the spread of harmful content like such as things as drugs and seesam just kind of like typical scare mongering typical gas lighting um but the real reality that I believe you know my assessment is that it's just to monitor people to stop them thinking independently and just to keep going and keep maintaining control over the population um so in conclusion disinformation is part of Russ's broader strategy everything they do is kind of tied into it in some way remember the 4ds whenever you're about news related to Russia um and just you know think

about how effective it's being they can undermine democracies they can sway elections they can cause people to launch uh you know physical assaults and violence just by sending them cryptocurrency over telegram right um there pretty pretty dangerous times ahead uh if you're interested in learning more about some of the stuff where I got some of stuff and things I've been interested recently I've got a whole list of reports here as well just pause if anyone wants to take a picture um but yeah lots of lots of interesting stuff out there and this threat is definitely not going away and help to explain why they do some of the cyber attacks they do right thanks very much