The CyberWire · Alan Geason

Consequence of the Taliban victory for influence operations and information security. Privateering gangs described. Data exposures, data com

August 17, 2021·23 min·1 clip
Al-Qaeda celebrates the Taliban's victory as the U.S. scrambles to destroy sensitive data left behind in Afghanistan.
Host Dave Bittner opens by noting that the Taliban's victory in Afghanistan has been celebrated across extremist Islamist corners of the internet, with Al-Qaeda remnants particularly prominent in hailing the conquest as vindication. Beyond the humanitarian crisis, the episode highlights a secondary risk: the potential exposure of sensitive U.S. and Afghan government data. The U.S. embassy in Kabul ordered staff to destroy sensitive materials before the Taliban arrived, and the Washington Post reported that the U.S. likely moved or destroyed much of its data held in cloud storage. However, complete destruction is acknowledged as nearly impossible, and data shared with the now-deposed Afghan government is presumed to be in Taliban hands. An unrelated incident underscores cloud security risks: researcher Bob Dychenko found an exposed FBI-administered terrorist watchlist server on July 19, which was only taken offline on August 9 after he reported it to DHS. Analyst One, a Reston, Virginia threat intelligence firm, published findings linking Russian intelligence agencies GRU and FSB to specific ransomware and banking malware criminal groups. The research identifies code similarities between Ryuk ransomware and the SUDO espionage tool, suggesting cross-fertilization between criminal gangs and Russian intelligence. Connections are also drawn between Evil Corp and the Silverfish APT, which was implicated alongside Cozy Bear in the 2020 SolarWinds exploitation. Cybercriminal Yevgeny Bogachev, indicted in 2012 for Zeus malware, is described as having developed a new version targeting government and military entities in Ukraine, Turkey, and Georgia while living freely in Russia. Symantec's Liam Omerchu explains how ransomware evolved from small-scale attacks into a large affiliate profit-sharing model, with ransoms reaching $40 million. He details escalating extortion tactics including leak sites, executive phone calls, DDoS attacks, and leaking embarrassing personal information such as a CEO's extramarital affair. Omerchu notes that ransomware gangs have optimized their operations to encrypt only critical machines and accelerate the infection-to-payout cycle. He emphasizes that properly prepared organizations can limit damage to a small number of machines and recover without paying, though such cases rarely make the news. T-Mobile confirmed it was the target of a cyberattack but was still investigating whether customer data were compromised, with underground rumblings suggesting data may be offered for sale. Joe Kerrigan discusses the Flytrap Android malware, attributed to a Vietnam-based threat actor, which spread through Google Play Store apps disguised as coupon and soccer voting tools. The malware harvested Facebook credentials and session tokens using JavaScript injection into Android's WebView component. Zimperium researchers found the attackers' own command-and-control server had a vulnerability that exposed the entire database of stolen credentials to anyone who exploited it. Kerrigan notes that China and Iran were conspicuously absent from the list of affected countries. The episode closes with a report that nearly 6,000 current and former Colonial Pipeline employees and their family members had personal data compromised during the earlier ransomware attack.

As heard by us

A brisk CyberWire briefing on Afghanistan, exposed data, mobile malware, and ransomware's pressure-driven business model.

The CyberWire frames the Taliban victory as a security problem as much as a political one, tracking how influence operations, exposed watch-list data, and sensitive information could follow a change in power.

Read the full review in PlayNext →

Why you'd press play

If you want a rapid cyber roundup that links breaches, malware, and geopolitical fallout, start here.

Read the full recommendation in PlayNext →
Listen to the show on