Security Conversations
237
Security Conversations
08.17.2026 | 2:23''31'
A tiny 12 KB Windows backdoor, one victim, and a dead domain
About the episode
(Presented by State of Statecraft: A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors.)
Three Buddy Problem – Episode 109: The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Costin explains why a stack of ransomware takedown cases has been sitting on a shelf waiting for exactly this.
Plus, a tiny 12 KB Windows backdoor found on one machine with a dead C2, the mercenary outfits quietly living inside telcos, and why Google continues to flounder in the race for AI dominance.
Cast: Costin Raiu, Ryan Naraine and Juan Andres Guerrero-Saade
Timestamps:
0:00 Introductory banter
0:58 State of Statecraft, and a late CFP window
3:24 The White House offensive hacking memo
6:37 “Hack back” is the wrong frame for what’s being authorized
11:20 Ransomware cases sitting on the shelf
17:01 The million-dollar bond and who can realistically play
22:29 Where DPRK crypto theft falls under the new definitions
28:15 Would TLP Black take a contract?
36:55 Gen Digital’s 12 KB backdoor hiding its C2 in desktop.ini whitespace
46:57 Passive DNS, registration patterns, and pivoting on a dead domain
57:32 Feeding a one-off find back into detection engineering
1:02:14 Metador, Mafalda, and the mercenaries who love telcos
1:17:07 Armored Likho and what “Western APT” really means
1:28:16 The IOC market, private reporting, and CTI’s matching problem
1:58:10 Google’s culture problem, the weekly model churn, and Patch Tuesday math
Links:
- Transcript
- White House memo on private sector offensive operations
- Trump admin wants to allow companies to hack cybercriminals
- Custom Windows backdoor found on a single corporate machine
- New Armored Likho tools target Telegram and eavesdropping
- Multi-Agent AI Framework Used to Compromise Government Entities in Asia
- Anthropic Risk Report – August 2026
- The Metador Enigma: Unveiling an Unattributed Threat
- Report | The Mystery of Metador
- Armored Likho’s new weapon: BusySnake Stealer
- How We Caught Lazarus’s IT Workers Scheme Live on Camera
- Behind the exit of Google’s DeepMind CEO
- US to tell partners they must pick sides in AI race with China
- Microsoft Patch Tuesday 422 CVEs
- CVE Attribution & MSRC Reporting Dashboard
- State of Statecraft (Brussels)