Submind YouTube summaries
Thumbnail for NorthSec 2025 - Tammy Harper - Persōna Theory: Infiltration and Deception of Emerging Threat Groups

NorthSec 2025 - Tammy Harper - Persōna Theory: Infiltration and Deception of Emerging Threat Groups

Watch on YouTube

Video summary

Tammy Harper introduces the concept of Persona Theory, originally developed by Carl Jung in 1912, as a framework for understanding how individuals create masks to interact with others and build relationships. She applies this psychological theory to the modern context of cybercrime infiltration, arguing that creating digital personas is essential for successfully penetrating emerging threat groups. The core mission in these operations requires a structured approach where operators first identify their targets, probe them, gather and verify information, and then analyze it before distributing insights. Harper emphasizes that the most effective time for infiltration occurs during the recruitment or initial offer phase, when criminal groups are actively seeking skilled affiliates and are highly receptive to cold outreach from individuals with no prior reputation. During this critical recruitment window, operators must navigate various strategies to break the ice and establish trust within these exclusive communities. Groups like Van Helsing and Anubis use sophisticated methods such as promotional videos and detailed initial offers that outline their ransomware-as-a-service platforms, payment structures, and infrastructure capabilities. Harper explains that successful infiltration often involves leveraging current events or other active groups to pivot connections, while also managing the delicate balance of communication volume to maximize information gain with minimal data exposure. She notes that these groups operate globally, often originating from regions like Indonesia or the United States rather than traditional hotspots, which necessitates that operators adjust their schedules to align with the target's time zones to avoid raising red flags about their availability and operational hours. To effectively blend in, infiltrators must master specific social engineering tactics such as transliteration, where they mimic the phonetic spelling of foreign languages to appear as native speakers, and employ techniques like love bombing, ingratiation, and conflict resolution to build deep connections. Harper details case studies where operators successfully gained access to ransomware builders by acting as mentors, offering free resources like torrent files to build trust, and carefully mirroring the communication speed and style of their targets. However, she also highlights the challenges of exiting these groups without triggering alerts, requiring a slow and gradual withdrawal that avoids referencing sensitive topics while maintaining the facade of an active participant until the infiltration is complete. The presentation concludes with a discussion on how to manipulate group hierarchies to cause internal discord and prevent successful attacks. Harper describes a scenario where an infiltrator took on a soft-skill role like public relations instead of a technical one, which eventually led to infighting among the criminal operators who questioned why someone not involved in the actual attacks was receiving a financial cut. By fostering this internal conflict and refusing to participate in the core malicious activities, the infiltrator could effectively dismantle the group's cohesion from within without needing to execute any direct offensive operations. Ultimately, the talk underscores that successful infiltration relies on patience, meticulous persona management, and the strategic use of psychological principles to turn the threat actors against each other.
Read the full video transcript
Hello everyone. So, thank you very much for being here and uh I'm very very excited to be here. Last year I told Mets Lavois that I was going to uh be speaking at NorthStech. I manifested it and I'm very happy to be uh talking here uh today in front of you. So um a little bit about myself. I'm a huge astronomy nerd. I'm a cat mom. I love photography and I'm a huge techno head. Right now I'm listening to UFO 95 and um I'm really big into that. So uh without further ado because we have a lot of content that I want to talk about. So let's talk about it. So persona theory is um not necessarily a new concept. It's a concept that um the Swiss um psychiatrist Carl Young uh created back in 1912. And this is really about understanding the true nature of uh the individual and how we walk around and interact with people. So we put a mask on our face or just on our person and basically we can interact with people that way and we can change and modify ourselves to uh better adapt and connect with people and build relationships. And this is all how we create our personas. Everybody uh socially engineers each other. Everybody creates personas. This is nothing new. Um but now how are we going to take this concept and are we going to apply it to um online and creating digital personas? So this is what we're going to be looking at today. So right now the mission is very very important when you're doing infiltration and creating these personas. You want to create uh you want to have actually a structure, a framework because without that you're just going to be talking to people and you're not going to have an objective and you're going to be spending a lot of time going down rabbit holes and you're not really going to understand where you're going with this. So the first thing you want to do is you want to be able to identify your target. You want to probe the target and then you want to gather the information, verify that information and analyze it. Now these are all very important steps and then when you analyze it you want to distribute it as well. But these are all very important steps that will give you a framework on how to do the infiltration. So the first thing we want to look at is when is it the best time to infiltrate certain groups and I think I found a really good opportunity and that is the recruitment phase or the initial offer phase. So we'll take a look at what that looks like in a second but this is really when operators are actively seeking for participants. They are uh open to interaction. They are expecting to be cold called and cold re and like cold DM'd and for people to that have no reputation to reach out to them and no validity uh to to start interacting with them. So their um uh their assessment of individuals is going to be and their receptiveness to individuals is going to be very very high. So this is the prime time to really start uh talking to people. So what that looks like is something like this. So this is from RAMP uh which is a Russian Chinese um cyber crime forum. Uh it is um exclusive. Um you have to either pay to get in or have reputation to get in. Uh you can be vouched for by other uh sister sites like XSS and exploit. Um so for example we're taking a look at three different um initial offers here. So uh we have Anubis there and then we have Van Helsing and then we have uh Kllin or Quillin. So these basically show what their RAS or ransomware as a service platform has to offer and they're like okay so we're looking for members we're looking for affiliates. We're looking for partners and this is what we want and this is what we have to offer. So this is where they're going to talk about their lockers or their encryptors and their uh infrastructure. this is how they're going to start talking about their um uh their payment structure. So this is what you're going to see like 8020 splits or 7030 splits or 9010 or 8515 splits. So that 80 or the the bigger number goes towards the affiliate and the smaller number goes to the uh operators. So this is something that um this is the recruitment phase. So everyone is expecting to be uh uh to be contacted through here. So, it's interesting because some of the groups um get really creative at how they start promoting themselves and um we're going to take a quick look at that as well. Um so, for example, there's uh Van Helsing and this is going to be there's going to be a little bit of video here, but this is an actual recruitment commercial by Vanna Helsing and this is how they uh they're doing it. Heat. Heat. So that is how ransomware operators are starting to promote themselves because getting affiliates is really really tricky. Now, um just to give you a perspective on how many people are actually involved with these uh groups, um lockbit at its peak had like 100 affiliates. Um so there's not that many affiliates per group if you really really think about it. So they're all vying for the really skilled operators, the really skilled pentesters um with scruperless morals. Um, so there's a lot of skids, uh, which is like low-level, um, like script kitties, uh, or junior pentesters that are out there, but the really talented ones that can actually like take down an enterprise, uh, those are not as, um, as uh, popular and as common. So, another group that is very very interesting is Anubis. And, uh, this is a brand new group as well. And this group is highly sophisticated and they're really trying to take um data extortion and a monetization of access and to another level. They write these journalistic and investigative um uh presentations on their leak site about their victims. They don't go for uh quantity of victims. They go for mass uh the the most harshest and um really like um like in-depth uh extortion that you can find something very similar to what Alvie was doing in the very very end of their cycle. So um let's have a look at what it it means uh when you reach out to these individuals during that phase. So this is a group called Sloglav. Um this was uh originally a group um that uh was promoted on ramp and uh so what we were trying to do is we were trying to break the ice. So now there's a concept out there called uh hi or hello and um or the no hi and no hello. So we wanted to see it's all about um how much because I the way we look at it or I look at it is how much data like in bytes and bits do I send out versus how much they can give me. So I want to send out as much data as little data as possible for the maximum return for them to send me information. So um that's how I I perceive and then you can also have the concept of like the size of bubbles which is like how much text you send versus how much text they send. So this is just to give you a balance in how much uh text and how much you're writing to people. So for example here I was telling them again this is all lies but I was saying I have experience with a smaller ransomware group uh such as blank. Now, sexy was a group that was in the news at the time that this was um we were talking and um this is also uh because we try to leverage groups or it's a good idea to leverage groups um that are sort of in the ether at the time because maybe someone's seen this and why is this sorry there we go um so basically uh we have so like uh we try to go with um different like vulnerabilities that are also there. We try to go with um uh different um like um either different groups or different vulnerabilities that are in the um uh in the news at a time. So um this is one way to do it. The other way is for example to say hey so this is another group called APT47. Now we're breaking the ice. We're trying to connect to them. Now we had a successfully gathered uh entered the group Slav and we were using that to pivot to another group to basically say hey we're part of slow which was true and then we were basically saying like we have access we can show you that we have access we're part of this group now we wanted to pivot to a more um sophisticated group so this is a 73 which is also known as bashi now and we were saying hey we have um and then fishing kits were in the news at the time so we were trying to leverage fishing kits and we were saying like, hey, we've made money, so we know because again, we have to understand that there's like an 8020 split or a 9010 split involved. We we weren't sure how much these uh their splits were yet. So, we're trying to like like hey, you can get like 20% of this 40k. So, we were trying to like give them stuff like that. We've recycled initial access um that was very popular at the time. Um so basically saying like I have initial access to this environment which is not true but uh these were just basically shared and um we're just saying like hey I'm ready to go. I have a team and I'm ready to go. Um so that's how we can break the ice there. Um perfect. So but sometimes it doesn't always work. So there was a time for example where we're trying to jump into So this was for Invader X and uh Invader X has been operating very very under the radar. Uh they've had a few confirmed uh attacks in Europe but their DLS their dedicated league site is not publicly known yet. And uh so we were trying to figure out how to get uh involved in them uh with them. So, we reached out to uh this individual who was selling the source code to invader X or at least what appeared to be the source code of Invader X. And um what we came up what was interesting was we're like hey um so we have um uh can you like can you give us access? We want to join your group. and they kept asking us for the our nickname on uh RAMP and we can't give that because then they're going to just put up like a scam alert against us uh saying like oh we're a researcher we're a fed. So we were basically saying like no I can't we're trying to pivot away from that but they just kept asking and then circling back and circling back and circling back to it. So unfortunately this was not a successful uh infiltration. So um groups are really really emerging at a rapid pace. uh is specifically in 2025, we've seen a huge explosion of them and they come in waves. So this is for 2024, but we can see that every quarter there's a huge wave of groups that come out. So like in 2025, we already seen from um from January to to May we've seen a huge explosion of new groups coming out. A lot of these not are not around anymore. Um so like MPHI is Kraken. Kraken just published something recently, but um like fake Baboo or Babuk Bjorka. JD Sex, same thing. Wero just came back. Crazy Hunter is no longer around. SEPO just posted something. Mimona got hacked by Hunter International. Uh Run Somewhere um was in the news recently. Skira still around. Van Helsing no longer around. Anubis is still around. Nightspire is still around. So they come and go so quickly. So when you want to sculpt your persona, uh you have to also take into effect that unfortunately most of us are going to be at a disadvantage because most of the stuff happens on the right side of the map versus the left side of the map. So what's interesting as well is um understanding where your thread actor, your persona should come from as well. So this is actually uh the last IP uh from geographic uh IP address metrics based on the leaked breach forums v1. So that's April 2022 to March 2023 data um that was leaked um by EMO. And so it breaks down where the IP addresses for the last uh login were from. And most of them were from Indonesia, United States, Hong Kong, uh UK, Singapore. What's really interesting is that there's no like Russia or Ukraine or any CIS or uh common independent states um uh um uh countries in there. So that's really really interesting. I think that and that fact makes me think that this data has been tampered with. Um but also like tour is at number eight which is a little surprising but again a lot of these could be VPNs. We don't know. We haven't scanned for to see what the IP listing if those were for VPNs. But it gives you an idea of like what you're going to start encountering once you start interacting with more and more cyber criminals. Um so when you want to address the hours the difference in hours it's really difficult. Well, there's only one way to do it. You have to operate on their time. So, you're going to have to wake up early. You're going to have to put in that uh effort there and and try to put some time uh talking to people at 2 a.m., 3:00 a.m., 4:00 a.m. Because or else if you're always operating on your analyst time, which is uh 9 to5 for example, you're going to show up much later in their day, like much later in the day, and that might just set up some red flags because your hours of operation are uh going to have an issue there. and they're going to trigger some red flags. So, uh that's how it's going to look like. So, you want to move your hours so that you can uh basically align with theirs better. So, another thing that we want to take a look at is the writing style, how you're going to write these uh your uh personas and how you're going to write uh when you're interacting with people. So, it really is something that you have to sometimes just write like they do, which it like means like talking like a brain dead smoothrain NPC goonu who's been online for too long. Like for real, for real, no cap. Like that's literally sometimes how you're going to have to type. And so there's another really interesting concept is and we've we're going to take a look at a case study actually uh that covers this, but this is a a concept called transliteration. And this concept is a concept that basically um individuals will write um a uh in a word in uh in for example Russian but they will write it phonetically in using English characters and um so when you read it you're reading it uh Russian but it's written in English and LLMs are not very equipped at reading understanding this is specifically when you have like uh anglicization or you have um something like um uh slang as well like cyber uh like cyber crime slang incorporated in there um like LLM's just completely collapse. So we'll take a look at a case study in in a bit for that. So when we're trying to infiltrate there's some offensive tactics that we can do to employ social engineering on these individuals and these are just like rudimentary and like basic core concepts of like social engineering. So we'll take some look at that. So there's one concept called NRE which is the weaponization of like relationship energy. So spec so especially when you start interacting with someone for the very first time and you become familiar and you start to interact with them more and more and more and you get closer and you build that connection um you can become infatuated with them. You can have this and it it could be a friendship, it could be a lover, it could be anything. And this is the type of energy that you can actually if you can remove yourself from the equation and and have someone become infatuated with you. Um this could be a mentor, this can be a friendship, it could be a lot of different things. Um it really is something that um some people can uh weaponize. Um ingratiation is another concept and this is a concept where um you can flatter people, you can give u uh gifts and you can love uh lovebomb them. So for example um when it comes to gift giving um we uh in one of the options uh in the previous slides we were talking about like initial access and breaking the ice and we offered them like free access that was a small token to uh basically break the ice and to say like here's a little gift um or flattery like hey you did a really good job I saw that you did a really good job on this uh attack and and stuff like that and love bombing depending on the on the person that you're trying to uh connect with uh is something you can do. So if the individual is looking for a girlfriend or a boyfriend or something else, you can basically use that to manipulate them. So another really really really powerful um concept for social engineering is specifically that you you can very well use um online is concept uh conflict resolution. So you can create and engineer a a small um a small conflict, blow it up. It it's really like out of proportions and you resolve it together. So you've you've and this is a good way to establish trust early on in a in a in a relationship because you've surmounted a conflict and you've built that connection together. So when you're talking to someone online and you're you're saying like oh like this is a like this is an issue this is a problem and you problem solve that together and you surmount it that will bring you closer to something. So this is definitely one of the really good ways and we can also look look at that a little later if we have time. So uh another good technique is uh called uh the chameleon effect or mimicry. So that uh effect is essentially mirroring how they talk, how they uh we which we essentially uh discussed a little earlier, but this is um their you can if you're doing it in person, you can this is like we've said like oh you mimic their body position. You if they cross their arms, you cross your arms or um the the speech pattern. Um we do this naturally when we go overseas and we start learning a new language. we will like pick up the accent and stuff like that because we want to assimilate and um basically like become part in one of uh the culture there. So this is how um we do this naturally. So it's very important to uh be cognizant of how you're um you're performing and you can basically weaponize it even further. Um so let's take an for the last couple of minutes let's take a look at some actual case studies. So uh for example this is a group called APOS and so we reached out and this whole concept here was we wanted to be a mentor to this individual. Um they were brand new to the game and they uh didn't know how uh to they had a good piece of software and it was really really uh well written based on their post on their initial offer but we wanted to gain access to their builder. So we wanted their source code, we wanted their builder, we wanted uh to see what how um their encryptors work, how their decryptors work. So we we wanted access to their builders. So we basically reached out to them and um they were struggling. So because they had uh put up their blog on notion and um they were taken down within 24 hours. So we were saying like hey don't do that. you use an onion, which again we're not going to basically tell them like hey um like how to do like um cyber crime, but we're trying to also tell them like hey like like trying to give them like super common sense answers and also trick uh answers which we'll see in a second. So like use an onion. Of course, everyone uses an onion. But uh the next thing we wanted to do was also um offer them uh a way to um download uh data. So because a lot of um groups like so it it gets really really expensive to host a ton of data. So um we were thinking of like okay so if we can get make a torrent of fake data. So what we were going to do is DD random data to the drive in uh zip that put a password on it and send out like a 600 GB file to them and uh if they were um going to uh download it from us as a torrent we were going to get some IOC's or some some indicators like for example um their IPs that they were using even if it was a seedbox even if it was a VPN like we can start accumulating that data from them and uh we can use that later. So, um, we wanted to send a massive torrent file to to this, uh, to this group and we're trying to figure out how we can do that. So, this is again free gift and we're trying to build trust and conflict resolution. We're trying to problem solve an issue together and uh, we're being very very slow with how we're responding because each uh, gray box is a different day. So, we're trying to mimic how fast they're responding as well and not just like wall dump. So, we're trying to be very meticulous in how we approach things. So in the end uh they ended up sending us uh their builder. Um we had full access. We were officially an affiliate. We had full access to their infrastructure. Uh they were basic this is how they were going to conduct their um operation at the very beginning which was very manual. This showed they didn't have a panel. This showed that they they were using an executable to create a bonded encrypter and decryptor. And this is what they were sending people. We didn't pay for this. we just basically uh were able to do this. Now, a lesson learned on this subject is if you're doing this, make sure that you're in a VM, of course, always in a VM, but you want to make sure that you have automatic uh the the ability to receive files automatically in talks. Um because the first time they sent uh this individual sent it to us, we weren't uh available and we missed the window to accept the file and that is a big no no. So, uh, make sure that it's counterintuitive, I know, but make sure that you're always ready to accept something, uh, so that you don't miss on a getting a builder like that. So, um, we ended up having this, uh, this ransomware builder. We were able to give it to the people who were interested in this and, uh, the documentation for this was extensive. I'm talking like pages and pages and pages and pages of documentation, uh, provided by the thread actor here. So then the next idea is how do we exit here and not just ghost this person. Um because that's gonna if we just like did they just were the most vulnerable at this point it's now this is the afterare where we have to like slowly pull away from them and um basically not raise any flags. So we're slowly talking them through and uh we're they were asking like we're basically going back we didn't reference the leak the the builder at all. We're going back to uh talking about um their site. They didn't do anything. Um it took them almost eight months to do an onion. So we at that point we had nothing to do with them. We were not talking anymore. So let's take a look at the uh second case. So this is where we were talking about transliteration. So for transliteration um we reached out in uh Orthodox um cerillic uh Russian and we were saying um basically are you still recruiting um and they replied back nim and uh that means uh essentially yes we are um and we are still recruiting. Um the the issue was is that we had to reply back in the same fashion and LLM and stuff like that really have a hard time struggling with a term like that because if we were like to write imagine we were to write a question mark after the first word the they sent us. This is a really good way of of checking if you are a native speaker if you're like a Russian native speaker. If you are like you say like right away with just one word and one way of writing that word they're able to like do at least a good amount of data verification. So I'm still interested and then we based and we modeled our discussions based on this. Um and then they had a copy pasted uh section at the bottom which is interesting because this section is not in transliterated uh Russian it is in cerillic Russian. So uh using the cerillic alphabets. So um you can see that this was copy pasted from something that they already had prepared and basically they're saying how many people are in your team what software did you use before if any not a secret? Why did you leave? Go away. How do you drain um how do you drain the date from the target or the data from the d target? So it's it's um basically now we're in the interview section. So we have to pass this interview and we're basically going to be talking them hey um my team is finished uh is finishing up our last target uh with the previous group we have already uh worked this weekend uh we have experience with logit fobos and babou this is before babuk 2.0 know and um we're basically saying uh there are four of us on the team. Hiring a team is always more appealing than hiring a solo uh person um because a team means you have a lot of fallbacks, you have a lot of ability and resources um but it could also lead to more drama and uh essentially we were trying to uh get uh access to this uh panel. This is the RAS panel. Now, one thing that's really um difficult about this is uh they were asking for actual uh data. So, they were saying like, "Okay, so this is how you're going to gain access to our group. You're going to give us um uh the data for your your latest victim. You're going to give us the Zoom info for that latest victim, and then we're going to validate the data, and then we're going to claim it on our on our on our panel. then we're going to give you a access to the panel, the affiliate panel to so uh we can like download encryptors and decryptors and stuff like that. Um so that was a big issue like how do we fake data from a target? So we had to pull out of of this one. Um because we can't really fake that much data unless we're using massive amounts of like uh like just creating fake documents, fake JPEGs, fake docu uh fake Excel sheets, fake PowerPoints, fake PDFs. uh it just takes a lot a lot of effort to do that. So we can basically uh do that as a next project. So that's it for today. Uh if you have any questions uh I'm available. So hierarchies is really interesting. So um depending on the position and the individual that you're targeting or the group that you're targeting um sometimes you can have infighting. So very good question. So the question was do you take advantage of hierarchy? Um so there was one group that we did infiltration for um and uh we connected directly with the um uh one of the u main like the the developer the admin the the person running it and uh we didn't want to take on a technical role because we didn't want to actually be part of their team that was red teaming but we said like we can take something that has more soft skills and we started the identifying and talking more with that individual and we're like oh we can run like public relations for you. we didn't but that was the role that we wanted to take on for them. So um when we started doing this there was quickly some divide because we weren't the ones uh taking we were still asking for a cut because of course we're going to we want to ask for a cut of the of the ransom profits but without taking it but it would be shade like it would turn up too many red flags if we weren't asking for money. And um basically um so when they were trying to conduct attacks and they were trying to like plan who how the ransom would be split um they were we would be getting a cut but then they people were saying like oh this person isn't even um like part of the attack. They're not red teaming. They're not doing the data exfiltration. They're not doing the oent on the data. They're not doing any of this. So like why is this person getting uh getting money? And then we were like well because we're doing uh public relations. and they're like, "Well, you haven't even posted about us on a single forum yet. Like, what are you doing?" So, and then you can start to like break down the group from the inside and just cause more internal fighting. Uh, that group never successfully did a single attack. We were able to uh just stay there and just like grind it out and make them fight um and um just make them like blow themselves up. So, that was a really interesting one. Uh yeah.