NorthSec 2025 - Tammy Harper - Persōna Theory: Infiltration and Deception of Emerging Threat Groups
Watch on YouTubeVideo summary
Tammy Harper introduces the concept of Persona Theory, originally developed by Carl Jung in 1912, as a framework for understanding how individuals create masks to interact with others and build relationships. She applies this psychological theory to the modern context of cybercrime infiltration, arguing that creating digital personas is essential for successfully penetrating emerging threat groups. The core mission in these operations requires a structured approach where operators first identify their targets, probe them, gather and verify information, and then analyze it before distributing insights. Harper emphasizes that the most effective time for infiltration occurs during the recruitment or initial offer phase, when criminal groups are actively seeking skilled affiliates and are highly receptive to cold outreach from individuals with no prior reputation.
During this critical recruitment window, operators must navigate various strategies to break the ice and establish trust within these exclusive communities. Groups like Van Helsing and Anubis use sophisticated methods such as promotional videos and detailed initial offers that outline their ransomware-as-a-service platforms, payment structures, and infrastructure capabilities. Harper explains that successful infiltration often involves leveraging current events or other active groups to pivot connections, while also managing the delicate balance of communication volume to maximize information gain with minimal data exposure. She notes that these groups operate globally, often originating from regions like Indonesia or the United States rather than traditional hotspots, which necessitates that operators adjust their schedules to align with the target's time zones to avoid raising red flags about their availability and operational hours.
To effectively blend in, infiltrators must master specific social engineering tactics such as transliteration, where they mimic the phonetic spelling of foreign languages to appear as native speakers, and employ techniques like love bombing, ingratiation, and conflict resolution to build deep connections. Harper details case studies where operators successfully gained access to ransomware builders by acting as mentors, offering free resources like torrent files to build trust, and carefully mirroring the communication speed and style of their targets. However, she also highlights the challenges of exiting these groups without triggering alerts, requiring a slow and gradual withdrawal that avoids referencing sensitive topics while maintaining the facade of an active participant until the infiltration is complete.
The presentation concludes with a discussion on how to manipulate group hierarchies to cause internal discord and prevent successful attacks. Harper describes a scenario where an infiltrator took on a soft-skill role like public relations instead of a technical one, which eventually led to infighting among the criminal operators who questioned why someone not involved in the actual attacks was receiving a financial cut. By fostering this internal conflict and refusing to participate in the core malicious activities, the infiltrator could effectively dismantle the group's cohesion from within without needing to execute any direct offensive operations. Ultimately, the talk underscores that successful infiltration relies on patience, meticulous persona management, and the strategic use of psychological principles to turn the threat actors against each other.
Read the full video transcript
Hello everyone. So, thank you very much
for being here and uh I'm very very
excited to be here. Last year I told
Mets Lavois that I was going to uh be
speaking at NorthStech. I manifested it
and I'm very happy to be uh talking here
uh today in front of you. So um a little
bit about myself. I'm a huge astronomy
nerd. I'm a cat mom. I love photography
and I'm a huge techno head. Right now
I'm listening to UFO 95 and um I'm
really big into that. So uh without
further ado because we have a lot of
content that I want to talk about. So
let's talk about it. So persona theory
is um not necessarily a new concept.
It's a concept that um the Swiss um
psychiatrist Carl Young uh created back
in 1912. And this is really about
understanding the true nature of uh the
individual and how we walk around and
interact with people. So we put a mask
on our face or just on our person and
basically we can interact with people
that way and we can change and modify
ourselves to uh better adapt and connect
with people and build relationships. And
this is all how we create our personas.
Everybody uh socially engineers each
other. Everybody creates personas. This
is nothing new. Um but now how are we
going to take this concept and are we
going to apply it to um online and
creating digital personas? So this is
what we're going to be looking at today.
So right now the mission is very very
important when you're doing infiltration
and creating these personas. You want to
create uh you want to have actually a
structure, a framework because without
that you're just going to be talking to
people and you're not going to have an
objective and you're going to be
spending a lot of time going down rabbit
holes and you're not really going to
understand where you're going with this.
So the first thing you want to do is you
want to be able to identify your target.
You want to probe the target and then
you want to gather the information,
verify that information and analyze it.
Now these are all very important steps
and then when you analyze it you want to
distribute it as well. But these are all
very important steps that will give you
a framework on how to do the
infiltration. So the first thing we want
to look at is when is it the best time
to infiltrate certain groups and I think
I found a really good opportunity and
that is the recruitment phase or the
initial offer phase. So we'll take a
look at what that looks like in a second
but this is really when operators are
actively seeking for participants. They
are uh open to interaction. They are
expecting to be cold called and cold re
and like cold DM'd and for people to
that have no reputation to reach out to
them and no validity uh to to start
interacting with them. So their um uh
their assessment of individuals is going
to be and their receptiveness to
individuals is going to be very very
high. So this is the prime time to
really start uh talking to people. So
what that looks like is something like
this. So this is from RAMP uh which is a
Russian Chinese um cyber crime forum. Uh
it is um exclusive. Um you have to
either pay to get in or have reputation
to get in. Uh you can be vouched for by
other uh sister sites like XSS and
exploit. Um so for example we're taking
a look at three different um initial
offers here. So uh we have Anubis there
and then we have Van Helsing and then we
have uh Kllin or Quillin. So these
basically show what their RAS or
ransomware as a service platform has to
offer and they're like okay so we're
looking for members we're looking for
affiliates. We're looking for partners
and this is what we want and this is
what we have to offer. So this is where
they're going to talk about their
lockers or their encryptors and their uh
infrastructure. this is how they're
going to start talking about their um uh
their payment structure. So this is what
you're going to see like 8020 splits or
7030 splits or 9010 or 8515 splits. So
that 80 or the the bigger number goes
towards the affiliate and the smaller
number goes to the uh operators. So this
is something that um this is the
recruitment phase. So everyone is
expecting to be uh uh to be contacted
through here. So, it's interesting
because some of the groups um get really
creative at how they start promoting
themselves and um we're going to take a
quick look at that as well. Um so, for
example, there's uh Van Helsing and this
is going to be there's going to be a
little bit of video here, but this is an
actual recruitment commercial by Vanna
Helsing and this is how they uh they're
doing it.
Heat. Heat.
So that is how ransomware operators are
starting to promote themselves because
getting affiliates is really really
tricky. Now, um just to give you a
perspective on how many people are
actually involved with these uh groups,
um lockbit at its peak had like 100
affiliates. Um so there's not that many
affiliates per group if you really
really think about it. So they're all
vying for the really skilled operators,
the really skilled pentesters um with
scruperless morals. Um, so there's a lot
of skids, uh, which is like low-level,
um, like script kitties, uh, or junior
pentesters that are out there, but the
really talented ones that can actually
like take down an enterprise, uh, those
are not as, um, as uh, popular and as
common. So, another group that is very
very interesting is Anubis. And, uh,
this is a brand new group as well. And
this group is highly sophisticated and
they're really trying to take um data
extortion and a monetization of access
and to another level. They write these
journalistic and investigative um uh
presentations on their leak site about
their victims. They don't go for uh
quantity of victims. They go for mass uh
the the most harshest and um really like
um like in-depth uh extortion that you
can find something very similar to what
Alvie was doing in the very very end of
their cycle. So um let's have a look at
what it it means uh when you reach out
to these individuals during that phase.
So this is a group called Sloglav. Um
this was uh originally a group um that
uh was promoted on ramp and uh so what
we were trying to do is we were trying
to break the ice. So now there's a
concept out there called uh hi or hello
and um or the no hi and no hello. So we
wanted to see it's all about um how much
because I the way we look at it or I
look at it is how much data like in
bytes and bits do I send out versus how
much they can give me. So I want to send
out as much data as little data as
possible for the maximum return for them
to send me information. So um that's how
I I perceive and then you can also have
the concept of like the size of bubbles
which is like how much text you send
versus how much text they send. So this
is just to give you a balance in how
much uh text and how much you're writing
to people. So for example here I was
telling them again this is all lies but
I was saying I have experience with a
smaller ransomware group uh such as
blank. Now, sexy was a group that was in
the news at the time that this was um we
were talking and um this is also uh
because we try to leverage groups or
it's a good idea to leverage groups um
that are sort of in the ether at the
time because maybe someone's seen this
and why is this
sorry there we go um so
basically uh we have so like uh we try
to go with um different like
vulnerabilities that are also there. We
try to go with um uh different um like
um either different groups or different
vulnerabilities that are in the um uh in
the news at a time. So um this is one
way to do it. The other way is for
example to say hey so this is another
group called APT47. Now we're breaking
the ice. We're trying to connect to
them. Now we had a successfully gathered
uh entered the group Slav and we were
using that to pivot to another group to
basically say hey we're part of slow
which was true and then we were
basically saying like we have access we
can show you that we have access we're
part of this group now we wanted to
pivot to a more um sophisticated group
so this is a 73 which is also known as
bashi now and we were saying hey we have
um and then fishing kits were in the
news at the time so we were trying to
leverage fishing kits and we were saying
like, hey, we've made money, so we know
because again, we have to understand
that there's like an 8020 split or a
9010 split involved. We we weren't sure
how much these uh their splits were yet.
So, we're trying to like like hey, you
can get like 20% of this 40k. So, we
were trying to like give them stuff like
that. We've recycled initial access um
that was very popular at the time. Um so
basically saying like I have initial
access to this environment which is not
true but uh these were just basically
shared and um we're just saying like hey
I'm ready to go. I have a team and I'm
ready to go. Um so that's how we can
break the ice there. Um perfect. So but
sometimes it doesn't always work. So
there was a time for example where we're
trying to jump into So this was for
Invader X and uh Invader X has been
operating very very under the radar. Uh
they've had a few confirmed uh attacks
in Europe but their DLS their dedicated
league site is not publicly known yet.
And uh so we were trying to figure out
how to get uh involved in them uh with
them. So, we reached out to uh this
individual who was selling the source
code to invader X or at least what
appeared to be the source code of
Invader X. And um what we came up what
was interesting was we're like hey um so
we have um uh can you like can you give
us access? We want to join your group.
and they kept asking us for the our
nickname on uh RAMP and we can't give
that because then they're going to just
put up like a scam alert against us uh
saying like oh we're a researcher we're
a fed. So we were basically saying like
no I can't we're trying to pivot away
from that but they just kept asking and
then circling back and circling back and
circling back to it. So unfortunately
this was not a successful uh
infiltration.
So um groups are really really emerging
at a rapid pace. uh is specifically in
2025, we've seen a huge explosion of
them and they come in waves. So this is
for 2024, but we can see that every
quarter there's a huge wave of groups
that come out. So like in 2025, we
already seen from um from January to to
May we've seen a huge explosion of new
groups coming out. A lot of these not
are not around anymore. Um so like MPHI
is Kraken. Kraken just published
something recently, but um like fake
Baboo or Babuk Bjorka. JD Sex, same
thing. Wero just came back. Crazy Hunter
is no longer around. SEPO just posted
something. Mimona got hacked by Hunter
International. Uh Run Somewhere um was
in the news recently. Skira still
around. Van Helsing no longer around.
Anubis is still around. Nightspire is
still around. So they come and go so
quickly. So when you want to sculpt your
persona, uh you have to also take into
effect that unfortunately most of us are
going to be at a disadvantage because
most of the stuff happens on the right
side of the map versus the left side of
the map. So what's interesting as well
is um understanding where your thread
actor, your persona should come from as
well. So this is actually uh the last IP
uh from geographic uh IP address metrics
based on the leaked breach forums v1. So
that's April 2022 to March 2023 data um
that was leaked um by EMO. And so it
breaks down where the IP addresses for
the last uh login were from. And most of
them were from Indonesia, United States,
Hong Kong, uh UK, Singapore. What's
really interesting is that there's no
like Russia or Ukraine or any CIS or uh
common independent states um uh um uh
countries in there. So that's really
really interesting. I think that and
that fact makes me think that this data
has been tampered with. Um but also like
tour is at number eight which is a
little surprising but again a lot of
these could be VPNs. We don't know. We
haven't scanned for to see what the IP
listing if those were for VPNs. But it
gives you an idea of like what you're
going to start encountering once you
start interacting with more and more
cyber criminals. Um so when you want to
address the hours the difference in
hours it's really difficult. Well,
there's only one way to do it. You have
to operate on their time. So, you're
going to have to wake up early. You're
going to have to put in that uh effort
there and and try to put some time uh
talking to people at 2 a.m., 3:00 a.m.,
4:00 a.m. Because or else if you're
always operating on your analyst time,
which is uh 9 to5 for example, you're
going to show up much later in their
day, like much later in the day, and
that might just set up some red flags
because your hours of operation are uh
going to have an issue there. and
they're going to trigger some red flags.
So, uh that's how it's going to look
like. So, you want to move your hours so
that you can uh basically align with
theirs better. So, another thing that we
want to take a look at is the writing
style, how you're going to write these
uh your uh personas and how you're going
to write uh when you're interacting with
people. So, it really is something that
you have to sometimes just write like
they do, which it like means like
talking like a brain dead smoothrain NPC
goonu who's been online for too long.
Like for real, for real, no cap. Like
that's literally sometimes how you're
going to have to type. And so there's
another really interesting concept is
and we've we're going to take a look at
a case study actually uh that covers
this, but this is a a concept called
transliteration.
And this concept is a concept that
basically um individuals will write um a
uh in a word in uh in for example
Russian but they will write it
phonetically in using English characters
and um so when you read it you're
reading it uh Russian but it's written
in English and LLMs are not very
equipped at reading understanding this
is specifically when you have like uh
anglicization or you have um something
like um uh slang as well like cyber uh
like cyber crime slang incorporated in
there um like LLM's just completely
collapse. So we'll take a look at a case
study in in a bit for that.
So when we're trying to infiltrate
there's some offensive tactics that we
can do to employ social engineering on
these individuals and these are just
like rudimentary and like basic core
concepts of like social engineering. So
we'll take some look at that. So there's
one concept called NRE which is the
weaponization of like relationship
energy. So spec so especially when you
start interacting with someone for the
very first time and you become familiar
and you start to interact with them more
and more and more and you get closer and
you build that connection um you can
become infatuated with them. You can
have this and it it could be a
friendship, it could be a lover, it
could be anything. And this is the type
of energy that you can actually if you
can remove yourself from the equation
and and have someone become infatuated
with you. Um this could be a mentor,
this can be a friendship, it could be a
lot of different things. Um it really is
something that um some people can uh
weaponize. Um ingratiation is another
concept and this is a concept where um
you can flatter people, you can give u
uh gifts and you can love uh lovebomb
them. So for example um when it comes to
gift giving um we uh in one of the
options uh in the previous slides we
were talking about like initial access
and breaking the ice and we offered them
like free access that was a small token
to uh basically break the ice and to say
like here's a little gift um or flattery
like hey you did a really good job I saw
that you did a really good job on this
uh attack and and stuff like that and
love bombing depending on the on the
person that you're trying to uh connect
with uh is something you can do. So if
the individual is looking for a
girlfriend or a boyfriend or something
else, you can basically use that to
manipulate them. So another really
really really powerful um concept for
social engineering is specifically that
you you can very well use um online is
concept uh conflict resolution. So you
can create and engineer a a small um a
small conflict, blow it up. It it's
really like out of proportions and you
resolve it together. So you've you've
and this is a good way to establish
trust early on in a in a in a
relationship because you've surmounted a
conflict and you've built that
connection together. So when you're
talking to someone online and you're
you're saying like oh like this is a
like this is an issue this is a problem
and you problem solve that together and
you surmount it that will bring you
closer to something. So this is
definitely one of the really good ways
and we can also look look at that a
little later if we have time. So uh
another good technique is uh called uh
the chameleon effect or mimicry. So that
uh effect is essentially mirroring how
they talk, how they uh we which we
essentially uh discussed a little
earlier, but this is um their you can if
you're doing it in person, you can this
is like we've said like oh you mimic
their body position. You if they cross
their arms, you cross your arms or um
the the speech pattern. Um we do this
naturally when we go overseas and we
start learning a new language. we will
like pick up the accent and stuff like
that because we want to assimilate and
um basically like become part in one of
uh the culture there. So this is how um
we do this naturally. So it's very
important to uh be cognizant of how
you're um you're performing and you can
basically weaponize it even further. Um
so let's take an for the last couple of
minutes let's take a look at some actual
case studies. So uh for example this is
a group called APOS and so we reached
out and this whole concept here was we
wanted to be a mentor to this
individual. Um they were brand new to
the game and they uh didn't know how uh
to they had a good piece of software and
it was really really uh well written
based on their post on their initial
offer but we wanted to gain access to
their builder. So we wanted their source
code, we wanted their builder, we wanted
uh to see what how um their encryptors
work, how their decryptors work. So we
we wanted access to their builders. So
we basically reached out to them and um
they were struggling. So because they
had uh put up their blog on notion and
um they were taken down within 24 hours.
So we were saying like hey don't do
that. you use an onion, which again
we're not going to basically tell them
like hey um like how to do like um cyber
crime, but we're trying to also tell
them like hey like like trying to give
them like super common sense answers and
also trick uh answers which we'll see in
a second. So like use an onion. Of
course, everyone uses an onion. But uh
the next thing we wanted to do was also
um offer them uh a way to um download uh
data. So because a lot of um groups like
so it it gets really really expensive to
host a ton of data. So um we were
thinking of like okay so if we can get
make a torrent of fake data. So what we
were going to do is DD random data to
the drive in uh zip that put a password
on it and send out like a 600 GB file to
them and uh if they were um going to uh
download it from us as a torrent we were
going to get some IOC's or some some
indicators like for example um their IPs
that they were using even if it was a
seedbox even if it was a VPN like we can
start accumulating that data from them
and uh we can use that later. So, um, we
wanted to send a massive torrent file to
to this, uh, to this group and we're
trying to figure out how we can do that.
So, this is again free gift and we're
trying to build trust and conflict
resolution. We're trying to problem
solve an issue together and uh, we're
being very very slow with how we're
responding because each uh, gray box is
a different day. So, we're trying to
mimic how fast they're responding as
well and not just like wall dump. So,
we're trying to be very meticulous in
how we approach things. So in the end uh
they ended up sending us uh their
builder. Um we had full access. We were
officially an affiliate. We had full
access to their infrastructure. Uh they
were basic this is how they were going
to conduct their um operation at the
very beginning which was very manual.
This showed they didn't have a panel.
This showed that they they were using an
executable to create a bonded encrypter
and decryptor. And this is what they
were sending people. We didn't pay for
this. we just basically uh were able to
do this. Now, a lesson learned on this
subject is if you're doing this, make
sure that you're in a VM, of course,
always in a VM, but you want to make
sure that you have automatic uh the the
ability to receive files automatically
in talks. Um because the first time they
sent uh this individual sent it to us,
we weren't uh available and we missed
the window to accept the file and that
is a big no no. So, uh, make sure that
it's counterintuitive, I know, but make
sure that you're always ready to accept
something, uh, so that you don't miss on
a getting a builder like that. So, um,
we ended up having this, uh, this
ransomware builder. We were able to give
it to the people who were interested in
this and, uh, the documentation for this
was extensive. I'm talking like pages
and pages and pages and pages of
documentation, uh, provided by the
thread actor here. So then the next idea
is how do we exit here and not just
ghost this person. Um because that's
gonna if we just like did they just were
the most vulnerable at this point it's
now this is the afterare where we have
to like slowly pull away from them and
um basically not raise any flags. So
we're slowly talking them through and uh
we're they were asking like we're
basically going back we didn't reference
the leak the the builder at all. We're
going back to uh talking about um their
site. They didn't do anything. Um it
took them almost eight months to do an
onion. So we at that point we had
nothing to do with them. We were not
talking anymore. So let's take a look at
the uh second case.
So this is where we were talking about
transliteration.
So for transliteration um we reached out
in uh Orthodox um cerillic uh Russian
and we were saying um basically are you
still recruiting um and they replied
back nim and uh that means uh
essentially yes we are um and we are
still recruiting. Um the the issue was
is that we had to reply back in the same
fashion and LLM and stuff like that
really have a hard time struggling with
a term like that because if we were like
to write imagine we were to write a
question mark after the first word the
they sent us. This is a really good way
of of checking if you are a native
speaker if you're like a Russian native
speaker. If you are like you say like
right away with just one word and one
way of writing that word they're able to
like do at least a good amount of data
verification. So I'm still interested
and then we based and we modeled our
discussions based on this. Um and then
they had a copy pasted uh section at the
bottom which is interesting because this
section is not in transliterated uh
Russian it is in cerillic Russian. So uh
using the cerillic alphabets. So um you
can see that this was copy pasted from
something that they already had prepared
and basically they're saying how many
people are in your team what software
did you use before if any not a secret?
Why did you leave? Go away. How do you
drain um how do you drain the date from
the target or the data from the d
target? So it's it's um basically now
we're in the interview section. So we
have to pass this interview and we're
basically going to be talking them hey
um my team is finished uh is finishing
up our last target uh with the previous
group we have already uh worked this
weekend uh we have experience with logit
fobos and babou this is before babuk 2.0
know and um we're basically saying uh
there are four of us on the team. Hiring
a team is always more appealing than
hiring a solo uh person um because a
team means you have a lot of fallbacks,
you have a lot of ability and resources
um but it could also lead to more drama
and uh essentially we were trying to uh
get uh access to this uh panel. This is
the RAS panel. Now, one thing that's
really um difficult about this is uh
they were asking for actual uh data. So,
they were saying like, "Okay, so this is
how you're going to gain access to our
group. You're going to give us um uh the
data for your your latest victim. You're
going to give us the Zoom info for that
latest victim, and then we're going to
validate the data, and then we're going
to claim it on our on our on our panel.
then we're going to give you a access to
the panel, the affiliate panel to so uh
we can like download encryptors and
decryptors and stuff like that. Um so
that was a big issue like how do we fake
data from a target? So we had to pull
out of of this one. Um because we can't
really fake that much data unless we're
using massive amounts of like uh like
just creating fake documents, fake
JPEGs, fake docu uh fake Excel sheets,
fake PowerPoints, fake PDFs. uh it just
takes a lot a lot of effort to do that.
So we can basically uh do that as a next
project. So that's it for today. Uh if
you have any questions uh I'm available.
So hierarchies is really interesting. So
um depending on the position and the
individual that you're targeting or the
group that you're targeting um sometimes
you can have infighting. So very good
question. So the question was do you
take advantage of hierarchy? Um so there
was one group that we did infiltration
for um and uh we connected directly with
the um uh one of the u main like the the
developer the admin the the person
running it and uh we didn't want to take
on a technical role because we didn't
want to actually be part of their team
that was red teaming but we said like we
can take something that has more soft
skills and we started the identifying
and talking more with that individual
and we're like oh we can run like public
relations for you. we didn't but that
was the role that we wanted to take on
for them. So um when we started doing
this there was quickly some divide
because we weren't the ones uh taking we
were still asking for a cut because of
course we're going to we want to ask for
a cut of the of the ransom profits but
without taking it but it would be shade
like it would turn up too many red flags
if we weren't asking for money. And um
basically um so when they were trying to
conduct attacks and they were trying to
like plan who how the ransom would be
split um they were we would be getting a
cut but then they people were saying
like oh this person isn't even um like
part of the attack. They're not red
teaming. They're not doing the data
exfiltration. They're not doing the oent
on the data. They're not doing any of
this. So like why is this person getting
uh getting money? And then we were like
well because we're doing uh public
relations. and they're like, "Well, you
haven't even posted about us on a single
forum yet. Like, what are you doing?"
So, and then you can start to like break
down the group from the inside and just
cause more internal fighting. Uh, that
group never successfully did a single
attack. We were able to uh just stay
there and just like grind it out and
make them fight um and um just make them
like blow themselves up. So, that was a
really interesting one. Uh yeah.