ISC StormCast for Thursday, August 8th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 August 2019
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, August 8th, 2019 edition of the Sansoment Storms and a Stormcast. |
| 0:07.4 | My name is Johannes Ulrich. |
| 0:09.0 | I'm recording from Denver, Colorado. |
| 0:13.8 | Usually if a company employee does install malware on their system, they do so without really knowing what's happening. |
| 0:24.2 | They're falling for some email that contains the malicious attachment, or they are installing |
| 0:30.7 | software that they think is benign, or maybe even they think they install a new security tool. |
| 0:37.0 | Well, AT&T had sort of a different experience. or maybe even they think they install a new security tool. |
| 0:47.2 | Well, AT&T had sort of a different experience here in insiders intentionally installing not just malware, |
| 0:55.8 | but also installing network equipment to allow criminals access to AT&T's network. |
| 0:59.5 | The goal here was actually not customer data. The goal here was unlocked codes for mobile devices. |
| 1:04.9 | Usually if you do have a contract with AT&T, you need to wait for that contract to be fulfilled before you can obtain |
| 1:13.5 | an unlock code and then move your device to a different carrier. This particular gang did offer |
| 1:21.2 | third-party unlock services for customers who could not legitimately unlock their phone with AT&T. |
| 1:29.3 | Now initially they just essentially forwarded these requests to insiders who then provided |
| 1:35.5 | the unlock codes. |
| 1:37.4 | This then evolved into the insiders actually giving these criminals credentials to connect to AT&D's network. |
| 1:46.0 | But of course, these unusual access patterns were eventually discovered. |
| 1:51.0 | In the end, the insiders did install Malware and some unspecified network device. |
| 1:58.0 | Now, it says you have wireless access. I'm not really sure if this is |
| 2:02.2 | a Wi-Fi access point or really more like a cell phone modem maybe that bridged the |
| 2:08.5 | AT&T internal network to a cell phone connection. So these criminals who apparently were located |
| 2:15.0 | in Pakistan were able to connect directly to AT&T's internal network, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

