meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

The scareware rabbit hole. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Tech News, News, Daily News, Technology

4.81.1K Ratings

🗓️ 7 March 2026

⏱️ 29 minutes

🧾️ Download transcript

Summary

This week we are joined by Marcelle Lee, cybersecurity consultant and researcher, discussing "CTI tradecraft: Investigating a mobile scareware campaign." She details how a routine click on a Google News story led to a mobile scareware pop-up—and a deeper investigation into a broader campaign. Using free tools like Censys, URLScan, VirusTotal, and CyberChef, she pivoted from two domains to uncover more than 100 related domains, shared infrastructure, and links to questionable antivirus apps in the Google Play Store. The findings are mapped to the MITRE ATT&CK framework, showing how freely available resources can power meaningful, actionable threat intelligence. The research can be found here: ⁠CTI tradecraft: Investigating a mobile scareware campaign Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:10.4

If you're defending a network today, there's a simple question worth asking.

0:16.8

What does the attackers see when they look at your organization?

0:20.6

Nord Stellar helps answer that.

0:22.9

Nord Stellar is a threat exposure management platform that gives security teams visibility into

0:28.1

external risks, including leaked credentials, active session tokens, impersonation attempts,

0:33.9

and exposed assets across the surface web and the dark web.

0:38.4

It's built to help organizations detect the consequences of breaches early, before attackers

0:44.0

turn access into action.

0:46.2

From monitoring for InfoStealer malware logs, to identifying cybersquoting and brand abuse,

0:52.4

Nordsteller helps teams focus on the threats that actually matter.

0:56.7

Executives get clear, actionable insights tied to business risk. Security teams get real-time

1:02.2

alerts and one of the largest deep and dark web intelligence pools in the industry. Cybercriminals

1:08.3

may already be looking for your weak spots. Don't make it easy for them.

1:12.5

Be the one that's prepared. Defend your business with Nordsteller. Use the code Cyberwire 10 to unlock your

1:19.7

exclusive discount. Go to Nordstellar.com slash Cyberwire Daily and learn more.

1:40.5

Thank you.com slash CyberWire Daily and learn more. Hello everyone and welcome to the CyberWire Research Saturday.

1:46.0

I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting

1:50.8

ourselves in a rapidly evolving cyberspace. Thanks for joining us.

1:59.2

So I got an alert that popped up that basically said that my phone was infected and I needed to install this antivirus program because I had malware on my phone or whatever.

2:14.9

And it also indicated that I had gotten this malware from going to adult sites.

2:22.4

So this all came as a surprise to me.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.