Censys ARC Flash Episode 4: Black Hat & DEF CON 2026, AI, DPRK, Mirai & OT Security

Censys ARC Flash

In Episode 4 of Censys ARC Flash, Principal Security Researcher Silas Cutler and Censys VP of Research, Security and IT Michael Schwartz unpack what caught their attention during Hacker Summer Camp and connect it to what Censys is observing across the Internet.

The discussion covers DPRK IT worker activity and laptop farms, the continued persistence of Mirai and vulnerable IoT devices, and the risks surrounding Internet-exposed OT and industrial control systems.

Silas Cutler (00:07)
Welcome to the ARC Flash number four. Today you’ve got Michael and Silas here talking about the post DEF CON Black Hat review. It was a long week in Vegas, Michael. How are you holding up?

Michael Schwartz (00:18)
Probably better than you, ’cause you you did the the DEF CON weekend. I did not. I was there Monday through Friday, specifically Black Hat. I didn’t get to attend any talks, which is unfortunate. Now I look back on it and I’m like, sort of look forward to. mostly show floor stuff. And I know you were busy.

Silas Cutler (00:38)
Yeah. I think I got in on Sunday night and I left Monday morning. And then flight delays and all that drama.

Michael Schwartz (00:45)
Yeah.

Silas Cutler (00:46)
So but yeah, it was a good week. I caught like, distantly a couple talks. It was definitely odd DEF CON side with the new headphones that they’re using for talks. So going into the like track one and it being dead silent, it was — it was wild. But it seemed like it seemed like participants really liked them. It was fairly enjoyable of like working staff as well and being able to like hear my teammates also as we were coordinating. So it’ll be interesting to see if they bring it back next year.

Michael Schwartz (01:16)
Fantastic. And I guess for everyone else on the call, you work DEF CON as well, but you also had presentation opportunities throughout the weekend too.

Silas Cutler (01:26)
Yeah, so I had two talks this this past conference. First one was BSides Las Vegas, in Josh Corman’s I Am the Cavalry track, where I talked with Paul Roberts during the talk Operation Graceful Edit. Really cool research. Like, he and I have been working together for man, we’re going on like two and a half years. Like I’m the support at the end for both Paul and Stacey who have been doing incredible work and looking at some of these end of life devices and also like thinking forward like what should we do in the future that’ll be better. So I’m a big fan of the idea of like, you know, when you buy a device, there’s an expiration date on it. So you have some sort of rough semblance of an idea.

Michael Schwartz (02:07)
Specifically.

Silas Cutler (02:11)
I feel like I share way too much about my own personal infrastructure in that talk, but it was a good talk. Talked about also some like forever day vulnerabilities.

Michael Schwartz (02:19)
Yeah, I think like then the specific title there was like, was it around like LG televisions? Was that the particular one? The BSides LG Talk, or this is the the particular panel that you were on?

Silas Cutler (02:32)
The particular panel. There was also some other stuff about LG televisions and and some good research there. And then also like later that week on Saturday had a panel with DEF CON’s Blue Team Village. And that was really fun. Brian Baskin did a fantastic job at moderating us and sort of keeping the herd of us chickens in line. And then was on the panel with Sydney Marrone and Allison G. And the the title was fun ’cause it was Threat Hunting Explained Badly. So it had it got a bunch of good hot takes in it. It’s fun ’cause, it’s interesting ’cause threat hunting is one of those, we kind of blur the term a lot between like, do we mean internal threat hunting or are we talking like like when we’re going out in the wild and just looking for trouble? Like that’s threat hunting, but the the space blurs a little bit in terms of what we mean with our communication.

Michael Schwartz (03:20)
I agree on that. Especially when who you’re discussing with, like we’re discussing it broadly, like it’s gonna have usually the connotation of, I’m exploiting my internal log set data looking for threats that evaded detection. Yeah. Versus I’m out on the Internet looking for weird and crazy stuff.

On that note, for me, I’ll give my observations on and Black Hat in general ’cause I didn’t attend any of any of the talks, unfortunately. But it seemed it seemed like overall like less people. Hard to say why, maybe less international travelers overall, too. Or maybe, dare I say the commercialization of Black Hat where Black Hat now feels like what RSA used to be. But even in this case, like there was some heavy hitters that didn’t have a show floor presence this year. I think namely CrowdStrike and and Palo. I didn’t see those booths, although I did see presence there, at least from Palo with a like a VIP area. I’m wondering, and then a number of companies I’d never heard of with these massive booths, and it was really hard to determine, at least from walking around, what the primary differentiation was between the all the AI buzzword companies. You know, a bolt on to Claude or Open AI, or are you doing something actually really unique in the space, training your own models, fine-tuning models, you know, implementing open weight models, etc. etc. Really difficult to tell. Especially in the in the whole section with the AI pen testing, etc. Really hard to tell in differentiation. AI SOCs really hard to tell in in differentiation as well. So I don’t know if you have any sort of feelings in that regard.

Silas Cutler (05:05)
I come from those old sysadmin backgrounds on these things. I love it, especially when I see companies building towards the stability side with with open weight models and and a product that’s not gonna be dependent dependent on Claude’s guardrails every week, but it was a huge topic this year and like it’s incredible seeing how the space is adopting to it as well.

Michael Schwartz (05:26)
Agree. I mean even on our end how we see how we’re utilizing the tools on an everyday basis and where we hitch our rails and that’s like weekly changes, which is difficult to keep on top of. And I guess for organizations to also develop solutions on top of. Like if you don’t developing this is one of my sort of my primary pet peeves right now, is organizations that are developing solutions on top of frontier models from one of the large frontier model companies, which is like one, new guardrails just come into play at any one time, just break everything. And like that seems bad. And then also you have think about model obsolescence, which is hey, we built a solution on top of, you know, Opus 4.6 and then Opus 4.6 goes end of life, at some point it’s gonna go away and it might not work on 4.8, or 5 of that solution because of guardrails or some other implementation. And so I think in those cases it’s like yes, like in order to survive that, like there has to be that research and development effort into exploring a number of open weight models that may fulfill that need for you for that particular workflow.

Silas Cutler (06:37)
Yep. And also having the continuous testing as well to know that like if you are dependent on an older model, having the testing in place for newer models, just to ensure that you’re gonna still get the same results when things change.

Michael Schwartz (06:49)
Yeah, fantastic. I mean again, like it’s gonna be crazy to see next year and like who survives, who’s there. I think there’s there’s definitely gonna be market consolidation or just evaporation for that matter. It’s like yeah, that just didn’t work. So I guess we’ll see next year what Black Hat DEF CON looks like. But overall feels like the that like this whole thing is growing up, you know, more commercialization of Black Hat, more commercialization, commercialization of DEF CON, BSides Las Vegas more so as well. Does that create more opportunity for other conferences to sort of pop up? Like we’re seeing, you know, I’ll give [un]prompted a plug here, I think. With the October is the next conference, right?

Silas Cutler (07:40)
Very end of October. Yep.

Michael Schwartz (07:42)
Somewhere around there, CFP’s open. But right, it’s like, okay, conference starts up. Specifically around AI and that’s like taking off, right? Is that sort of you know the next place where all the practitioners get together and share the war stories? TBD. I think so far, so far everyone’s amazing. I but I guess we’ll see there. Yeah.

Silas Cutler (08:02)
Yeah. I mean content also was fantastic at both conferences as well. I figure that’s the next area we should dive into.

Michael Schwartz (08:08)
Yeah, yeah. Let’s talk about the content.

Silas Cutler (08:09)
So I know at least big thing for me was a lot of the like DPRK stories that came out. Because there was one big one that came out from DEF CON, it seemed like, and one big one that came out from Black Hat. So on the Black Hat side, there was the I’m trying to remember who it was. It was, was Stykas the author of it?

Michael Schwartz (08:29)
Stykas I think. I’ll look it up, you go on.

Silas Cutler (08:34)
Yeah, so they love seeing these stories about threat actor C2 infiltration and and what people are able to find when they end up sitting within the same visibility space as the threat actor. 1,600 companies it looks like that they found as well that had been compromised. So really interesting seeing the scope of some of these campaigns. And I know that at least for the Contagious Interview stuff, that’s been a topic that we’ve been watching very closely for the better part of the past year. Like there’s there are a lot of overlaps, there’s some critical differences with Beaver Tail. But at least from like what we’re still scanning, we’re seeing a lot of similar similar infrastructure and beyond.

Michael Schwartz (09:10)
Yeah, I think one, you know, if we pull this back into sort of Censys perspective and and just sort of TLDR for everyone on on the webinar today that doesn’t know what’s going on in DPRK land, Contagious Interview, which is basically, you know, DPRK actors, so residents, etc, that are part of a program that are trying to get jobs with, you know, a North American or your European security IT company. So they’re just posing as someone else.

But in this particular case, they could be bringing kit with them, you know, and in a particular interview process. It’s like, hey, like we’re gonna work on this coding interview and and you know distribute malware that way as well. So it’s not just like a I guess a social engineering threat that ends up being a person that works through you now, right? Your organization gets instrumented officially, unofficially, through this process. So from the — I think the Censys side, some of the interesting things that we see is like we have really good detection for a lot of IP KVMs and we can see laptop farms, etc, that look super interesting.

Silas Cutler (10:17)
And I mean GL.iNet has several new models of their IP KVM coming out and they look they look really cool in general.

Michael Schwartz (10:25)
Yeah, not

Michael Schwartz (10:25)
to mention that that tech is super cool. Like of checking out a few of them. Like these are neat. I don’t know — I guess if I ran a bunch of remote laptop farms, that’d be really, really cool.

Silas Cutler (10:36)
Yeah, I mean I use quite a few KVMs in general. Like I have two on my desk and down in my server rack, there’s an eight port and having something that was IP based would be really nice. One of the like one of the kind of like details I suspect might have gotten lost though from a lot of the discussions this week was: it was interesting hearing Todd Hemmen, the deputy assistant director for FBI’s cyber capabilities branch, make a side comment during one of his panels about potentially having accidentally hired a North Korean IT worker as part of the federal workforce. And so I’m hoping we get some more details about that because I think I joked about it several years ago that like how long is it going to be until until US government hires somebody off Fiverr?

Michael Schwartz (11:14)
Yeah.

Silas Cutler (11:17)
But it sounds like we’ve kind of hit that point.

Michael Schwartz (11:20)
Perhaps until it gets in further detail there. Sounds like just mentioning a side comment. I mean, I’ve seen a number of the like, the general scams — I mean, air quote “scams,” ’cause I’m gonna say whether it’s DPRK or whatnot, but exceptionally prevalent across the board. So it puts — there’s some large pressures. I remember working with recruiting. Specifically when we’re investigating, you know, potential DPRK resumes, but just in general, it’s just like there’s a whole bunch of criminal opportunity there. Fake resumes, LinkedIn profiles to get recycled. malware laden resumes, you know, there’s different scams that get perpetrated. I mean, there’s not that is a weak underbelly and it’s difficult to communicate all the different threats that exist, or your social engineering threats, your malware threats, especially in most orgs where recruiting is already underwater with AI generated resumes. Like that’s like a whole nother issue, which is all this noise.

Silas Cutler (12:23)
Yeah. I talked to a few folks on the floor at DEF CON as well that were having trouble, both on the like trying to be hired side but also on the recruiting side, because with a lot of those tools as well, they will tune resumes specifically towards what are in the job requirements. And so some candidates will be absolutely flawless on paper. But when you get to an interview and you’re like, All right, tell me about MS08-067 it’s Greek.

Michael Schwartz (12:44)
Yeah. Right, roger that, I see those. As a hiring manager, I see those. I’m like, this looks perfect. I’m like, yeah, it’s a specific resume to my job posting. But then you know, think about in those cases, you know, as a document, is it a lure, right? It’s just to get that discussion going and then hey, check out my GitHub repo and clone my repo and do a thing, or check out my mail doc. Then it’s off to the races.

Silas Cutler (13:14)
Yeah, so we had a lot of content we published as Censys before the conference as well. And so one of the ones that I’ll dive in straight to that I was really excited about was Allyson Martinez published a blog that looked pretty deeply into Mirai. I’ve been following Mirai for years and this was incredible getting to see some fresh research on it because I think most folks may remember Mirai from back in 2016 with the DDoS against Dyn, which took out Netflix, PlayStation, and a quarter of the Internet for a few hours. But Mirai still continues to this day, and not just the dead bots that will forever be echoing for a control server that’s not there, but we still see live instances running the original protocol as well. So that was a really interesting thing to see kick off.

Michael Schwartz (14:01)
Yeah, for those on the show, Allyson was our summer intern. She’s an undergrad at at Georgia Tech. Yeah, fantastic piece of research there. I think one of the things, and this is thematic, like we’ve been talking about this a lot, and it’s sort of gonna broach a few topics that we’ll talk about here. Mirai, Mirai, however you wanna wanna pronounce it, took advantage of unsecure, vulnerable IoT devices.

How many times have we talked about that specific thing in the last 10 years in perpetuity? And I guess this is one of the reasons why Mirai, is prevalent, or Mirai, variants are prevalent because there seems to be this unending supply of vulnerable IoT devices. And everyone’s like, what do we do about it? I mean, you had a panel about it, like end of life devices, and then my argument is I don’t think it really matters, end of life doesn’t matter, if like when the thing is released, no one’s ever gonna patch it in the first place. So who cares about end of life? It’s just there. And we see that with things like Mirai, where that like new vulns and new default passwords and that’ll get integrated into a new bot variant and then sort of off to the races from there, but all that old stuff is still there.

Silas Cutler (15:23)
Yeah. I mean it is also fascinating because one of the things I touched on in the panel as well was in some cases, when we’re able to get a good idea for what the total volume is, that essentially is a fairly accurate attack surface mapping of of the sort of state of that vulnerable ecosystem. And like we’ve seen the exploitation of Mirai forks that go after GPON routers, and you end up with a fairly well enumerated subset of the Internet that that’s just those devices.

Michael Schwartz (15:50)
Interesting. Do you think there’s any, or do you gather that there’s any motivation to somehow holistically, at least in certain regions, identify those like attribute those things like hey, like this IP address is this person you need to take this stuff offline or work with ISPs to filter that data?

Silas Cutler (16:08)
I mean, there’s, there’ve been some really good efforts in the past where when there are like takedowns of the control server infrastructure, sinkholing by law enforcement and then creating a list, then working with the carriers has done some good work at shutting things down. I know I’ve gotten a couple of alerts from Comcast back when I used to have Comcast as my home Internet provider because I was running a number of different Mirai bots out of my basement, checking the C2 servers and they were like, Hey, we think you have a problem.

Michael Schwartz (16:36)
This is interesting because this parallels like the next topic that I wanted to talk about is right, a lot of hubbub communication around Iranian threat actors targeting OT networks or exploiting PLCs connected to the Internet. And I say hubbub because you know attribution in this case is left to the government, and there’s been no private entities been able to make attribution, and then there’s also really, no attribution information shared out to the private sector for the private sector to do attribution. So you know, someone just points at Iran. It’s Iran. I don’t know. But what I can say at the end the day is that Censys has had for, you know, the last number of years, has had visibility and reported on PLC’s industrial control system protocols directly exposed to Internet. Modbus is the biggest offender. There’s some challenges on the Modbus side, but overall, it’s like, this stuff is there. It’s relatively left in an unsecure state, meaning that anyone with Internet access can in a lot of cases view HMIs, can directly connect to one of these protocols via authorized software that you can go download and acquire. Credentials are the same. So from a capability standpoint, there’s really nothing in that overview that like that I would say, like, that’s a sophisticated Iranian threat actor that can pull that up.

Silas Cutler (18:10)
Yes. And it’s also interesting ’cause like we’ve seen like for months, it feels like we’ve seen like, weak attempts at disruptions or defacements, things that are not going to have actual, that have the potential to cause severe disruption, not by intention like an intentional move, but by poking around the systems as aggressively as some of those folks have, there’s been the concern. But those aren’t really good signs of sophistication.

Michael Schwartz (18:34)
I think the lone exception being this latest activity that was first reported in my home state of Minnesota on values actually being changed or configurations being eliminated that caused water pressure issues and then boil water advisors came as a result.

Silas Cutler (18:54)
Yep. And also the the scale of that as well, I would say is one of the first early signs of some good sophistication as tied to this campaign. Because if there’s multiple states that were impacted as well and there was a coordinating effort, that sophistication is I see it.

Michael Schwartz (19:09)
Here’s the challenging part of my end. Or at least the challenging part that I identify, and I want to call this out a lot. The majority of the ICS protocols we see on the Internet today, this includes PLCs, everything under the umbrella, is on a mobile network. I think like, 70% is on Verizon Wireless. There’s 10% on AT&T, and then it sort of goes from there. Geolocation on cellular modems is, it’s really not good. It’s not accurate. So there’s really no mechanism to say, I want to go target everything in the state of Minnesota. It’s, you’re gonna get lucky. So I think in this particular case, so even with our data, when I think our data is the is, you know, so is the most accurate available today. I don’t see another data going to another data source that’s gonna say, all of these are in these geolocations of Minnesota. And there’s some caveats there, which is like, there potentially could be an SNMP service that has contact information or right where we’ve seen a VNC is open or there’s an HMI and it has a picture of the water tower with the address. But I’m saying that that’s like we had examples in the dozens compared to the, you know, hundreds of thousands of water systems that are online in some capacity. So from a targeting perspective, it was like North America works. Outside of that, it’s really spray and pray. So it’s identify standard ports, these are the things that are there that makes the most amount of sense and then we can spray across them.

Silas Cutler (20:45)
Yeah, this is fascinating because I see a similar problem occurring for threat actors. I saw it a lot with the Conti leaks when those happened, because from some of the trick bot panels, like clearly they had large volume of access to places, but even with access, the next job is then identification. If you’ve got something like a a solid domain that’s tied to like a system and you can say, Okay, this is workstation 01.silascutler.com, great. That’s gonna save a lot of time on attribution, but for a lot of them, operators are diving in there and sometimes what people are seeing is dwell time is actually just threat actors trying to figure out like, what system am I on? Am I on grandma’s computer or am I on the receptionist computer at at a multinational company?

Michael Schwartz (21:16)
Yeah. So in this case it’s like, you know the Iranian PLC actors like really don’t know what sort of the TTPs were behind that the and some of the data they might have indicated that the actors knew where they were and knew what they were doing or just doing some sort of mass exploitation. But I do find it inherently interesting because there is like if we were to say like, hey, take this stuff off the Internet or hey, put a VPN, you know, 2FA in front of it, like there was just a recently released Polish report about an attack right on their OT environment for, I think it was a wind farm. And great report. Loved reading it. A lot of the recommendations that the industry would have to secure these networks were in place. And I get like, it’s kind of funny because I called this out a few times in a few different presentations. It’s like these recommendations are not a panacea for like everything, especially when you throw a Fortinet device in front. So the vulns and the in the cred loss and all that stuff. And it turns out in this Polish Cert report.

Michael Schwartz (22:39)
The Fortinet was the problem.

Silas Cutler (22:41)
Yes. And that became the weak point that allowed them to get in.

Michael Schwartz (22:45)
Right. But even in this case, it’s like, yeah, but now we get to explore like this network seemed to be well designed, right? Or these were recommendations that I would propagate throughout industry here, but now we have a sort of a case example of how maybe more sophisticated threat actor came in and sort of rooted around in this network as well. So more lessons learned there.

Silas Cutler (23:06)
Definitely, ’cause I know there were I think 3 wipers that were also disclosed in that report as well. Like this is a report that we’re gonna need a bit of time to digest as well, ’cause there’s a lot of deep links in this and I’m always very interested when we start to see actual devices start to really really start to be wiped by hostile software.

Michael Schwartz (23:25)
Yeah, the wipe, I think the the wipe is the problem. The wipe is going to be impactful to operations no matter where it’s deployed. It’s more so than like, hey, we deleted a configuration on the PLC. Most of those configurations generally are backed up. And we start, you start wiping the control systems or the workstations, and that’s generally more impactful. Depending on the type of environment it is, if it’s a remote environment too, getting people out to that site to restore capability can be more difficult.

I like to call out as well as that like generally where you see these OT protocols, you see other associated protocols on that IP address, then there’s a lot of VNC, there’s SMB, there’s a whole bunch of other stuff that can be exploited, but right, where there’s VNC, there’s a workstation. Where there’s a workstation, there’s a network. Where there’s a network, there’s a bunch of other stuff that’s connected. It’s just not that OT protocol that’s the most concerned.

Silas Cutler (24:20)
Yeah. It it gives away the whole shop based on what’s being publicly exposed. And I mean this this report has big Sandworm vibes, so there’s a there’s a lot to dig into and we and we saw device destruction back in 2016, 2017.

Michael Schwartz (24:33)
Yeah.

Silas Cutler (24:36)
If anybody has any of those devices, DM. I’m very interested.

Michael Schwartz (24:42)
Fantastic.

Silas Cutler (24:43)
I think we’re at about time at this point.

Michael Schwartz (24:45)
Exactly.

Silas Cutler (24:46)
Yeah, we can switch to taking any questions if folks have questions. Otherwise, I think we’re pretty near the end for today.

Michael Schwartz (24:52)
Yeah, I’ll do a quick plug for our State of the Internet Report. I did brief that quite a bit during Black Hat this week. We do have a teaser blog that’s out. You can register to get the full version, which is due in the first weeks of October. We’re just putting the finishing touches here on the analysis — probably do it for another couple weeks. Looking at a whole bunch of threat trend analysis of all the threats that we tracked today. I think we have over 200 in the corpus. We’ll see how it shakes out over the course of I think doing a doing a look back a little over year. So that should be pretty interesting when that when that comes out.

Silas Cutler (25:29)
Super cool. I’m really excited to see how that turns out and it’s getting close to being done.

Michael Schwartz (25:35)
All right.

Silas Cutler (25:35)
We’ll see you all next month.

Michael Schwartz (25:38)
Take care everyone.

Silas Cutler (25:39)
Cheers.

Catch the Next Episode on September 9

Censys ARC Flash goes live once a month. Sign up to sit in on the next episode when it airs on September 9th to get the latest cybersecurity intelligence and ask your questions live.

References