Skip to content

Podcasts/Best episodes

Best podcast episodes on nation-state hacking

Volt Typhoon, Salt Typhoon, Lazarus, Turla and NotPetya: state-backed operations told by the people who tracked them, from narrative accounts to attribution tradecraft.

12 episodes from 12 shows. Dates and lengths are from each show's own feed.

  1. 01

    Darknet Diaries

    54: NotPetya

    · 57 min · Beginner

    The classic account of the 2017 attack on Ukraine and its worldwide spillover.

  2. 02

    Click Here

    How China’s Volt Typhoon hacked a small-town utility

    · 23 min · Beginner

    Volt Typhoon's prepositioning in critical infrastructure, told from the victim's side.

  3. 03

    Caveat

    How North Korea strikes and survives.

    · 41 min · Beginner

    How North Korea's cyber program funds the regime and evades sanctions.

  4. 04

    Smashing Security

    This job interview could destroy your company

    · 59 min · Beginner

    North Korean operators posing as recruiters to compromise job candidates.

  5. 05

    The Defender's Advantage Podcast

    UNC5221 and the BRICKSTORM Campaign

    · 26 min · Practitioner

    China-nexus espionage through edge devices and long dwell times, from Mandiant responders.

  6. 06

    Microsoft Threat Intelligence Podcast

    Russia’s Forest Blizzard Is Abusing Home + Small Office Routers for Cred Theft

    · 52 min · Practitioner

    GRU-linked activity using SOHO routers for credential theft.

  7. 07

    Crying Out Cloud

    #6 - Chinese Spies Acquire Keys To The Azure Kingdom

    · 31 min · Practitioner

    Covers the 2023 theft of a Microsoft signing key used to read US government email, a landmark cloud identity breach.

  8. 08

    Blueprint: Build the Best in Cyber Defense

    Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam

    · 97 min · Practitioner

    Lessons from a real compromise by a fake IT worker, with detection and hiring controls you can apply.

  9. 09

    The Lawfare Podcast

    Lawfare Daily: Can Chinese Cyber Operations Be Deterred, with Dakota Cary

    · 43 min · Practitioner

    Why deterrence has not stopped Chinese intrusions against critical infrastructure.

  10. 10

    Talkin' Bout [Infosec] News

    A Live Stream From inside Lazarus Group

    · 64 min · Practitioner

    A rare look at North Korean IT-worker tradecraft as it happened, discussed by working pentesters.

  11. 11

    Three Buddy Problem

    Inside the Turla Playbook: Hijacking APTs and fourth-party espionage

    · 107 min · Expert

    Russian spies stealing a Pakistani APT's access: fourth-party espionage and why attribution is hard.

  12. 12

    Behind the Binary by Google Cloud Security

    EP11 Tracing Lazarus: Greg Sinclair on Attributing North Korean Cyber Threats Through Binary Similarity

    · 62 min · Expert

    How code similarity supports attribution of North Korean operations.