Best podcast episodes on nation-state hacking
Volt Typhoon, Salt Typhoon, Lazarus, Turla and NotPetya: state-backed operations told by the people who tracked them, from narrative accounts to attribution tradecraft.
12 episodes from 12 shows. Dates and lengths are from each show's own feed.
- 01
· 57 min · Beginner
The classic account of the 2017 attack on Ukraine and its worldwide spillover.
- 02
How China’s Volt Typhoon hacked a small-town utility
· 23 min · Beginner
Volt Typhoon's prepositioning in critical infrastructure, told from the victim's side.
- 03
How North Korea strikes and survives.
· 41 min · Beginner
How North Korea's cyber program funds the regime and evades sanctions.
- 04
This job interview could destroy your company
· 59 min · Beginner
North Korean operators posing as recruiters to compromise job candidates.
- 05
The Defender's Advantage Podcast
UNC5221 and the BRICKSTORM Campaign
· 26 min · Practitioner
China-nexus espionage through edge devices and long dwell times, from Mandiant responders.
- 06
Microsoft Threat Intelligence Podcast
Russia’s Forest Blizzard Is Abusing Home + Small Office Routers for Cred Theft
· 52 min · Practitioner
GRU-linked activity using SOHO routers for credential theft.
- 07
#6 - Chinese Spies Acquire Keys To The Azure Kingdom
· 31 min · Practitioner
Covers the 2023 theft of a Microsoft signing key used to read US government email, a landmark cloud identity breach.
- 08
Blueprint: Build the Best in Cyber Defense
Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam
· 97 min · Practitioner
Lessons from a real compromise by a fake IT worker, with detection and hiring controls you can apply.
- 09
Lawfare Daily: Can Chinese Cyber Operations Be Deterred, with Dakota Cary
· 43 min · Practitioner
Why deterrence has not stopped Chinese intrusions against critical infrastructure.
- 10
A Live Stream From inside Lazarus Group
· 64 min · Practitioner
A rare look at North Korean IT-worker tradecraft as it happened, discussed by working pentesters.
- 11
Inside the Turla Playbook: Hijacking APTs and fourth-party espionage
· 107 min · Expert
Russian spies stealing a Pakistani APT's access: fourth-party espionage and why attribution is hard.
- 12
Behind the Binary by Google Cloud Security
· 62 min · Expert
How code similarity supports attribution of North Korean operations.