1
00:00:01,679 --> 00:00:04,919
Speaker 1: Welcome back everybody. Today, we're going to be looking at

2
00:00:04,960 --> 00:00:09,160
inside China's cyber war and US defense research. If you've

3
00:00:09,199 --> 00:00:11,439
been watching the world lately, you know the nature of

4
00:00:11,480 --> 00:00:14,240
warfare has completely shifted. It's not just about boots on

5
00:00:14,279 --> 00:00:16,199
the ground. It's not just about who has the biggest

6
00:00:16,239 --> 00:00:20,640
carrier strikes or the quiet submarines. The most dangerous battles

7
00:00:20,679 --> 00:00:24,079
being fought right now are helping are happening in silence.

8
00:00:24,640 --> 00:00:27,160
They're happening on servers, data centers, and the networks of

9
00:00:27,160 --> 00:00:31,120
our most sensitive institutions. And most Americans have absolutely no

10
00:00:31,199 --> 00:00:35,039
idea we are actively losing a digital war. But Google's

11
00:00:35,079 --> 00:00:38,520
Threat intelligence group dropped the bombshell report. They're exposed a massive,

12
00:00:38,600 --> 00:00:42,719
multi year cyber espionage campaign orchestrated by a highly sophisticated

13
00:00:42,719 --> 00:00:49,000
threat actor known as UNC sixty five oh eight, a

14
00:00:49,159 --> 00:00:53,000
China and Nexus state sponsored hacker group, China cyber soldiers

15
00:00:53,000 --> 00:00:55,960
working directly for the People's Republic of China, and what

16
00:00:56,079 --> 00:00:58,359
they pulled off should scare the heck out of every

17
00:00:58,399 --> 00:01:02,399
single one of us. These folks didn't target random infrastructure.

18
00:01:02,439 --> 00:01:04,719
They went off, They went after the crown jewels. They

19
00:01:04,719 --> 00:01:09,560
targeted North American medical, academic and military research institutions. The

20
00:01:09,599 --> 00:01:12,799
place is developing the next gen of American tech medical

21
00:01:12,840 --> 00:01:16,560
breakthroughs in US defense. I know you're asking, how did

22
00:01:16,560 --> 00:01:18,319
they get in? They found a weak point in an

23
00:01:18,319 --> 00:01:21,959
externally facing platform called REDCAP. For those who don't know,

24
00:01:22,079 --> 00:01:25,280
REDCAP stands for Research Electronic Data Capture. It's a secure

25
00:01:25,280 --> 00:01:28,799
web application used by scientists, military researchers, and doctors to

26
00:01:28,799 --> 00:01:32,879
build and manage online databases. It's exactly where you store

27
00:01:33,560 --> 00:01:37,280
highly classified, highly sensitive data when you're running advanced trials

28
00:01:37,959 --> 00:01:40,560
UNC sixty five. OHA found a way to crack those

29
00:01:40,599 --> 00:01:42,840
servers open, and once they got inside, they didn't just

30
00:01:42,879 --> 00:01:46,439
smash and grab. That's not how these elite state actors operate.

31
00:01:46,519 --> 00:01:49,319
They play the long game. They deployed a highly customized

32
00:01:49,319 --> 00:01:53,519
piece of malware called infinitord. Think of infiniture as a

33
00:01:53,560 --> 00:01:56,879
digital ghost. It's a customer built, custom built tool designed

34
00:01:56,920 --> 00:02:00,000
for one specific purpose to sit quietly in the show

35
00:02:00,040 --> 00:02:03,239
shadows of a network, harvest credentials, steal user names and

36
00:02:03,280 --> 00:02:07,760
passwords passwords, and maintain what the tech world calls persistence.

37
00:02:08,599 --> 00:02:11,240
They stayed hidden inside some of these environments for over

38
00:02:11,280 --> 00:02:13,479
a year. Think about that for a second. For twelve

39
00:02:13,560 --> 00:02:17,439
plus months, Chinese intelligence operators had a backdoor key to

40
00:02:17,520 --> 00:02:21,680
American military and medical research networks. They were sitting in

41
00:02:21,719 --> 00:02:24,960
the room virtually reading over the shoulders of our top

42
00:02:25,000 --> 00:02:29,120
scientists and defense strategists. So what are they looking for?

43
00:02:29,479 --> 00:02:32,639
Everything that matters for the next fifty years of global dominance.

44
00:02:34,000 --> 00:02:37,240
They exfiltrated massive trops of data on advanced medical research.

45
00:02:37,280 --> 00:02:40,639
They stole US defense strategy documents. They targeted advanced technology,

46
00:02:40,639 --> 00:02:43,560
cutting edge artificial intelligence, and this is the part that

47
00:02:43,599 --> 00:02:49,400
really hits home. Autonomous and uncrude systems, drone technology, robotic warfare,

48
00:02:49,479 --> 00:02:51,360
the exact tech that our guys are going to rely

49
00:02:51,439 --> 00:02:54,039
on in the field to stay alive. If you want

50
00:02:54,039 --> 00:02:56,240
to defeat America in a conflict ten years from now,

51
00:02:56,280 --> 00:02:57,719
you don't want to wait for the war to start.

52
00:02:57,759 --> 00:03:00,080
You steal the bootprints where they're still being written. If

53
00:03:00,120 --> 00:03:02,159
you want to defeat the soccer team in the World

54
00:03:02,159 --> 00:03:04,639
Cup before, you don't want to wait for them to

55
00:03:04,639 --> 00:03:06,759
start implementing their strategy. You want to know what it

56
00:03:06,800 --> 00:03:10,719
is beforehand if you can. But the technical but the

57
00:03:10,759 --> 00:03:14,039
technical sophistication didn't stop at the malware. The Google thread

58
00:03:14,080 --> 00:03:17,080
hunters discovered that these guys were using incredibly novel techniques

59
00:03:17,120 --> 00:03:19,439
to get the data out of our house and into theirs.

60
00:03:20,240 --> 00:03:23,599
They actually manipulated Google workspace compliance rules. Think about how

61
00:03:23,639 --> 00:03:26,719
brilliant this is. They didn't use some loud, aggressive file

62
00:03:26,800 --> 00:03:29,800
transfer protocol that were triggered alarm. They quietly altered the

63
00:03:29,840 --> 00:03:33,759
internal administrative rules of the victim organization's own Google system.

64
00:03:34,280 --> 00:03:37,400
They made the system itself bypass its own security checks,

65
00:03:37,439 --> 00:03:41,159
treating the data theft like a routine, compliant, autumn heated task.

66
00:03:42,000 --> 00:03:44,360
By the time security teams realized what was happening, that

67
00:03:44,439 --> 00:03:49,000
data was already gone. Fortunately, Google's Threat Intelligence group caught

68
00:03:49,000 --> 00:03:52,400
onto this. They acted. They disrupted the infrastructure of the

69
00:03:52,520 --> 00:03:55,240
UNC six y five oh eight was running, was using

70
00:03:55,319 --> 00:03:57,280
to run these operations, and that've been burning the men

71
00:03:57,319 --> 00:04:00,719
out OZO notifying the effected organizations to help them patch

72
00:04:00,719 --> 00:04:05,000
the holes and kick these ghosts out. But who is this?

73
00:04:05,400 --> 00:04:08,879
But who else is there? Who else is in there

74
00:04:09,000 --> 00:04:12,039
right now that we haven't caught, That's the real question.

75
00:04:12,800 --> 00:04:15,479
This is not an isolated incident. This is a highly coordinated,

76
00:04:15,520 --> 00:04:19,000
incredibly well funded, asymmetrical war being waged against the US.

77
00:04:20,800 --> 00:04:23,759
When we're distracted by the news, nonsense, and the politics.

78
00:04:24,079 --> 00:04:28,399
Our adversaries are systematically draining our intellectual property and dismantling

79
00:04:28,399 --> 00:04:31,279
our tech edge. If we don't start taking cybersecurity as

80
00:04:31,279 --> 00:04:35,079
seriously as we take kinetic warfare, we're gonna wake up

81
00:04:35,079 --> 00:04:37,240
one day and realize we lost the war before a

82
00:04:37,319 --> 00:04:40,199
shot wasn't ever fired. Stay safe out there, everyone, and

83
00:04:40,240 --> 00:04:41,000
stay vigilant.

