Episode

The scareware rabbit hole.

Podcast
Research Saturday
Published
Mar 7, 2026
Duration seconds
1673
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/415/notes
Audio
https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW1524581446.mp3?updated=1772735397
JSON
/v1/public/podcasts/research-saturday-1377435/episodes/the-scareware-rabbit-hole
Markdown
/podcast/research-saturday-1377435/the-scareware-rabbit-hole.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/the-scareware-rabbit-hole/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/research-saturday-1377435/the-scareware-rabbit-hole.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

This week we are joined by Marcelle Lee, cybersecurity consultant and researcher, discussing "CTI tradecraft: Investigating a mobile scareware campaign." She details how a routine click on a Google News story led to a mobile scareware pop-up—and a deeper investigation into a broader campaign. Using free tools like Censys, URLScan, VirusTotal, and CyberChef, she pivoted from two domains to uncover more than 100 related domains, shared infrastructure, and links to questionable antivirus apps in the Google Play Store. The findings are mapped to the MITRE ATT&CK framework, showing how freely available resources can power meaningful, actionable threat intelligence. The research can be found here: ⁠CTI tradecraft: Investigating a mobile scareware campaign