RSS Amplifier

Rob T. Lee's Sleep. Diet. Exercise. AI. · Jul 18, 2026

“Disrupting threat actors must become the status quo in our industry.”

0
Sign in to vote or save

Rob T. Lee · Rob T. Lee's Sleep. Diet. Exercise. AI.

Update, August 13, 2026
A national security presidential memorandum signed Wednesday authorizes vetted private US companies to run cyber surveillance and cyber effects operations against foreign criminal organizations: breaking in quietly and breaking things, in the memo’s own definitions, under federal direction, with a bond of at least $1 million posted against noncompliance and every operation approved in writing by co-directors at DOJ and DHS.

But the interesting question is this: why did Washington suddenly believe this could work?

Sandra Joyce’s team at Google Threat Intelligence Group spent the last year making disruption look controlled, legal, and boringly effective. Joyce proved disruption works while staying scrupulously inside the legal line. IPIDEA in January. GRIDTIDE in February. Measurable degradation across hundreds of threat groups, zero unauthorized access, and a bright line she kept repeating: “this is not hacking back.”

Joyce’s work accomplished two things at once: It produced results no sanctions package has ever produced. And it made private-sector operations look like something a government could supervise instead of something it should fear.

Be precise about what happened, though, because this memo is uncharted waters, and licenses a lane Google deliberately refused to enter. The memo authorizes something companies could not do before as published federal policy: they may now operate on systems it does not own: covert access to collect intelligence, then operations to manipulate, disrupt, deny, degrade, or destroy those systems if DOJ and DHS approve the work in writing, and at the pace of written interagency approval.

Which is my first worry. The permissionless lane, where Google shut down attacker cloud projects, domains, and API access on its own systems, and used court orders when the infrastructure sat elsewhere, is the one that produced the results.

The second worry is older. The program assumes a target is criminal rather than state-run unless clear intelligence says otherwise, and in the Russian ecosystem that distinction is one phone call. Attribution is the load-bearing wall. Almost right is the expensive kind.

Joyce said disruption has to become the status quo in our industry. As of Wednesday it’s federal policy with an escrow account. The marque question is settled. Whether the oversight holds is not. Tell me where you land.

→ The memorandum: https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/

Originally published July 17, 2026

Sandra Joyce, VP of Google Threat Intelligence, has spent the past year arguing on the industry’s biggest stages that briefing governments and waiting isn’t a strategy, and that disrupting adversary infrastructure has to become normal practice.

She’s right.

On Monday, Brussels and London announced their first joint cyber sanctions package. The EU named nine individuals and four entities. The UK named 24. The targets: FSB Centre 16, GRU officers, and the criminals working alongside them. The EU traces the campaign back to at least 2010.1

By the afternoon, Moscow called the charges baseless and the operations kept running. (Both sides could pre-record their parts at this point. Maybe they already do.)

This is the same playbook Washington has run since 2014. The only thing new on Monday was who held the pen.

As deterrence, it accomplishes exactly one thing: it lets the governments issuing it feel like they responded. Attribution, indictment, sanction, repeat has never stopped an active state campaign. Not once. Call it what it is: finger-wagging with a legal budget.

And the attribution feeding these sanctions packages mostly comes from commercial threat intel, from shops like Mandiant, where I helped author the first M-Trends reports.

The intelligence is real. What governments do with it is the problem.

2014: DOJ indicts five PLA officers, the first nation-state cyber indictment. No arrests2.

2018: twelve GRU officers charged for the DNC hack, seven more for the anti-doping and OPCW hacks. None in custody.

2020: six more charges for NotPetya and Olympic Destroyer.3

2020: the EU’s second cyber sanctions ever, for the 2015 Bundestag hack, five years after the fact. (The EU’s cyber sanctions framework didn’t exist until 2019, so every attack before that got graded against rules written afterward.)45

2021: Treasury designates six Russian tech companies.6

2026: Monday.

The cycle never changes. An incident, one to three years of attribution work, a press conference, asset freezes on people who hold no Western assets, travel bans on people who were never coming here. Then the next campaign, usually within months.

Even the academic literature has quit pretending. Scott Jasper’s study of Russian cyber operations says it bluntly: sanctions and indictments have “done little to alter Moscow’s behavior.”7

Mandiant founder Kevin Mandia said at RSAC 2025 that China nearly doubled its cyber aggression because there are no agreed rules of engagement.8 Of course it did.

Most of the names on these lists sit inside sovereign territory with no extradition treaty. You can’t freeze assets that were never here. You can’t arrest a GRU officer who never leaves Moscow. Sanctioning two officers does nothing to the GRU, which keeps running at full strength with new staffing. Sanctioning at that scale is record keeping, not deterrence.

Yes, the playbook buys some things. Joint attribution keeps the coalition glued together, and advisories give companies legal cover to name campaigns and coordinate.

Hitting enablers can bite: the 2021 designation of Positive Technologies hurt more than any officer listing because that company lived in the global economy.9 North Korean crypto theft got squeezed at the conversion layer, not by naming hackers.10

Where operators have extraditable exposure, combined instruments work; ask LockBit.11 All real. None of it deters state operations. (The EU’s own defenders call it “building the normative framework.” Notice what that phrase doesn’t claim.)

Sharing intelligence stopped being a strategy somewhere around the fifth GRU indictment.

Google, Microsoft, Cloudflare, and Lumen own the platforms, networks, and APIs the campaigns run through. That’s visibility plus the authority to act, without touching anyone’s sovereign systems.

Joyce said it plainly at RSAC 2026: “disrupting threat actors must become the status quo in our industry.”12 Her structural point is the one no government can copy: the private sector IS the infrastructure adversaries abuse.

The toolkit: civil suits that seize infrastructure, public exposure that burns tradecraft, technical shutdowns and sinkholing, and product hardening that closes the abuse path for good.

It’s already been executed three times this year.

January: Google and partners dismantled IPIDEA, the world’s largest residential proxy network. Thirteen brands, consumer devices recruited through 600+ Android apps.13 In one seven-day window, Google’s threat intel team counted 550+ distinct threat groups using it, including state actors from China, Russia, North Korea, and Iran.14 Court orders killed the storefronts. 7,400+ C2 servers went dark.15

February: GRIDTIDE. A China-linked espionage group had run a backdoor since at least 202316 using the Google Sheets API as command and control. Implants polled spreadsheet cells for instructions, so every byte of C2 traffic looked like a finance team updating a budget file. (I’d almost admire the tradecraft if it weren’t sitting inside 53 victim organizations across 42 countries.17) Google terminated the cloud projects, sinkholed the domains, and revoked the API access. No government on earth can revoke a Google Sheets API key.

July: NetNut. The Popa botnet turned two million smart TVs and streaming boxes into exit nodes for a proxy brand owned by Alarum Technologies, a Nasdaq-listed company.18 Alarum called June’s attribution research “inaccurate,” its SDKs consensual bandwidth-sharing.19 Weeks later Google killed the C2 accounts and disabled the infected apps, while the FBI and IRS Criminal Investigation seized hundreds of domains.20 Then the market ruled: 21% down on takedown day, another 51% four days later, an $8 stock near $2.20 by mid-July, securities-fraud investigations open.21

These are the difference between upstream and downstream.
Disruption cuts the adversary’s supply lines while the campaign is live.
Sanctions show up years after the siege.

Washington has the vocabulary now. National Cyber Director Sean Cairncross and Kevin Mandia shared the Aspen stage talking cost imposition and shaping adversary behavior, and Mandia’s version remains the bluntest: “no travel, no money, no fun.”22 Reach the actual humans.

The direction is right. Consequences have to exceed rewards before operators change behavior, and physical deterrence works when you can reach the body. Against state-protected operators, you usually can’t.

The machinery is the problem. Government cost imposition moves through an interagency process in months.

Joyce’s doctrine: platform authority, civil courts, no hack-back. It’s already producing results. Private tech companies own the infrastructure, the platforms, apps, and networks that these attacks run on. They can shut an operation down directly and immediately.

The CISA 2015 information-sharing protections were a prototype. The next version has to cover coordinated disruption: liability protection, defined authorities, real oversight.

Building that legal scaffolding is also the case I made in the SANS RSAC safe harbor paper, Asymmetry to Parity: attackers operate under zero regulatory constraint while defenders carry legal, insurance, and compliance friction on every action they take.23

The doctrine has three real problems. Ignoring them would make this piece as hollow as Monday’s package.

Reconstitution. Residential proxies are a commodity, and IPIDEA’s successors are being assembled right now. Joyce concedes it herself: “These groups will recover and they will be back.24” The purpose is not elimination. It’s forcing adversaries to rebuild from scratch, which burns months, money, and tradecraft while defenders harden and victims get notified.

Concentration. If disruption capability lives inside five or six companies, who decides which campaigns get disrupted and which is watched for intelligence? Who audits the disruptor when attribution is wrong?

Speed. The loop still runs on human-coordinated legal action, and both Joyce and Mandia expect largely autonomous AI-driven attacks within a few years. A civil court order doesn’t move at the pace of an agentic campaign. (That gap worries me more than anything else in this piece.)

Serious problems, all three. None of them rescue the worse approach.

If you don’t run a hyperscaler, none of this sounds like yours to act on. It is.

Disruption runs on visibility, and the disruptors don’t keep the work to themselves. IPIDEA shipped with intelligence handed to platform providers, law enforcement, and research firms. GRIDTIDE shipped with published indicators and the exact persistence tradecraft to hunt.

  • Hunt it. Pull every non-browser process making Google Sheets API calls from your servers and make someone explain each one. GRIDTIDE persisted as a systemd service dressed up as a Debian utility, moved laterally over SSH using service accounts, and dropped SoftEther VPN Bridge for its outbound tunnel.

  • Audit your systemd services, review authorized_keys on every service account, and flag any VPN bridge nobody remembers installing.

  • Report adversary infrastructure you spot in your own logs to the platforms that can revoke it.

  • Push indicators through your ISAC instead of sitting on them.

  • Write the IR plan assuming no sanctions package is coming to help, because it isn’t.

  • Ask. When a vendor tells you they found adversary infrastructure on their platform, ask what they did about it. Notify-and-wait is an answer worth knowing before you renew.

Fifteen years of attribution, indictment, and sanctions produced a Kremlin statement that could’ve been copy-pasted from 2018. One January takedown produced measurable capability loss across 550+ threat groups the same day25. Sandra Joyce is right. Disruption has to become the status quo. Sanctions can keep the records.

Tell me where you land on this.

Rob T. Lee is Chief AI Officer & Chief of Research, SANS Institute

Read the original on robtlee73.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.