The Deception Chain: What Changed, What Didn't

Part 2 of a three-part synthesis of the Cybersecurity Defense Lab series

HOW TO

8/21/202610 min read

Two Scenes, Seven Years Apart

In 2007, a banking trojan spread by posing as a Flash Player update. A user saw a familiar dialog box, clicked "update," and handed over their banking credentials without a second thought.

In January 2024, a finance employee at the engineering firm Arup joined a video call with his CFO and several familiar colleagues. He had doubts. The doubts dissolved when he saw their faces and heard their voices. He authorized fifteen transfers totaling $25.6 million. Every person on that call was synthetic.

Seven years apart, the two incidents share almost nothing at the level of technology. One is a static file exploiting a trust in software update mechanisms. The other is a real-time, interactive fabrication exploiting trust in human perception itself. What they share is the target: a person, asked to make a judgment, under conditions engineered to make the wrong judgment feel safe.

The previous article in this series asked how much autonomy malicious code has — how far it can act without a human decision in the loop. This one asks a different question about the threats that still need that decision: how sophisticated does the lie aimed at the human have to become, and has anything that defends against it kept pace?

Three threat classes trace this arc: trojans, social engineering, and ransomware. Read separately, they are three chapters. Read together, they describe one escalating lie, told about three different things.

Stage One: The Disguise

A trojan's entire mechanism rests on a single question, asked once: is this file what it claims to be?

The earliest example on record barely qualifies as an attack. ANIMAL (1975), written by John Walker, was a guessing game. To make it easier to distribute, Walker wrote a small subroutine called Pervade that quietly copied the game into other directories while it ran. There was no malicious intent — Walker later called it a good idea. But the architecture of software that silently propagates itself in the background, without the user choosing to install anything, was born here regardless of intent.

By the late 1990s, that architecture had a purpose. NetBus (1998), written by Carl-Fredrik Neikter, was marketed by its author as a legitimate remote administration tool — the name itself is Swedish for something close to "network prank." Its capabilities were, correspondingly, mostly harmless: opening and closing a friend's CD-ROM drive, moving their cursor.

A year later, Sub7 — its name a reversal of NetBus, built by a developer known as Mobman — discarded the pretense of a joke. It captured keystrokes, activated microphones without indication, and enabled remote camera access. The disguise had not changed in kind. It had changed in what it was hiding.

The next evolution was economic rather than technical. Zeus (Zbot), prominent from roughly 2007 onward, frequently arrived disguised as a Flash Player update — a piece of software update UX so familiar that users had been trained, correctly, to trust it in almost every other context. Emotet, first identified in 2014, began as a banking trojan and evolved into something closer to infrastructure: a modular delivery platform that distributed other malware families, including TrickBot and IcedID, effectively renting access to compromised machines to other criminal operators.1 TrickBot itself, emerging in 2016, followed a similar arc from banking credential theft toward serving as an early-stage foothold for large-scale ransomware operations — the precursor to what the industry now calls "big-game hunting."

The disguise, across three decades, is aimed at exactly one moment: execution. Once you have decided to run the file, the trojan's job is finished — everything after that is a consequence of a single, already-made decision.

This is why the trojan produced a legal artifact unique among the threats in this series: the SODDI defense, or "some other dude did it" — defendants in criminal cases arguing that a trojan, not they, performed the actions logged on their machine. The defense forced courts to grapple with a genuinely hard evidentiary question: if a machine's actions can be attributed to code the owner did not know was there, how do you prove intent?

That question — what a machine's actions actually prove about the person behind it — becomes considerably sharper in the next stage, where the machine is no longer hiding an intruder. It is impersonating someone you already trust.

Stage Two: The Performance

A trojan deceives about an object. Social engineering, in its current form, deceives about a person — and unlike a file, a person can be interrogated. They can be asked to turn their head. They can be asked a question they should know the answer to. The lie has to survive interaction, in real time, which is a categorically harder thing to sustain than a disguised file sitting quietly on disk.

The scale of this shift shows up in the numbers before it shows up in any single case. The FBI's Internet Crime Complaint Center, in its 2025 annual report, recorded more than $20 billion in reported losses from internet-enabled fraud — with business email compromise alone accounting for over $3 billion.2 More tellingly, the report included, for close to the first time in its history, a dedicated section on AI-enabled fraud: over 22,000 complaints and $893 million in losses attributed specifically to techniques like AI-generated writing that mimics an executive's style, and voice cloning used to confirm a fraudulent request by phone.

The Arup case, described above, is the clearest illustration of what that statistic looks like in practice. What makes it useful for analysis is not just its scale but a detail in Arup's own account of the incident: the attackers built every synthetic face and voice in that call from material that was already public — conference recordings, earnings calls, video interviews. No breach was required to obtain the raw material for the deception. It had been given away voluntarily, over years, in the ordinary course of business.

A useful contrast arrived within the same window. Weeks before Arup's case became public, the advertising conglomerate WPP was targeted by a nearly identical scheme: a cloned voice of CEO Mark Read, a fake WhatsApp account, a staged Microsoft Teams meeting soliciting a "new venture." It failed. The targeted executive grew suspicious and verified the request independently. Same technique, same period, opposite outcome — and the variable was not the sophistication of the fabrication. It was whether the target routed the decision through a second channel before acting.

The deception extended into a domain with lower production values but an equally direct payoff: hiring. In one documented case from early 2025, a candidate secured a position at Infosys by having a friend sit in for the video interview. No synthetic media was involved — the technique was as old as impersonation itself. The fraud held for roughly two weeks, until the gap between interview performance and actual job performance became impossible to miss, and the candidate was terminated and criminally charged.3

That the same class of fraud succeeds with sophisticated real-time video fabrication and with a friend on a webcam is the point. Security researchers at Palo Alto Networks' Unit 42 demonstrated that a real-time synthetic video identity capable of passing a casual interview can be produced by someone with no prior experience in roughly seventy minutes, using inexpensive consumer hardware.4 Separately, GetReal Security's 2025 survey found that more than 41 percent of enterprises had unknowingly hired a fraudulent candidate at least once, and Gartner has projected that by 2028, one in four job applications globally will be fabricated in some way.5

The response emerging from this pattern is not a new detection technology. It is a rollback of the channel itself. Companies including Google, Cisco, and McKinsey have begun reintroducing in-person interviews specifically to counter AI-assisted candidate fraud6 — the same logic, applied to hiring, that led the WPP executive to pick up a phone instead of trusting a Teams call: when a channel becomes cheap to fabricate, move the decision to a channel that is not.

That principle — verify through a different path than the one carrying the request — is the only defense in this section that appears more than once. It is worth holding onto, because it reappears, unexpectedly, in the section that follows.

Stage Three: The Bargain

The first two stages deceive about identity — what a file is, who a person is. The third deceives about something else: what will happen if you comply.

Ransomware's origin case makes an unusually direct link between stages one and three, because it is simultaneously a trojan and a bargain. In 1989, Dr. Joseph Popp — a Harvard-trained evolutionary biologist — mailed roughly 20,000 floppy disks to attendees of a World Health Organization AIDS conference, labeled as an educational AIDS risk-assessment program.7 After ninety reboots, the program encrypted file names and demanded $189, payable by mail to a Panama address, for a "license renewal." The disguise (stage one) delivered the payload; the payload's entire function was a threatening transaction (stage three). Many victims, who were AIDS researchers, panicked and wiped their own drives rather than pay — destroying irreplaceable data through the response the attack was designed to provoke.

WannaCry (2017) scaled the same bargain to over 150 countries within hours, using EternalBlue — an exploit developed by the U.S. National Security Agency and subsequently stolen and leaked. What stopped it was not the ransom mechanism but an oversight inside it: security researcher Marcus Hutchins noticed the malware checking whether a specific, unregistered domain was live before proceeding. He registered it — for $10.69 — and the propagation halted. Machines already infected remained encrypted; the kill switch stopped the spread, not the damage already done.

NotPetya, a month later, is the case that most directly undermines trust in the bargain as a category. It presented as ransomware — a payment demand, an encryption routine, the full visual grammar of a ransom note. CISA's technical analysis established that the malware's internal design contained no relationship between a victim's decryption key and their unique identifier, meaning that even a victim who paid in full could not be issued a working key.8 It was not ransomware in any functional sense. It was a wiper wearing ransomware's clothing — the disguise, once again, but now the thing being disguised was not a file's origin. It was the attacker's actual intent. Intelligence assessments have pointed to the Russia-linked group Sandworm as responsible; shipping firm Maersk, pharmaceutical company Merck, and logistics firm FedEx were among the organizations affected, with total damage estimated near $10 billion.

Colonial Pipeline (2021) returns the pattern to a scale closer to Arup: a single compromised VPN credential, on an account without multi-factor authentication, gave the DarkSide group entry to the systems controlling nearly half of the U.S. East Coast's fuel supply. Colonial paid 75 Bitcoin — roughly $4.4 million at the time. The FBI later recovered 64 of those Bitcoin by tracing the wallet through the blockchain, a detail that complicates the bargain in the opposite direction from NotPetya: paying did not guarantee recovery of the ransom for the attacker, either.

By this point, ransomware operators had professionalized the bargain into something closer to a commercial transaction, complete with a name — Ransomware-as-a-Service — customer support channels for victims negotiating payment, and public brand reputations that operators actively managed, because a reputation for not decrypting after payment was bad for repeat business. That last detail is worth sitting with: the ecosystem's stability came to depend, in part, on attackers keeping their word often enough that the bargain remained credible. NotPetya was not a failure of this system. It was an operation that was never part of it, wearing the system's clothing to exploit the trust the system had built.

What Never Moved

Read as three separate threats, these are three technical stories. Read as one axis, they describe the same target, addressed with escalating sophistication:

StageThe lie is aboutWhat the victim must judgeDisguise (trojan)What a file isShould I execute this?Performance (social engineering)Who I'm speaking toIs this really them, right now?Bargain (ransomware)What compliance buysWill this actually resolve the situation?

The production values changed almost beyond recognition — from a floppy disk mailed to a conference to a synthetic executive answering questions on a live video call. What did not change is that every one of these attacks resolves at the same point: a human being, deciding, under manufactured conditions of trust.

And across three decades of escalating production value, the working defense has not diversified nearly as fast as the attacks. It shows up, case after case, as the same move: route the decision through a channel the attacker does not control. The WPP executive placed a call instead of trusting a video feed. Multi-factor authentication is, structurally, a second channel — which is exactly the channel Colonial Pipeline's compromised account lacked. Even WannaCry's kill switch was, from the malware's own design perspective, an out-of-band check — a query to see whether a specific condition was true in a place the malware's authors didn't fully control, which is precisely the kind of check that broke their operation once a defender found it first.

Better detection did not stop the Arup deepfake. Better detection did not save the researchers who wiped their own AIDS research data in 1989. What stopped WPP's near-identical incident, and what has driven Google, Cisco, and McKinsey back to in-person interviews, is not a smarter filter. It's the much older and less glamorous discipline of not letting the channel carrying a request also be the channel that verifies it.

A Different Kind of Target

Every case in this article deceives a human being. The next threat class this series examined does not bother.

When the target of a fabricated instruction is not a person's judgment but an AI agent's context window — text embedded in a webpage, a file, or a search result, indistinguishable to the system from a legitimate instruction — the entire defensive lesson of this article stops applying. There is no channel to diversify, because there was never a human decision in the loop to protect in the first place.

That is where this series goes next.

References

Additional references

Video Companions

This article synthesizes three episodes of the Cybersecurity Defense Lab series:

Next in this series: The Verification Axis — two attacks that broke nothing, forged nothing, and deceived no one, and were dangerous precisely because of it.

  1. CISA, "Emotet Malware Advisory" (AA20-280A); MITRE ATT&CK, Emotet (S0367). https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-280a

  2. Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report. https://www.ic3.gov/Media/PDF/AnnualReport/2025_IC3Report.pdf

  3. The420.in, "Telangana Engineer's 'Dragon'-Style Impersonation Scam Exposed in Infosys Job Fraud." https://the420.in/telangana-engineer-dragon-style-impersonation-scam-exposed-infosys-job-fraud-virtual-interview/↩

  4. Palo Alto Networks Unit 42, "False Face: Demonstrating the Alarming Ease of Synthetic Identity Creation." https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/

  5. GetReal Security, press release, December 2025. https://www.prnewswire.com/news-releases/new-getreal-security-research-41-of-enterprises-surveyed-report-having-hired-and-onboarded-fraudulent-candidates-302638982.html ; Gartner, newsroom press release, July 2025. https://www.gartner.com/en/newsroom/press-releases/2025-07-31-gartner-survey-shows-just-26-percent-of-job-applicants-trust-ai-will-fairly-evaluate-them

  6. Computerworld, "To Counter AI Cheating, Companies Bring Back In-Person Job Interviews." https://www.computerworld.com/article/4044734/to-counter-ai-cheating-companies-bring-back-in-person-job-interviews.html

  7. Contemporary and retrospective technical accounts of the AIDS Trojan (PC Cyborg) incident, 1989.

  8. CISA, Alert on Petya/NotPetya ransomware. https://www.cisa.gov/news-events/alerts/2017/07/01/petya-ransomware

© 2026. All rights reserved.