Shadowing Practice: World's Deadliest Computer Virus: WannaCry - Learn English Speaking with Video

Creating lesson...
1
Midnight, China.
2
Hotel in the east of Dalian.
3
A computer glows on a bedside table in a dim hotel room.
4
Its user sits in a deep trance.
5
For five days now, he's been trying to solve a problem.
6
Literally days.
7
He hasn't had much sleep or any real break besides short trips to the hotel's restaurant to grab some food.
8
He's been working on a simple project.
9
How to create a monster.
10
But so far, he hasn't had much luck, and neither have the other peers assigned for the mission.
11
This is not good.
12
Failure means there will be consequences.
13
The user's name is Park, and he's a programmer.
14
Unlike his Hollywood peers, he doesn't spend days tapping away at the keyboard.
15
Instead, he spends most of his time scouring the internet for clues.
16
What can be the thing that makes the monster work?
17
Surely someone out there has found the the missing piece.
18
Perhaps it's somewhere on hacker forums, or for sale on the dark web.
19
He searches again and again, but nothing.
20
So far, the only thing they have is a leak.
21
Recently, a trove of incredibly advanced cyber weapons was stolen from the NSA and dumped into the wild.
22
But they are useless unless you find a way to make them work with your code.
23
A way neither Park nor his co-workers have found.
24
All they need is...wait, what was that?
25
Eternal Eternal Blue.
26
Somebody reverse engineered Eternal Blue, one of the NSA's top tools.
27
Could this work?
28
He looks through the code.
29
This is wonderful.
30
Thrilled, he gets to work.
31
Several hours later, the monster is almost ready.
32
Park is exhausted, but satisfied.
33
With just a few tweaks, the superiors will have precisely what they requested.
34
Finally, he has earned his rest.
35
He turns off the computer and finds a small bed in the rim's corner.
36
The next morning, Park turns the computer back on, determined to give the monster the finishing touches.
37
Except, the monster has vanished.
38
Frantically he searches file by file.
39
Nothing is there.
40
The machine's been wiped clean.
41
A message comes through.
42
His lead, Kanban in Korean, congratulates him for the hard work.
43
They… they didn't wait.
44
An order came.
45
They released the monster.
46
Unfinished.
47
panic sets in, but it's too late.
48
The monster is already wreaking havoc, crippling computers in schools, train stations, offices, and hospitals one by one.
49
WannaCry, one of the deadliest malware specimens in history, was released on May 12, 2017, and rewrote cybersecurity for good.
50
After that, there was no rollback.
51
World War II split the Korean Peninsula into two parts.
52
Then the Korean War happened, which changed nothing except destroying millions of lives and leaving the peninsula in ruins.
53
It also cemented the unending rivalry between what we know today as North Korea and South Korea.
54
After the war, North Korea was backed up by two powerful parents, the USSR and China.
55
However, in the 1990s, as the USSR collapsed and China opened itself to the world, Pyongyang isolated itself.
56
Reaching out to the USA and its allies meant sleeping with the enemy.
57
So instead, it closed off.
58
Famine and hardships developed quickly.
59
So North Korea had to create its own system to survive.
60
A practice that continues this very day.
61
Crime.
62
It started with counterfeits, everything from Viagra to birth control, and even forged U.S currency.
63
But as the world became digital, Pyongyang saw the opportunity to take its criminal activities to new heights.
64
Their testing ground was close to home, South Korea.
65
Between 2009 to 2013, North Korea terrorized its neighbor with cyber attacks.
66
At first they were denial of service or, in simple terms, overwhelming websites with requests to shut them down.
67
But soon the attacks became more complex.
68
In March of 2013, the North Korean military unleashed a coordinated day of digital strikes against the capital of South Korea, Seoul.
69
It used a type of malware called dropper trojan, specifically designed to target South Korean systems.
70
Within hours, 32,000 machines were infected, including two major banks and three of the largest TV stations.
71
This was clearly not an isolated IT outage.
72
Offices, ATMs and TVs across Seoul went dark.
73
Dark Seoul.
74
And with it came a revelation.
75
North Korean hackers were no rookies.
76
They were becoming sophisticated, precise and deadly.
77
Soon the rest of the world would learn that lesson.
78
A year later, in 2014, Sony Pictures was preparing to release a comedy that mocked North Korea's leader, Kim Jong-un.
79
Pyongyang heard about this plan and did not like it. At all.
80
And if they could not yet launch a missile across the Pacific, at least they could strike America's propaganda machine with their growing cyber army.
81
Through a carefully planned spear-fishing campaign, North Korean hackers breached Sony.
82
They stole information about the studio staff, unreleased movies, and even private emails between celebrities.
83
they dumped it all into the public domain, sparking chaos.
84
A country with only 1,024 IP addresses and limited broadband had just hacked Hollywood.
85
Here we briefly pause to ask you to subscribe and like this video.
86
We put a lot of effort into our content and your support will help us grow.
87
Plus, we have other great videos about North Korea, like the Sony hack and the general history of North Korean cyber operations.
88
Feel free to check them out after this video for extra content.
89
Cybercrime had proven itself a powerful weapon for grabbing headlines and disrupting global discourse.
90
But could it also bring profit?
91
Crime had helped North Korea through famine, so perhaps cybercrime could follow its legacy.
92
It was time for pragmatic hacking.
93
By 2015, the banking sector came under attack.
94
Vietnam's Tian Phong Bank, several Polish banks, and various financial institutions in Mexico and Uruguay all reported North Korean intrusions.
95
But these incidents were just rehearsals for something bigger.
96
first major financially motivated cybercrime from North Korea, the Bangladesh heist.
97
This cyber heist shook the world for its magnitude.
98
After lurking inside the bank's system for nearly a year, the hackers attempted to steal $1 billion.
99
They sent phishing emails, compromised the bank's SWIFT mechanism, which is how financial institutions send and receive requests for money transfers,
100
and authorized about three dozen requests to the Federal Reserve Bank of New York.
101
Fortunately, the New York bank noticed the strange requests and stopped the attack.
102
But the attackers still managed to steal $100 million.
103
The message here was clear.
104
North Korea's cyber operatives were disciplined, persistent, and dangerously effective.
105
In 2016, North Korean hackers no longer surprised the world.
106
People had gotten used to this country making headlines.
107
By that time, tensions between North Korea and the West began boiling.
108
Again.
109
Kim was testing nuclear weapons.
110
Again.
111
Sanctions piled on.
112
And even China, North Korea's longtime ally, expressed some mild criticism.
113
The world was turning on North Korea, and pressure was mounting on the country.
114
But this time, things were different.
115
They were no longer limited to simple DDoS attacks.
116
They had forged an army of elite threat actors that could hijack film studios, banks, and plunge entire country's infrastructure to darkness.
117
In April 2017, Kim and his cyber army were entangled in all kinds of complicated geopolitical games.
118
However, something else was beginning to stir public discourse.
119
a new player had stepped onto the stage, one that would help fuel the birth of many monsters, the Shadow Brokers.
120
It was a mysterious group of hackers who started posting cryptic messages on social media between late 2016 and early 2017.
121
The rants were incoherent, with purposefully bad English, and filled with strange geopolitical commentary.
122
They just looked like a band of sketchy script kiddies, but this was nothing but obfuscation.
123
Shadow Brokers' posts had links, and those links contained entire caches of malware.
124
stolen straight from the National Security Agency of the United States.
125
The NSA had been quietly hoarding these for years.
126
Among them was EternalBlue, a tool that exploited an obscure vulnerability and allowed the takeover of any Windows machine.
127
The agency had known about that vulnerability since 2012.
128
Still, instead of bringing it up with Microsoft to ensure the safety of millions of users, it had chosen to remain silent and develop a tool that took advantage of this situation.
129
In 2017, right before the exploit was leaked, Microsoft finally patched the vulnerability, probably because, seeing their tools stolen, the NSA tipped the company off.
130
Typically, this should have limited the damage.
131
However, users rarely update their devices, some out of ignorance, others out of habit, and most out of inconvenience.
132
So for most users, the patch came too late.
133
By late April, the exploits were already dissected by security researchers.
134
Back then, if you dipped your toe into the InfoSec community, you probably were aware of how massive this development was, not least because everybody was discussing it.
135
One of the companies joining the conversation was RiskSense, a cybersecurity firm that, like everybody else, published its own take on the exploits.
136
But RiskSense stands out for one thing.
137
It became the unexpected catalyst in the chain of events that triggered WannaCry.
138
Only three days before the attack, a senior staff member posted in RiskSense's GitHub, a developer's website.
139
But this entry was not just another write-up of Eternal Blue.
140
He had reverse-engineered its code.
141
In a nutshell, he disassembled the complex tool to understand how the exploit worked.
142
That 9th of May, or perhaps a day or two later, North Korean threat actors stumbled upon the post.
143
It was exactly what they needed.
144
With this knowledge, they could learn how to use Eternal Blue and combine it with another exploit, Double Pulsar, to create the ultimate cyber weapon,
145
a ransomware crypto worm that would spread automatically faster than anything they had ever created.
146
But was this really what North Korea was looking for?
147
Let's go back to Kim and his cyber army now.
148
By late 2016, Kim was growing increasingly frustrated, and by 2017, the tensions peaked.
149
But North Korea wasn't seen as a powerful adversary.
150
Instead, people saw it as a reckless outcast.
151
Perhaps what the world needed was a show of force.
152
Perhaps this was the right time to unleash their shiny weapon.
153
But there was a problem.
154
The monster was not ready.
155
Yes, it was already capable of significant damage, but it was still flawed.
156
Imperfect monsters are dangerous.
157
They can slip out of control if not handled correctly.
158
And maybe the tension and stress made North Korea careless.
159
Or perhaps not.
160
Maybe it was deliberate.
161
Perhaps desperation led them to act fast while they still had a chance.
162
Whatever the case, on May 12th, the malware was unleashed.
163
And in less than a working day, it spread across the world, paralyzing more than three-fourths of it.
164
The world was under the grip of a beast.
165
At least, until around lunchtime.
166
WannaCry is regarded as one of the deadliest ransomware outbreaks in cybersecurity history.
167
But the irony is that the malware itself is not particularly advanced.
168
Its true power came from two things, how it infected and how it spread.
169
Most of these characteristics came courtesy of the United States, the staunchest enemy of North Korea.
170
The deadly combination of the NSA's exploits, EternalBlue and DoublePulsar.
171
EternalBlue enables remote code execution on unpatched Windows machines.
172
It uses the SMB v1 protocol, a system that Windows computers use to communicate and share files.
173
It is the best known of ShadowBroker's tools, and we explained it in detail in our video about Napetya, another devastating cyber attack this exploit enabled.
174
Double Pulsar is slightly less known.
175
In the leak, it was bundled together with Eternal Blue, and doesn't really work without a decent penetration tool like that.
176
Because in essence, Double Pulsar is a backdoor, a passage that, when installed, keeps access to the target's system, like a tunnel connecting the attacker and the victim.
177
It doesn't cause any damage, in fact it's designed to be so low profile that it's pretty much undetectable.
178
But through this tunnel, other, nastier things can be smuggled.
179
So once inside, once EternalBlue broke the victim's defenses and DoublePulsar established a tunnel through them,
180
WannaCry deploys its payloads, two simple encryption algorithms that crawls through the system
181
and turns everything they see into gibberish with the .wncry extension.
182
Before finishing the process, the malware deletes any shadow copies in the victim's computer, making the recovery of the files incredibly difficult.
183
Then the cherry on top, it executes its famous red screen.
184
Oops, your files have been encrypted.
185
If you want to decrypt all your files, you need to pay.
186
You only have three days to submit your payment.
187
If you don't pay in seven days, your files will be lost forever.
188
Send $300 worth of Bitcoin to this address.
189
Just imagine seeing all of this on your computer.
190
Panic is inevitable.
191
The first red screens appeared around 7.44 a.m in Southeast Asia.
192
Within an hour, it spread to Latin America.
193
and around 10 a.m.
194
UTC, it was already causing mayhem in Spain, France, Germany, and the United Kingdom.
195
Train stations, offices, schools, anywhere with computers woke up with WannaCry's mark.
196
WannaCry is considered self-propagating malware.
197
This is because, unlike most malware, it doesn't need phishing emails or human interaction to spread.
198
Instead, it moves on its own from one infected computer to others connected to external and internal networks, all thanks to EternalBlue.
199
This vulnerability allowed hackers to execute arbitrary code on a victim's computer and install the ransomware.
200
From there, the infected machine would scan local networks and the internet for unpatched systems, breaking into as many as possible.
201
While the malware was spreading all over Europe, it was severely affecting the UK's National Health Service.
202
At first, only a couple of hospitals were hit, then dozens.
203
And at some point, one-third of its infrastructure collapsed.
204
One of the people witnessing this crisis as it unfolded in real time was Tony Bleepman, a doctor working as an emergency consultant in London during the attack.
205
I went to work a locum shift, I was not a regular member of staff in a London hospital.
206
My shift started at midday
207
and I got there just before midday to the consultant's office
208
where a lot of people were sitting around their computers
209
and pretty much as I arrived the WannaCry virus came up on everybody's screen.
210
About the same time people were getting phone calls from other people that this had happened in other parts of the NHS.
211
It became clear fairly shortly that the IT had been significantly compromised.
212
With hospitals nationwide struggling to operate, the medical staff had to adapt to the chaos as quickly as possible.
213
It was decided that we would just do what we did before there was IT in hospitals.
214
So instead of having a map on the screen of where every patient was, we took an old-fashioned
215
whiteboard and marker pens and we drew a plan of the department
216
and somebody was put in charge of that board to record where all the patients were and where they were moving to.
217
We rapidly moved to paper registration and paper note keeping for patients.
218
While the staff did everything they could to keep hospitals functioning normally, surgeries and appointments were postponed.
219
Hundreds of patients were left in limbo, uncertain when or how their procedures would happen.
220
But I think you need to look at the wider impact as well.
221
Since about 2010 there has been a regionalisation of specialist services.
222
So London, with a population of approximately 12 million, has only four major trauma hospitals and a limited number of heart attack centres.
223
And they rely on networks for referrals and for receiving patients.
224
And so that was problematic in
225
that some patients in smaller hospitals had difficulties in getting critical patients to the tertiary centres
226
because I heard this but I'm not sure if it's true
227
that in at least one of the trauma centers everything apart from immediate life-saving surgery was cancelled
228
because there was no access to the support systems that the surgeons required.
229
I'm not sure that's verified but that's what I heard on the day
230
that non-essential operating had stopped
231
and I think for a short time there was a pause
232
in invasive cardiac procedures as well in the regional centers the situation was scary,
233
and it didn't take long for most of the country to get glued to the nearest radios, TVs, and computers.
234
Among them was a UK researcher named Marcus Hutchins.
235
At 2.30 p.m.
236
Marcus had just finished lunch and returned home.
237
He had a few days off, so he was taking it easy.
238
But the moment he opened his computer, the scale of the crisis hit him, and he felt he needed to do something.
239
Marcus recalls the motions of that day with Jack Recider on Darknut Diaries
240
when he was brought back to his old parents' room.
241
And my first instinct was this isn't phishing, this is hitting way too many organizations, way too many parts of the same organization,
242
it has to be something bigger.
243
So I went and asked my friend Caffeine, can I have a sample of this?
244
And the second I looked at it, I was like, oh this is bad.
245
As Marcus continued to investigate the malware, he quickly noticed something else unusual.
246
The worm was trying to connect to a random domain before deploying its payload.
247
And when I saw this unregistered domain in the WannaCry code, I was like, nice, this is probably a command and control server.
248
So I registered it.
249
And then I started looking, what can I do with this code?
250
What can I do with the control of this domain?
251
I'm thinking it's a command and control server and maybe we can exploit a vulnerability.
252
But it actually turned out while we were trying to figure out what is the purpose of this domain?
253
What does it actually do?
254
We had already stopped WannaCry because the domain was a kill switch.
255
With the domain registered, WannaCry couldn't cause any further damage.
256
It didn't erase existing infections, but it did stop the malware's attack.
257
By 1503, the destruction was officially over.
258
Marcus had just become a hero in cybersecurity history, and computers around the world could finally breathe again.
259
However, the case of WannaCry was far from being solved.
260
WannaCry hijacked an estimated 200,000 computers across 150 countries, infecting almost a few every country worldwide,
261
all through just two hours of being operational.
262
And it could have easily caused more damage if not for the discovery of the kill switch.
263
Something that makes you instantly wonder, what was the kill switch doing there?
264
And more importantly, what was the real purpose of the attack?
265
The UK police launched an investigation to answer some of those questions, but the mystery only deepened as new details of WannaCry emerged.
266
For example, it was revealed that the scheme generated less than $200,000, a small sum for the scale of the attack.
267
Not only did many victims refuse to pay, but the payment mechanism was essentially useless.
268
Unlike better-designed ransomware, WannaCry had no automated system for distributing decryption keys or tracking who had paid and who hadn't.
269
It was odd.
270
Too odd for threat actors who are supposedly in it for the money.
271
This led to a darker theory.
272
Perhaps WannaCry was not about money.
273
The kill switch supported this theory.
274
Some researchers believed it was not meant to stop the worm but to cover the hacker's footsteps.
275
The kill switch was a way for the worm to understand whether it operated in an organic environment or a sandbox.
276
A sandbox is a virtual computer used to run malware for research purposes.
277
So in this case, if the malware detected a connection to a certain domain, it would shut itself off, assuming it was being studied.
278
However, the creators of WannaCry have been sloppy.
279
The domain was not different for each infection, it was static.
280
So when Marcus registered it, The worm believed the entire internet was a sandbox and shut itself off.
281
If the domains had been different for every computer, the kill switch would have only worked for Marcus, and the infection would have continued spreading.
282
That would be a smart way to design ransomware, the way nearly every known attack works.
283
But in other aspects, WannaCry was pretty sophisticated and was definitely designed with a lot of care and a lot of resources.
284
So the most logical explanation was that the malware was simply unfinished.
285
Somebody released a testing version instead of the final one.
286
The set of circumstances that led to WannaCry was so insane
287
because of course you have the Shadow Brokers leak and the Shadow Brokers isn't, they haven't attributed yet but it's widely believed to be Russian intelligence.
288
So Russian intelligence hacks the NSA, steals one of their most prized vulnerabilities, leaks it onto the open internet,
289
at which point North Korea pick it up and decide to make ransomware with it,
290
and we're not even to this day sure whether WannaCry was supposed to be released yet.
291
There are a lot of just signs in in the code
292
that it might have been a work in progress that accidentally leaked a little earlier than they had intended it to.
293
As the investigation progressed, the UK brought the case to America, which uncovered the nastier side of it.
294
At the end of the day, the NSA's fingerprints were all over the two stolen exploits that made WannaCry work, Eternal Blue and Double Pulsar.
295
WannaCry's power came straight from America's intelligence, and working together, British and American investigators discovered who was behind the worm.
296
First, the FBI analyzed WannaCry's code and concluded that there were at least two other versions of the malware, dating from February and April of 2017.
297
All three versions shared the same code.
298
No reverse engineer was involved.
299
This was the work of a single group of threat actors.
300
Then came another revelation.
301
WannaCry had much in common with other infamous cyber attacks.
302
The malware data chart matched the one used in the Sony and Bangladesh cyber attacks.
303
Also, the development environment was the same.
304
Visual C++, and while this alone does not guarantee that the malware creators were the same, one discovery made the difference.
305
Several IPs and email addresses were reused across WannaCry, Sony, and Bangladesh.
306
It was like finding that after robbing three separate places, the burglars went to the same warehouse to store the stolen goods.
307
All of these attacks had been perpetrated by the same threat actor, and all the evidence was pointing in one direction.
308
Lazarus Group.
309
Lazarus Group, also known as Guardians of Peace or Who Is Team, is believed to be behind most of North Korea's cyber attacks.
310
Jeff White, an investigative journalist, explores this group in great detail and believes these hackers never act independently.
311
They are North Korea's war machine.
312
Some hackers working for North Korea are accused of attacking banks.
313
Some are accused of attacking governments or media organizations.
314
So there's this idea that there are different teams.
315
And yes, they will be within the military because North Korea is a highly militarized society.
316
From memory, I think something like 5 or 6 million of its 25 million inhabitants are in the military services.
317
So yes, the hackers will be inside the military.
318
They will be part of an organizational structure.
319
They will have a commanding officer who is controlling what they do.
320
So that's the sort of setup in terms of the hackers.
321
There was one more thing all of these attacks had in common.
322
Tracing them and connecting them allowed the investigators to finally connect the Lazarus Group to a real person,
323
turning what used to be a shadowy organization with ties to North Korea into a group of operatives with faces and names.
324
In the aftermath of the Sony hack and the Bangladesh heist, FBI agents found a shared network of emails that led them to a mysterious user, Kim Hyun-woo.
325
Although this turned out to be a fabricated persona, the alias was actually helpful for the FBI.
326
They connected this alias to Chosin Expo Group, a North Korean front company for state-sponsored hacking.
327
Chosun Expo was initially an experimental venture between North Korea and South Korea.
328
It sold everything from lottery tickets to mushrooms and even ornate bases.
329
But at some point, South Korea withdrew from the venture, and North Korea maintained the business.
330
On paper, the company's purpose was to supply various goods and services, including software, freelancing software development, and gambling-related products.
331
But this was only on paper.
332
The FBI soon uncovered that Chosen was connected to the Sony and Bangladesh incidents.
333
Not only was it using an official government-run email account to target victims, but the logins of Chosen Expo's website were tied to the network of fake email accounts used in the attacks.
334
The evidence was clear.
335
Whoever ran the company's website also participated in the cyber attacks.
336
They came across a Gmail address, a Google email address that had been used in that attack.
337
So they issued a warrant to Google and said, we want the data on this account.
338
And they discovered a CV
339
that had been sent by one of the allegedly North Korean
340
hackers to his new employer in China as he was going across the border to work for this company in China.
341
And of course, it had his photo and his name and all that kind of thing.
342
And they had this whole correspondence about how this North Korean was looking forward to going over to China, to set up in China and to have this new life.
343
Incredible privilege, by the way, to travel abroad as a North Korean.
344
His name was Park Jin-hyuk.
345
Unlike other nicknames and aliases found during the investigation, he did not have a ghostly presence.
346
His birthday, education, language proficiency, and skills were all in the hands of investigators.
347
And this was just enough to build a case.
348
North Korea's cyber army was behind the attacks.
349
And Park Jin-hyuk was the executioner's hand.
350
By the end of 2017, the USA publicly shared that North Korea was behind WannaCry.
351
The press and the White House spoke openly, pointing to Pyongyang, claiming that the reason behind the attack was to generate chaos against the USA and allies,
352
something that North Korea obviously denied.
353
But there was one detail the White House conveniently did not mention.
354
As discussed thoroughly during this video, WannaCry did not have a trigger or respond to one clear event.
355
Instead, it combined various factors including North Korea's thirst for power, the shadow broker's leak, and indirectly, the NSA's obsession with exploits.
356
Brad Smith, president of Microsoft, acknowledged this in a post after the incident.
357
In it, he heavily criticized the U.S and its tendency to hoard exploits, comparing the situation to the U.S military having some of its Tomahawk missiles stolen.
358
This was not taken well in Washington.
359
The U.S government tried its best to deflect the questions surrounding America's indirect role in WannaCry, and when asked whether the NSA was accountable for WannaCry,
360
their Your answer was...
361
No, not at all.
362
WannaCry resulted from a chain of events that fueled a beast, but North Korean threat actors could not have completed this beast without the Shadow Brokers leaks.
363
Luckily, we have a video about this mysterious group on our channel if you want to learn more about their story, and how those leaks came to be.
364
Thank you for watching, and we'll see you in the next video!

Vocabulary and speaking notes for this lesson

This B2 speaking lesson is built on the video “World's Deadliest Computer Virus: WannaCry”. The speaker keeps coming back to these words: Wannacry, Korea, attack. This video has 364 sentences and 4610 words to shadow. The speech runs for 27:08. The speaker talks at a natural 170 words per minute, close to everyday conversation. Only 78% of the words are among the 3,000 most common in English, so the vocabulary is demanding.

Key vocabulary in this video

The 15 most advanced words in the video, with pronunciation and meaning:

WordPronunciationMeaning
malware noun/ˈmæl.wɛəɹ/Software which has been designed to operate in a malicious, undesirable manner.
cyber adjective/ˈsaɪ.bəɹ/Of, or having to do with, the Internet; alternative form of cyber-.
hacker noun/hækəɹ/Someone who hacks.
exploit noun/ˈɛksplɔɪt/A heroic or extraordinary deed.
leak noun/liːk/A crack, crevice, fissure, or hole which admits water or other fluid, or lets it escape.
worm noun/wɝm/A generally tubular invertebrate of the annelid phylum; an earthworm.
vulnerability noun/ˌvʌln(ə)ɹəˈbɪlɪti/The state of being vulnerable; susceptibility to attack or injury, either physical or emotional; the state or condition of being weak or poorly defended.
cybersecurity noun/saɪbəsɪˈkjʊəɹɪtɪ/Security against electronic attacks such as cyberwarfare or cyberterrorism.
infect verb/ɪnˈfɛkt/To bring (the body or part of it) into contact with a substance that causes illness (a pathogen), so that the pathogen begins to act on the body; (of a…
cybercrime nounCrime committed using computer networks.
heist noun/haɪst/A robbery or burglary, especially from an institution such as a bank or museum.
phishing noun/ˈfɪʃɪŋ/The malicious act of keeping a false website or sending a false e-mail with the intent of masquerading as a trustworthy entity in order to acquire sensitive…
sandbox noun/ˈsæn(d).bɑks/A children's play area consisting of a box filled with sand.
investigator noun/ɪnˈvɛs.tɪˌɡeɪ̯.təː/One who investigates.
mysterious adjective/mɪˈstɪɹi.əs/Of unknown origin.

Phrasal verbs you will hear

WordMeaning
back up verbTo move backwards, especially for a vehicle to do so.
close off verbTo seal or block the entrance to a road, an area, or a building so that people cannot enter.
come across verbTo change sides; to cross over to work for the opposition.
come through verbTo come into a room or other space through a door or passageway.
come under verbTo come underneath (something).
figure out verbTo come to understand; to discover or find a solution; to deduce.
go back to verbTo stem from; to originate in.
look forward to verbTo anticipate, expect, or wait for, especially with a feeling of approval or pleasure; to be excited or eager to.

Grammar in this video

The structures the speaker uses most, with the exact words from the video:

StructureIn the video
“Used to” used to + verb — a past habit or state that is no longer trueused to this · used to run · used to be
Passive voice be + past participle — the focus is on what happens, not who does itwas stolen · is exhausted · been wiped
Present perfect have/has + past participle — a past action that still matters nowhas found · have found · has earned

Pronunciation to watch

The speaker uses 21 contractions and reduced forms, such as doesn't, didn't, I'm. Say them the short way, as you hear them.

  • The “sh” and “zh” sounds: phishing /ˈfɪʃɪŋ/, unleash /ʌnˈliʃ/, unfinished /ʌnˈfɪnɪʃt/, revelation /ˌɹɛv.əˈleɪ.ʃən/
  • Long words — get the stress right: vulnerability /ˌvʌln(ə)ɹəˈbɪlɪti/, cybersecurity /saɪbəsɪˈkjʊəɹɪtɪ/, investigator /ɪnˈvɛs.tɪˌɡeɪ̯.təː/, mysterious /mɪˈstɪɹi.əs/, operative /ˈɑpəɹətɪv/

How to practise with this video

  1. Listen to the whole video once without speaking and note the words you do not know.
  2. Start at 0.75× speed, shadow it sentence by sentence, then go back to normal speed once it feels easy.
  3. Record yourself and compare with the original, paying attention to words like malware, cyber, hacker.

What is the Shadowing Technique?

Shadowing is a science-backed language learning technique originally developed for professional interpreter training and popularized by polyglot Dr. Alexander Arguelles. The method is simple but powerful: you listen to native English audio and immediately repeat it out loud — like a shadow following the speaker with just a 1–2 second delay. Unlike passive listening or grammar drills, shadowing forces your brain and mouth muscles to simultaneously process and reproduce real speech patterns. Research shows it significantly improves pronunciation accuracy, intonation, rhythm, connected speech, listening comprehension, and speaking fluency — making it one of the most effective methods for IELTS Speaking preparation and real-world English communication.

Shadowing technique: read the full step-by-step guide →