Persōna Theory: Infiltration and Deception of Emerging Threat Groups

Tammy Harper (Senior Threat Intelligence Researcher · Flare)

NorthSec 2025 · Day 2 · Ville-Marie · Conference

Overview

Threat intelligence teams that want to infiltrate emerging ransomware and cybercrime groups need more than technical skill — they need operationally coherent digital personas built on a systematic framework of linguistics, OPSEC, OSINT, and social engineering. Tammy Harper of Flare draws on Carl Jung's original concept of the persona and applies it to the practice of infiltrating ransomware recruitment phases, where operators are actively seeking affiliates and their receptiveness to unknown contacts is at its peak. The talk includes live chat logs from successful infiltrations of named ransomware groups, practical guidance on timezone shifting and writing style adaptation, and case studies of both successful and failed approaches. ---

Watch on YouTube

Visual summary for Persōna Theory: Infiltration and Deception of Emerging Threat Groups by Tammy Harper
Visual summary for Persōna Theory: Infiltration and Deception of Emerging Threat Groups by Tammy Harper

Key moments

  1. 1:30 Recruitment phase is optimal window: operators expect cold contact
  2. 2:59 Ramp RaaS recruitment posts: 80/20 splits, capability listings, affiliate ads
  3. 4:29 VanHelsing produced actual cinematic recruitment commercial for affiliates
  4. 7:29 Sloglav infiltrated via minimal credibility claim leveraging current news groups
  5. 15:01 Transliteration defeats LLMs: Russian phonetically in English characters
  6. 18:01 Engineered conflict resolution builds trust faster than positive rapport alone
  7. 21:02 Apos ransomware builder obtained via slow mentor persona without payment
  8. 30:06 Insider disruption: planted persona caused group infighting, zero attacks launched

Persōna Theory: Infiltrating and Deceiving Emerging Threat Actor Groups

Speaker: Tammy Harper (Flare)

Conference: NorthSec 2025 — May 15–16, 2025, Marché Bonsecours, Montreal

Watch on YouTube: https://www.youtube.com/watch?v=WSMDOh1oqs4

Reading time: ~8 minutes

TL;DR

Threat intelligence teams that want to infiltrate emerging ransomware and cybercrime groups need more than technical skill — they need operationally coherent digital personas built on a systematic framework of linguistics, OPSEC, OSINT, and social engineering. Tammy Harper of Flare draws on Carl Jung's original concept of the persona and applies it to the practice of infiltrating ransomware recruitment phases, where operators are actively seeking affiliates and their receptiveness to unknown contacts is at its peak. The talk includes live chat logs from successful infiltrations of named ransomware groups, practical guidance on timezone shifting and writing style adaptation, and case studies of both successful and failed approaches.

Introduction

In Jungian psychology, the persona is the social mask — the face an individual constructs and presents to the world to navigate different contexts and relationships. Everyone manages personas; everyone social engineers. Tammy Harper opens her talk at NorthSec 2025 by grounding this well-understood human behaviour in its application to digital intelligence gathering.

Creating a synthetic online identity for the purpose of infiltrating a closed criminal community is not simply a matter of registering an alias. It requires understanding the internal economy of the community, its trust signals and reputation mechanics, its communication norms and linguistic registers, its operational timezone, and the psychological profile of the individuals the persona will interact with. Done without this framework, a researcher attempting infiltration will quickly signal their outsider status and be blocked, ignored, or burned.

Harper's framework is structured around five steps: identify the target, probe the target, gather information, verify and analyze it, and distribute the intelligence. The talk focuses on the probing and gathering phases, with particular attention to the question of when — not just how — to approach a target.

▶ Watch: Persona theory foundations and the infiltration framework (0:00)

The Recruitment Phase as the Optimal Entry Point

Ransomware operations are franchise businesses. The core operators develop and maintain the ransomware encryptor and supporting infrastructure; affiliates perform the actual intrusions. The affiliate relationship is structured as a revenue split — typically 70–80% to the affiliate, 20–30% to the operator — and operators compete aggressively for skilled talent. LockBit at its peak had approximately 100 affiliates. The pool of genuinely skilled operators who can execute an enterprise compromise is small, and every active RaaS platform is competing for them.

This competition creates the recruitment phase: a period during which operators post on closed forums advertising their platform, its capabilities, and their affiliate terms. Harper identifies this as the optimal time to make initial contact because operators are actively expecting cold DMs from unknown individuals. They are in selling mode. Their risk tolerance for engaging with unvetted contacts is elevated. A researcher with no established forum reputation has a plausible reason to reach out, and the operator has an incentive to respond.

Harper illustrates the recruitment phase with examples from Ramp — an exclusive Russian-Chinese cybercrime forum that requires either a financial payment or a vouching from a reputable member of a partner site such as XSS or Exploit. She shows initial offer posts from Anubis, VanHelsing, and Qilin, each advertising their locker capabilities, affiliate infrastructure, and revenue splits. VanHelsing, notably, produced an actual video recruitment commercial — a cinematic advertisement for their ransomware platform complete with dramatic music.

▶ Watch: Ransomware recruitment phase and affiliate economics (2:00)

Constructing a Credible Persona

The core challenge in persona construction is establishing credibility with minimal information disclosure. Harper describes this in terms of information economics: the goal is to transmit as few bytes as possible about the synthetic identity while extracting maximum information from the target. Every claim the persona makes is a liability — it can be checked, cross-referenced, or used to expose the researcher.

The initial message to a target group should be short. Harper describes the "no hi, no hello" culture on these forums — lengthy opening messages signal inexperience or desperation. The first contact should be brief, reference something contextually relevant (a vulnerability in the news, a named group the persona claims affiliation with), and invite the operator to respond without demanding it.

For the group Sloglav, promoted on Ramp, Harper's team opened contact by claiming prior experience with a smaller ransomware group that was in the news at the time. Leveraging a currently active group in the outreach serves a dual purpose: it is plausible (many low-level operators move between groups), and the operator may not have detailed knowledge of every affiliate in the named group. Once an initial relationship with Sloglav was established, the team used that affiliation as a credential to pivot to a more sophisticated group — APT73, also known as Bashy — claiming membership in Sloglav as a social proof mechanism while dangling attractive bait such as claimed initial access to a corporate environment.

Not every infiltration succeeds. Harper describes an attempt to contact a seller of InvaderX source code that failed because the target repeatedly requested the persona's nickname on Ramp — information that, if provided, would expose the researcher's identity to the broader forum community as a potential informant. Unable to provide the handle and unable to redirect the conversation, the team abandoned that particular approach.

▶ Watch: Building credible personas and the cold approach (6:00)

Operational Security: Timezone Shifting, Language, and Transliteration

Harper dedicates significant attention to the operational details that distinguish a sustainable infiltration from one that burns within days.

Timezone alignment is non-negotiable. Most cybercriminal operators active on Eastern European and Russian forums operate on schedules that are incompatible with a North American analyst's working hours. If a persona consistently engages only during business hours in North America, the timing pattern will eventually register as anomalous. Harper is direct: researchers doing this work have to be willing to operate at 2 AM, 3 AM, and 4 AM to match the target's active window.

Writing style is equally critical. The linguistic register of cybercrime forums is specific — a mixture of forum slang, abbreviations, and jargon that marks membership. Harper describes this with characteristic bluntness: to communicate authentically on these platforms, a persona sometimes has to write in a way that would be jarring in any professional context.

The most technically demanding linguistic element is transliteration — the practice of writing Russian words using Latin characters, phonetically. This is common on forums with mixed CIS and Western membership, and it creates a significant challenge for both human analysts and automated tools. LLMs are poorly equipped to parse transliterated Russian, which means researchers relying on automated translation pipelines may misread the intent or content of messages from targets who use this convention.

▶ Watch: Timezone operations, writing style, and transliteration (14:00)

The Fragmented Threat Landscape and Persona Geography

Harper presents data on the rapid churn in the ransomware ecosystem. From 2020 to 2024, new groups emerge every quarter in significant numbers, and many disappear within months. In the first few months of 2025 alone, she lists more than a dozen named groups — Mophia, Kraken, JDSEC, Werro, Crazyhunter, SecPo, Mamona, Run Somewhere, Skira, VanHelsing, Anubis, Nightspire — with varying survival statuses at the time of the talk.

This churn has strategic implications for persona construction. A persona that claims affiliation with a group that dissolved three months ago is immediately suspect. A persona claiming affiliation with a group that was recently in the news but is now dormant has some plausibility but also some risk of verification. The timing of persona deployment relative to the target group's lifecycle is an operational variable that requires continuous monitoring.

Geographic authenticity is another dimension. Harper presents data from the leaked Breach Forums V1 dataset (April 2022 to March 2023), analyzing the geographic distribution of last-login IP addresses. The top origins — Indonesia, United States, Hong Kong, UK, Singapore — notably exclude Russia, Ukraine, and other CIS countries despite those being the perceived home regions of many operators. Harper interprets this as evidence of data tampering, heavy VPN usage, or both, and notes that Tor ranks eighth in the dataset — lower than might be expected given the forum's nature.

For persona design, this means a North American IP address is not inherently suspicious, but a pattern of activity that looks like a nine-to-five workday in UTC-5 is.

▶ Watch: Threat landscape churn and geographic persona considerations (12:00)

Notable Quotes

"Everybody socially engineers each other. Everybody creates personas. This is nothing new. But now, how are we going to take this concept and apply it to online and creating digital personas?"

"Their receptiveness to individuals is going to be very, very high during the recruitment phase. This is the prime time to really start talking to people."

"The way I look at it is: how much data, in bytes and bits, do I send out versus how much they can give me? I want to send out as little data as possible for the maximum return."

"You have to operate on their time. You're going to have to wake up early, put in that effort, talk to people at two AM, three AM, four AM — or else if you're always operating on analyst time, your hours of operation are going to trigger red flags."

"Writing like they do sometimes means talking like a brain-dead, smooth brain NPC gooner who's been online too long. That is literally sometimes how you're going to have to type."

Key Takeaways

  • The recruitment phase is the optimal infiltration window. When RaaS operators are actively advertising for affiliates, they are maximally receptive to cold contact from unknown personas — this is the time to make an approach.
  • Information economics governs first contact. Minimize what the persona reveals while maximizing what the target discloses; short, contextually grounded opening messages outperform lengthy pitches.
  • Pivot chains extend access. Establishing credibility with a smaller group provides a usable credential for approaching more sophisticated groups, compounding intelligence access over time.
  • Timezone alignment is operationally required. Personas that operate only on analyst schedules will generate anomalous timing patterns that experienced operators will notice.
  • Transliteration is a technical and linguistic challenge. Cybercriminals from CIS regions frequently write Russian phonetically in Latin characters; standard LLM-based translation pipelines handle this poorly.
  • The threat landscape churns rapidly. Group affiliations claimed by a persona must reflect the current threat landscape — a claim referencing a defunct group will be immediately flagged.
  • A systematic framework is essential. Infiltration without clear objectives, a credible backstory, disciplined OPSEC, and a method for verifying and distributing gathered intelligence produces noise rather than actionable intelligence.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Flare threat intelligence analyst presents a systematic framework for constructing and deploying digital personas to infiltrate ransomware recruitment phases — including live chat logs from successful infiltrations of Sloglav and APT73/Bashy, OPSEC requirements for timezone shifting and transliteration, and analysis of threat landscape churn that determines persona viability.

Heather Calloway (CISO) — SOLID

Harper is documenting what successful ransomware infiltration actually looks like operationally — the timing, the linguistics, the OPSEC, the pivot chains. The talk is useful for threat intelligence teams and for understanding how the ransomware affiliate economy recruits and vets members. It doesn't speak to governance or organizational defense.

→ Top-rated talks at NorthSec 2025

All talks from NorthSec 2025