Bring your own binaries – Train your own Graph Neural Network for Binary Function Search
Will Lyn (Head of Cyber Intelligence · National Crime Agency)
44CON 2024 · Day 1 · Main
Overview
Will Lyn, Head of Cyber Intelligence at the National Crime Agency (NCA), delivers a compelling talk that shifts the focus from traditional law enforcement's approach to cybercrime to a more dynamic, ecosystem-centric strategy. The presentation, titled "Bring your own binaries – Train your own Graph Neural Network for Binary Function Search," despite its technical title, actually delves into the NCA's broader strategic evolution in combating serious organized cybercrime, particularly ransomware. Lyn argues that the threat landscape has transformed from distinct, siloed actor types to a blended, "spectrum" threat, where financially motivated cybercriminals often blur lines with state-sponsored activities.

Key moments
- 0:00 Introduction to the National Crime Agency (NCA) and its role
- 2:00 Shifting cyber threat landscape: from clear types to a blended spectrum
- 3:00 Ransomware: UK's most significant cyber security and crime threat
- 4:30 The cybercriminal ecosystem: like Star Wars' Cantina Bar
- 5:20 Breakdown of the cybercrime ecosystem: goods, products, and services
- 6:30 Virtual currencies and cash out: enabling the cybercrime business model
Bring your own binaries – Train your own Graph Neural Network for Binary Function Search
Speakers: Will Lyn, Head of Cyber Intelligence, National Crime Agency
Conference: 44CON
YouTube: https://www.youtube.com/watch?v=GBmlAuohHuA
Overview
Will Lyn, Head of Cyber Intelligence at the National Crime Agency (NCA), delivers a compelling talk that shifts the focus from traditional law enforcement's approach to cybercrime to a more dynamic, ecosystem-centric strategy. The presentation, titled "Bring your own binaries – Train your own Graph Neural Network for Binary Function Search," despite its technical title, actually delves into the NCA's broader strategic evolution in combating serious organized cybercrime, particularly ransomware. Lyn argues that the threat landscape has transformed from distinct, siloed actor types to a blended, "spectrum" threat, where financially motivated cybercriminals often blur lines with state-sponsored activities.
This talk is crucial for anyone involved in cybersecurity, from defenders to policymakers, as it outlines how a major law enforcement agency is adapting to an increasingly sophisticated and interconnected cybercriminal underground. Lyn introduces the concept of the "Moss Eisley Cantina Bar" to describe this burgeoning ecosystem of illicit products, goods, and services, fundamentally enabled by virtual currencies. He details the NCA's strategic shift from merely tracking individual malware variants to actively disrupting the underlying infrastructure and enablers of this ecosystem, showcasing significant successes like the LockBit takedown. The presentation not only highlights the operational victories but also candidly addresses the challenges of measuring impact in this complex domain, emphasizing the critical need for public-private sector collaboration.
Background
▶ Watch: Introduction to the National Crime Agency (NCA) and its role (0:00)
The National Crime Agency (NCA) is the UK's lead agency against serious and organized crime, with a dedicated National Cyber Crime Unit (NCCU) spearheading the national response to cybercrime. Historically, law enforcement was structured to combat geographically specific threats like drug trafficking, where the entire supply chain, from cultivation to street-level dealers, could be mapped and targeted. However, the rise of cybercrime presented a fundamentally different challenge.
Just a decade ago, the cyber threat landscape was perceived as having clear delineations: hacktivists, organized criminals, hostile state actors, and lone wolves. Cybercrime was largely financially motivated, focused on individuals through carding and banking malware, with targeting often automatic or mass-based. These "vertically integrated" crime groups, akin to traditional mafia structures, were not overly sophisticated. This changed dramatically with the advent of ransomware, which Lyn identifies as the "most significant cyber security threat to the UK" and a national security issue in its own right. Modern ransomware operations employ "automatic and big game hunting" targeting, leverage sophisticated vulnerabilities quickly (e.g., MoveIT), and even trade zero-day exploits. The clear lines have blurred, creating a "blended or spectrum type threat" where financially motivated cybercrime can often intersect with state interests, particularly with Russian-speaking groups being predominant.
The catalyst for this transformation, according to Lyn, is the emergence of a sophisticated online cybercriminal marketplace or ecosystem, which he vividly likens to the "Moss Eisley Cantina Bar" from Star Wars – a place where "you can get anything you think you might want if you're up to no good." This ecosystem is categorized by products (e.g., malware), goods (e.g., stolen credentials, data), and services (e.g., Translation-as-a-Service, Coding-as-a-Service, Infrastructure-as-a-Service, Cash-out-as-a-Service).
Crucially, virtual currencies (cryptocurrencies) are identified as the primary unlock for this ecosystem. In the past, cashing out illicit gains from banking malware or carding involved complex, risky, and costly processes like recruiting mules, purchasing physical goods, and shipping them internationally, often resulting in 60-80% profit loss. Cryptocurrencies, however, allow threat actors to receive 99.5% of their ransom payment almost instantaneously, cheaply, and with low risk, bypassing traditional banking limits and scrutiny. This ease of cash-out "blew this open," making ransomware a symptom of this online ecosystem rather than its root cause. The ecosystem significantly lowers the barrier of entry into cybercrime – no longer requiring native Russian language skills, forum status, or escrow payments – and has proliferated high-end cyber tools and capabilities to a broad audience.
Recognizing these shifts, the NCA adapted its approach. They moved away from tracking individual malware variants – a futile exercise given the proliferation from 8-12 variants to 70-80 – towards disrupting the "elements of the ecosystem that support and enable the cyber criminal business model." This new doctrine focuses on threat reduction, disruption (as arrests are often impossible due to geographical constraints, especially with Russia), demonstrating impact, and operating with pace, scale, agility, and collaboration. The challenge for law enforcement, traditionally focused on physical crime, is immense, requiring a significant cultural and mindset shift to embrace collaboration with public and private sector partners, acknowledging their superior expertise in the online domain.
Key Findings
▶ Watch: Ransomware: UK's most significant cyber security and crime threat (3:00)
The talk reveals several key findings about the evolving nature of cybercrime and law enforcement's response:
- The Cybercriminal Ecosystem as the Root Cause: Ransomware is not merely a standalone threat but a direct symptom of a highly developed online cybercriminal ecosystem. This "Moss Eisley Cantina Bar" provides readily available products (malware), goods (credentials, data), and services (CaaS, IaaS, Cash-out-as-a-Service), which significantly lower the barrier to entry for new criminals and proliferate high-end tools.
- Cryptocurrencies as the Primary Enabler: Virtual currencies have fundamentally transformed the cybercrime business model by enabling near-instant, low-cost, and high-profit cash-outs (up to 99.5% retention). This eliminated the logistical and trust challenges associated with traditional money laundering, making large-scale ransomware operations immensely profitable and scalable.
- Law Enforcement's Doctrine Shift: The NCA, recognizing the futility of tracking individual malware variants (which grew from 8-12 to 70-80), has pivoted to a strategy of disrupting the enablers within the cybercriminal ecosystem. This includes targeting infrastructure, marketplaces, and services that support criminal operations, aiming for threat reduction and disruption rather than solely arrests.
- Attribution Works and Undermines Trust: Despite the difficulty, attribution of key individuals within cybercrime groups (e.g., LockBitSupp) is effective. It associates cost and risk to the actors and, crucially, undermines trust and confidence in the ransomware-as-a-service (RaaS) platform and the broader ecosystem, leading to internal tensions and fragmentation.
- The LockBit Takedown (Operation Cronos) as a Model: The operation against LockBit, the "most prolific and harmful ransomware group in the world," demonstrated unprecedented access to their inner workings, data, and infrastructure. By repurposing LockBit's own leak site and countdown timers against them, law enforcement effectively used the adversary's tactics to publish attribution, indictments, sanctions, and technical reports, sending a clear message to affiliates.
- Criminals Lie about Data Deletion: Analysis of LockBit negotiation data revealed that, even after victims paid ransoms, the criminals frequently did not delete the stolen data, exposing victims to ongoing risk and further eroding trust within the ecosystem.
- Measuring Impact Remains Challenging: Quantifying the success of disruptions, especially in proving "the attacks that didn't happen" or accurately measuring the "cost and risk" imposed on criminals, is a significant challenge for law enforcement. This highlights the need for new metrics beyond traditional arrest and conviction rates.
- Ecosystem Fragmentation and Shifting Loci: Successful law enforcement disruptions and internal "exit scams" have led to a "post-truth era" and fragmentation within the centralized cybercriminal platforms. This results in more ransomware groups, but also a wider range of sophistication, creating internal tensions. There's also a gradual shift away from Russia as the sole locus of ransomware, with emerging threats from other jurisdictions like the Global South and Turkey (e.g., Scattered Spider).
Technical Deep Dive
▶ Watch: The cybercriminal ecosystem: like Star Wars' Cantina Bar (4:30)
The NCA's evolving counter-cybercrime doctrine is evidenced by a series of successful, collaborative operations that demonstrate a strategic shift towards disrupting the underlying infrastructure and enablers of the cybercriminal ecosystem.
One of the earliest examples of this coordinated approach was the takedown of Emotet in 2021. Emotet, a notorious malware loader, served as a precursor for numerous other threats. This operation, reportedly led by German authorities, effectively neutralized a significant entry point for various cybercriminal activities.
Following this, Operation Hive in January 2023 marked a major disruption against the Hive ransomware group. The FBI successfully infiltrated Hive's infrastructure, gaining access to decryption keys. This allowed the NCA and international partners to provide decryption keys to over 1,500 victims they were aware of, a crucial step in mitigating the impact of ransomware attacks. The operation culminated in a public takedown, complete with splash pages featuring various law enforcement emblems.
The NCA also pioneered the use of sanctions as a tool against cybercriminals. In 2021-2022, working with US partners, the UK utilized its sanctions regime for the first time to attribute and target key members of the Trickbot, Conti, and Ryuk ransomware groups, which were prominent at the time. This demonstrated the power of non-traditional enforcement mechanisms in raising the cost and risk for threat actors.
Further amplifying their strategy, Operation Cookie Monster in April 2023 targeted Genesis Market, one of the largest initial access marketplaces. Genesis facilitated the sale of credentials for a vast array of online accounts, from low-level consumer accounts (Netflix, sports channels) to sophisticated corporate credentials that served as vectors for ransomware operations. This international effort significantly disrupted a critical component of the cybercriminal supply chain.
The disruption of QakBot (also known as Qbot) in August 2023 further showcased the impact of infrastructure-focused operations. QakBot, a long-standing banking Trojan and botnet, had infected approximately 750,000 victims worldwide. The coordinated effort successfully disrupted its command-and-control infrastructure, limiting its ability to spread and facilitate further attacks.
Most recently, Operation Endgame in May 2024 represented the "largest ever coordinated operation against botnets." This Euro-coordinated disruption targeted over 100 different pieces of infrastructure associated with several common botnets, including IcedID, Bumblebee, and SmokeLoader. The NCA played a direct role in tackling infrastructure located within the UK.
However, the pinnacle of the NCA's new doctrine is undoubtedly the takedown of LockBit, an operation that began to materialize in 2023 and culminated in Operation Cronos in February 2024. LockBit was described as the "most prolific and most harmful ransomware group in the world," responsible for thousands of victims. The NCA gained unprecedented access to "all the LockBit data" – a "treasure trove" encompassing the group's inner workings, data, and infrastructure. This included information on approximately 200 affiliates, their builds and attacks, stolen data, negotiation logs, and crypto wallets.
The core objectives of Operation Cronos were not just technical disruption but also to associate cost and risk to the threat actors and undermine trust and confidence in the LockBit RaaS platform and the broader ransomware ecosystem. To achieve this, the NCA employed a highly innovative tactic: they used LockBit's own infrastructure and methods against them. LockBit famously utilized countdown timers on their leak site to pressure victims into paying ransoms. Law enforcement took control of the leak site, replaced the victim tiles with information about the takedown, and displayed their own countdown timer.
During this period, the repurposed leak site became a platform for law enforcement to publish:
- Press releases detailing the operation.
- Attributions of individuals involved, including the administrator, LockBitSupp. Lyn described LockBitSupp as a character who "loves his guns, he loves getting in the gym," contrasting him with the "classic Russian moneyed Bad Boys" like the Evil Corp members who flaunt lavish lifestyles. This detail underscores the diverse motivations and profiles within the cybercriminal underworld.
- Technical reports.
- Indictments.
- Sanctions.
- Details of arrest activity in Poland and Ukraine.
- Information about a potential decryptor key developed by Japanese law enforcement.
Furthermore, the NCA leveraged its access to send direct messages to LockBit affiliates attempting to log into their panels. Gavin, a lead on the operation, famously crafted the message: "Thanks to LockBitSupp and all of your friends... the NCA and our International Partners have taken over this infrastructure. You will be hearing from us very soon. Have a nice day." This vindictive message was a direct psychological blow aimed at disrupting the affiliates' operations and sowing distrust. The data acquired from LockBit also provided crucial insights, such as the fact that criminals often lied about deleting victim data even after ransom payments were made.
The LockBit operation is ongoing, with the NCA operationalizing the vast amount of data acquired. While LockBit has attempted to rebuild, the NCA believes the threat posed by the group has "decreased really significantly," with many affiliates having left.
Demo / Proof of Concept
▶ Watch: Breakdown of the cybercrime ecosystem: goods, products, and services (5:20)
While the talk did not feature a live, interactive demonstration or a traditional proof of concept in the technical sense, the entire presentation serves as an extensive account of real-world "proofs of concept" in the form of successful law enforcement operations. The detailed recounting of takedowns like Emotet, Hive, Genesis Market, QakBot, Operation Endgame, and most notably, the LockBit disruption (Operation Cronos), illustrates how the NCA's evolving doctrine translates into tangible outcomes. Each operation, with its specific tactics, collaborative efforts, and measurable impacts (like victim decryption or infrastructure seizure), demonstrates the practical application of their strategy to disrupt the cybercriminal ecosystem.
Defensive Implications
▶ Watch: Virtual currencies and cash out: enabling the cybercrime business model (6:30)
The NCA's insights offer critical implications for cybersecurity defenders across all sectors:
- Report Incidents – It Matters: The most significant defensive implication is the urgent plea for victims to report ransomware incidents to law enforcement and agencies like the NCSC. Lyn uses a compelling analogy of reporting a stolen bike: while individual recovery might be low, collective reporting helps identify "hot spots" and enables law enforcement to understand the threat landscape, allocate resources effectively, and launch targeted interventions. Without this intelligence, agencies operate in the dark, unable to prioritize which of the 70-80 active ransomware variants to pursue. The NCSC portal can signpost victims to appropriate support.
- Don't Trust Criminals, Even After Payment: The LockBit takedown explicitly revealed that ransomware groups frequently lie about deleting stolen data even after victims pay the ransom. This reinforces the long-held advice that paying a ransom offers no guarantee of data integrity or confidentiality, and often funds future criminal activities. Defenders should never assume data is gone post-payment and must continue with their own recovery and security measures.
- Understand the Ecosystem, Not Just the Malware: Defenders must shift their perspective from viewing individual malware variants as isolated threats to understanding them as symptoms of a broader, interconnected cybercriminal ecosystem. This means focusing defensive efforts on disrupting the supply chain of products, goods, and services that enable these attacks, and understanding the financial mechanisms (cryptocurrencies) that fuel them.
- Embrace Public-Private Collaboration: The NCA explicitly acknowledges that law enforcement cannot tackle cybercrime alone and relies heavily on the "amazing expertise and capability and knowledge" within the private sector. Defenders should actively seek opportunities for collaboration, intelligence sharing, and partnership with agencies like the NCA and NCSC. This symbiotic relationship is crucial for building a comprehensive defense.
- Be Aware of Shifting Threat Landscapes: The fragmentation of the cybercriminal ecosystem and the gradual geographic shift away from Russia as the sole locus of ransomware (e.g., Scattered Spider from other jurisdictions) means defenders must remain agile in their threat intelligence. New groups, potentially with varying levels of sophistication, will emerge from diverse regions, requiring continuous adaptation of defensive strategies.
- Focus on Resilience and Recovery: Given the high sophistication and proliferation of tools within the ecosystem, complete prevention of attacks is increasingly difficult. Defenders should prioritize cyber resilience, robust backup strategies, incident response planning, and efficient recovery capabilities to minimize the impact of successful breaches.
Key Takeaways
- Cybercrime is an Evolving Ecosystem: Modern cybercrime, particularly ransomware, is a symptom of a sophisticated, interconnected online ecosystem offering products, goods, and services, rather than isolated criminal groups.
- Cryptocurrencies are a Game-Changer: Virtual currencies fundamentally unlocked and scaled the cybercrime business model by enabling low-risk, high-profit, and instantaneous cash-outs, eliminating traditional limitations.
- Law Enforcement's Strategic Pivot: Agencies like the NCA have moved from tracking individual malware variants to disrupting the foundational enablers and infrastructure of the cybercriminal ecosystem.
- Targeted Disruption and Attribution Work: Operations like the LockBit takedown demonstrate that unprecedented access, strategic use of an adversary's own tactics, and public attribution can significantly disrupt major RaaS groups and undermine trust.
- Measuring Impact Remains a Challenge: Quantifying the success of disruptions, especially proving negative outcomes (attacks prevented) and assessing the psychological impact on criminals, requires new and innovative measurement methodologies.
- Collaboration is Paramount: Effective defense against global cyber threats necessitates strong, continuous collaboration and intelligence sharing between law enforcement and the private sector.
- Report Incidents for Collective Defense: Reporting cybercrime incidents, even seemingly minor ones, provides crucial intelligence that enables law enforcement to understand the threat landscape and focus resources effectively.
About the Speaker(s)
Will Lyn (who clarifies his surname is "line," not "Lym") is the Head of Cyber Intelligence at the National Crime Agency (NCA), the UK's lead agency against serious and organized crime. With a career spanning approximately 15 years in law enforcement and a decade specifically focused on cyber, Lyn brings a wealth of experience to his role.
His background includes diverse assignments, such as serving as a liaison officer in Afghanistan for two years and running investigation teams within the NCA's National Cyber Crime Unit (NCCU). Prior to his current position, he spent five years as the NCA's embed to the FBI Cyber Division in Washington D.C., an experience he describes as "really great and interesting," notably coinciding with the Donald Trump presidency.
Lyn oversees the NCA's cyber intelligence function, which is critical to understanding the serious organized crime threat to the UK. He emphasizes that the NCA, with approximately 250-260 staff predominantly based in London, Birmingham, and the Northwest, is focused on cyber-dependent crime. His insights reflect the agency's evolving strategy to combat complex, online threats that defy traditional law enforcement approaches, highlighting the critical importance of international and public-private sector collaboration.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Lyn is a credible NCA insider delivering a genuinely useful strategic briefing on how UK law enforcement has adapted its doctrine to target the ransomware ecosystem rather than individual variants. The LockBit/Operation Cronos material carries real signal value, but the talk reads more like an informed practitioner overview than something that would surprise a seasoned threat intel or IR professional. Worth the slot at 44CON; won't be the talk people quote in six months.
Heather Calloway (CISO) — SOLID
Will Lyn delivers a clear and credible account of how law enforcement has evolved its doctrine against ransomware, with Operation Cronos as the centerpiece. The strategic framing — ecosystem disruption over variant tracking — is genuinely useful for security leaders, but the talk stops short of telling the private sector audience what, specifically, they should change about how they operate.