The thread: profit and statecraft are merging
Three recent cases logged on this beat describe what look like different crimes: ATM jackpotting, business email compromise, and a Russian state hacking campaign. Read together, they show a single pattern. The actors behind significant cyber attacks are converging on the same playbook, the same targets and often the same infrastructure, whether their motive is cash or espionage. For US technology companies and consumers, that convergence erodes the old assumption that financially motivated crime and nation-state operations can be defended against separately.
A malware economy with a long memory
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus, malware used to steal millions of dollars in ATM jackpotting attacks across the United States, as BleepingComputer reported. Ploutus is not a new name. Its persistence is the point. A tool built to force ATMs to dispense cash has remained viable long enough for prosecutors to pursue the person allegedly responsible for writing it. That suggests the criminal side of this beat has developed something closer to a product lifecycle than a series of one-off schemes, with code that outlives individual crews and can be reused across campaigns.
Insiders who understand the plumbing
In a separate case, two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise scams and phishing campaigns, again per BleepingComputer. BEC is the least exotic attack on this list, and that is exactly why it matters. It requires no zero-day and no novel exploit, only convincing messages and an understanding of how organizations route money and authority. The defendants' military backgrounds point to a broader hazard: the people best positioned to abuse a system's normal operation are often the ones trained to protect it. For US companies, the lesson is that the phishing threat model cannot be reduced to external strangers.
State tradecraft borrowing criminal techniques
The third case moves in the opposite direction. The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed RedFlick to deploy its signature CosmicPulse backdoor, according to BleepingComputer. Nation-state operators have long favored stealth and patience over the smash-and-grab economics of ransomware or ATM jackpotting. Yet the mechanics of establishing a foothold, delivering a payload and keeping it resident overlap heavily with what criminal crews do. When a state actor adopts a fresh installation technique, it is effectively consuming the same innovation pipeline that criminal malware developers feed.



