Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Play to win, pay to lose.

    Today we are joined by Jean-Pierre Mouton, Senior Threat Intelligence Consultant at GuidePoint Security, discussing their work on "How Play Achieves Encryption." Play ransomware, also known as PlayCrypt, continues to target organizations across multiple sectors using a consistent double-extortion playbook that combines data theft with widespread encryption. A recent investigation details how the group gained access through a SonicWall VPN, moved laterally using tools such as Mimikatz and PsExec, exfiltrated sensitive data, and used the victim’s own SentinelOne uninstallation utility to disable endpoint protection. The findings highlight several behavioral indicators defenders can monitor, including tool staging through SYSVOL and SystemBC for command and control, event log clearing, and suspicious WinSCP activity.

    The research and executive brief can be found here:

    • ⁠⁠⁠⁠How Play Achieves Encryption
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • An apple a day, a phish away.

      Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-a-Service platform designed to steal Apple credentials and disable Activation Lock on stolen devices.

      The platform uses email, SMS, WhatsApp, and AI-driven voice calls to impersonate Apple Support, with researchers uncovering a broader ecosystem spanning 506 domains, 168 storefront brands, and 30 backend installations. Despite its sophisticated social-engineering capabilities, basic coding flaws exposed extensive operational logs and revealed the shared infrastructure, developer activity, and reseller network behind the criminal operation.

      The research and executive brief can be found here:

      • ⁠Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        25 min
      • All about that proxy.

        Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes.

        Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign.

        The research and executive brief can be found here:

        • Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims
        • Learn more about your ad choices. Visit megaphone.fm/adchoices

          26 min
        • A beast by any other name.

          Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses.

          In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities.

          The research and executive brief can be found here:

          • ⁠⁠⁠⁠GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
          • Learn more about your ad choices. Visit megaphone.fm/adchoices

            24 min
          • RMM-ber this ransomware.

            Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access.

            Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution.


            The research and executive brief can be found here:

            • ⁠From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks
            • Learn more about your ad choices. Visit megaphone.fm/adchoices

              20 min
            • Who let the AI hack?

              Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool.

              The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities.

              The research and executive brief can be found here:

              • LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools
              • Learn more about your ad choices. Visit megaphone.fm/adchoices

                24 min
              • A RAT in the spreadsheet.

                Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests.

                The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access.

                The research and executive brief can be found here:

                • ⁠Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation
                • Learn more about your ad choices. Visit megaphone.fm/adchoices

                  30 min
                • The botnet that scouts before it strikes.

                  Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices.

                  The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation.

                  The research and executive brief can be found here:

                  • Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation
                  • Learn more about your ad choices. Visit megaphone.fm/adchoices

                    28 min
                  • A little help from your search engine.

                    Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command.

                    The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised.

                    The research and executive brief can be found here:

                    • Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer
                    • Learn more about your ad choices. Visit megaphone.fm/adchoices

                      20 min
                    • The driver's seat to ransomware.

                      This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks.

                      The research and executive brief can be found here:

                      • Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs
                      • Learn more about your ad choices. Visit megaphone.fm/adchoices

                        24 min

                      About Research Saturday

                      From the publisher's feed

                      Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

                      More shows like Research Saturday

                      Risky Business by Risky Business Media

                      Risky Business

                      374 Listeners

                      CyberWire Daily by N2K Networks

                      CyberWire Daily

                      1,027 Listeners

                      ChinaPower by CSIS | Center for Strategic and International Studies

                      ChinaPower

                      206 Listeners

                      Smashing Security by Graham Cluley

                      Smashing Security

                      317 Listeners

                      Click Here by Recorded Future News

                      Click Here

                      420 Listeners

                      Darknet Diaries by Jack Rhysider

                      Darknet Diaries

                      8,055 Listeners

                      Cybersecurity Today by David Shipley

                      Cybersecurity Today

                      179 Listeners

                      Hacking Humans by N2K Networks

                      Hacking Humans

                      314 Listeners

                      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                      CISO Series Podcast

                      191 Listeners

                      Career Notes by N2K Networks

                      Career Notes

                      14 Listeners

                      Pekingology by Center for Strategic and International Studies

                      Pekingology

                      140 Listeners

                      Cybersecurity Headlines by CISO Series

                      Cybersecurity Headlines

                      138 Listeners

                      The AI Fix by Mark Stockley

                      The AI Fix

                      32 Listeners

                      The FAIK Files by Perry Carpenter | N2K Networks

                      The FAIK Files

                      18 Listeners