Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Encore: Welcome to New York, it's been waitin' for you.

    Joshua Miller from Proofpoint joins Dave to discuss findings on "Welcome to New York: Exploring TA453's Foray into LNKs and Mac Malware." In mid May, TA453, also known as Charming Kitten, APT42, Mint Sandstorm, and Yellow Garuda, was found sending a benign conversation lure masquerading as a senior fellow with the Royal United Services Institute (RUSI) to the public media contact for a nuclear security expert at a US-based think tank focused on foreign affairs.

    The research states that "the email solicited feedback on a project called “Iran in the Global Security Context” and requested permission to send a draft for review." Proofpoint shares it's findings and what you can expect from the threat group.

    The research can be found here:

    • Welcome to New York: Exploring TA453's Foray into LNKs and Mac Malware

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    19 min
  • APT36's cyber blitz on India.

    Ismael Valenzuela, Vice President Threat Research & Intelligence, from Blackberry Threat Research and Intelligence team is discussing their work on "Transparent Tribe Targets Indian Government, Defense, and Aerospace Sectors Leveraging Cross-Platform Programming Languages." BlackBerry has identified Transparent Tribe (APT36), a Pakistani-based advanced persistent threat group, targeting India's government, defense, and aerospace sectors from late 2023 to April 2024, using evolving toolkits and exploiting web services like Telegram and Google Drive.

    Evidence such as time zone settings and spear-phishing emails with Pakistani IP addresses supports their attribution, suggesting alignment with Pakistan's interests.

    The research can be found here:

    • Transparent Tribe Targets Indian Government, Defense, and Aerospace Sectors Leveraging Cross-Platform Programming Languages

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    19 min
  • Piercing the through the fog.

    Kerri Shafer-Page from Arctic Wolf joins us to discuss their work on "Lost in the Fog: A New Ransomware Threat." Starting in early May, Arctic Wolf's Incident Response team investigated Fog ransomware attacks on US education and recreation sectors, where attackers exploited compromised VPN credentials to access systems, disable Windows Defender, encrypt files, and delete backups.

    Despite the uniformity in ransomware payloads and ransom notes, the organizational structure of the responsible groups remains unknown.

    The research can be found here:

    • Lost in the Fog: A New Ransomware Threat

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    17 min
  • Exploring the mechanics of Infostealer malware.

    This week, we are joined by a Security Researcher from SpyCloud Labs, James, who is discussing their work on "Unpacking Infostealer Malware: What we’ve learned from reverse engineering LummaC2 and Atomic macOS Stealer." Infostealer malware has become highly prevalent, with SpyCloud tracking over 50 families and finding that 1 in 5 digital identities are at risk.

    This research analyzes the workings and intentions behind infostealers like LummaC2 and Atomic macOS Stealer, focusing on the types of data extracted and the broader security implications.

    The research can be found here:

    • Reversing LummaC2 4.0: Updates, Bug Fixes
    • Reversing Atomic macOS Stealer: Binaries, Backdoors & Browser Theft
    • How the Threat Actors at SpaxMedia Distribute Malware Globally
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      27 min
    • Riding the hype for new Arc browser.

      Jérôme Segura, Senior Director of Threat Intelligence at Malwarebytes, is discussing their work on "Threat actors ride the hype for newly released Arc browser." The Arc browser, newly released for Windows, has quickly garnered positive reviews but has also attracted cybercriminals who are using deceptive Google search ads to distribute malware disguised as the browser.

      These malicious campaigns exploit the hype around Arc, using techniques like embedding malware in image files and utilizing the MEGA cloud platform for command and control, highlighting the need for caution with sponsored search results and the effectiveness of Endpoint Detection and Response (EDR) systems.

      The research can be found here:

      • Threat actors ride the hype for newly released Arc browser

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      26 min
    • 1700 IPs and counting.

      Amit Malik, Director of Threat Research at Uptycs, is sharing their work on "New Threat Detected: Inside Our Discovery of the Log4j Campaign and Its XMRig Malware." The Uptycs Threat Research Team has discovered a large-scale Log4j campaign involving over 1700 IPs, aiming to deploy XMRig cryptominer malware.

      This ongoing operation was initially detected through the team's honeypot collection, prompting an in-depth analysis of the campaign. The research says "The JNDI plugin is particularly useful to attackers because it allows them not only to fetch the values of environment variables in the target system but also to freely define the URL and protocol resource for the JNDI network connection."

      The research can be found here:

      • New Threat Detected: Inside Our Discovery of the Log4j Campaign and Its XMRig Malware

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      16 min
    • International effort dismantles LockBit.

      Jon DiMaggio, a Chief Security Strategist at Analyst1, is sharing his work on "Ransomware Diaries Volume 5: Unmasking LockBit." On February 19, 2024, the National Crime Agency (NCA), a UK sovereign law enforcement agency, in collaboration with the FBI, Europol, and nine other countries under "Operation Cronos," disrupted the LockBit ransomware gang’s data leak site used for shaming, extorting, and leaking victim data.

      The NCA greeted visitors to LockBit’s dark web leak site with a seizure banner, revealing they had been controlling LockBit’s infrastructure for some time, collecting information, acquiring victim decryption keys, and even compromising the new ransomware payload intended for LockBit 4.0.

      The research can be found here:

      • Ransomware Diaries Volume 5: Unmasking LockBit

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      29 min
    • From secret images to encryption keys.

      This week, we are joined by Hosein Yavarzadeh from the University of California San Diego, as he is discussing his work on "Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch Predictor" This paper introduces new methods that let attackers read from and write to specific parts of high-performance CPUs, such as the path history register (PHR) and prediction history tables (PHTs).

      These methods allow two main types of attacks. One can reveal a program's control flow history, as shown by recovering a secret image through the libjpeg routines. The other enables detailed transient attacks, demonstrated by extracting an AES encryption key, highlighting significant security risks for these systems.

      The research can be found here:

      • Graph: Growing number of threats leveraging Microsoft API

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      21 min
    • The double-edged sword of cyber espionage.

      Dick O'Brien from Symantec Threat Hunter team is discussing their research on “Graph: Growing number of threats leveraging Microsoft API.” The team observed an increasing number of threats that have begun to leverage the Microsoft Graph API, usually to facilitate communications with command-and-control (C&C) infrastructure hosted on Microsoft cloud services.

      The research states "the technique was most recently used in an attack against an organization in Ukraine, where a previously undocumented piece of malware used the Graph API to leverage Microsoft OneDrive for C&C purposes."

      The research can be found here:

      • Graph: Growing number of threats leveraging Microsoft API

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      19 min
    • Geopolitical tensions rise with China.

      Adam Marré, CISO at Arctic Wolf, is diving deep into geopolitical tension with China including APT31, iSoon and TikTok with Dave this week. They also discuss some of the history behind China cyber operations.

      Adam shares information on how different APT groups are able to create spear phishing campaigns, and provides info on how to combat these groups.

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      34 min

    About Research Saturday

    From the publisher's feed

    Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

    More shows like Research Saturday

    Risky Business by Risky Business Media

    Risky Business

    374 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,027 Listeners

    ChinaPower by CSIS | Center for Strategic and International Studies

    ChinaPower

    206 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    317 Listeners

    Click Here by Recorded Future News

    Click Here

    420 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,055 Listeners

    Cybersecurity Today by David Shipley

    Cybersecurity Today

    179 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    314 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    191 Listeners

    Career Notes by N2K Networks

    Career Notes

    14 Listeners

    Pekingology by Center for Strategic and International Studies

    Pekingology

    140 Listeners

    Cybersecurity Headlines by CISO Series

    Cybersecurity Headlines

    138 Listeners

    The AI Fix by Mark Stockley

    The AI Fix

    32 Listeners

    The FAIK Files by Perry Carpenter | N2K Networks

    The FAIK Files

    18 Listeners