Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Downloading cracked software.

    David Liebenberg from Cisco Talos joins to discussing Talos' discovery of cracked Microsoft Windows software being downloaded by enterprise users across the globe. Downloading and running this compromised software not only serves as an entry point for threat actors, but can serve as a gateway to access control systems and establish backdoors.

    Talos identified additional malware, including RATs, on endpoints running this cracked software, which allows an attacker to gain unauthorized remote access to the compromised system, providing the attacker with various capabilities, such as controlling the system, capturing screenshots, recording keystrokes and exfiltrating sensitive information.

    This research article was not published by Cisco Talos' team.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    18 min
  • Behind the Google shopping ad masks.

    Maxim Zavodchik from Akamai joins Dave to discuss their research on "Xurum: New Magento Campaign Discovered." Akamai researchers have discovered an ongoing server-side template injection campaign that is exploiting digital commerce websites. This campaign targets Magento 2 shops, and was dubbed Xurum in reference to the domain name of the attacker’s command and control (C2) server. 

    The research states "The attacker uses an advanced web shell named “wso-ng” that is activated only when the attacker sends the cookie “magemojo000” to the backdoor “GoogleShoppingAds” component."

    The research can be found here:

    • Xurum: New Magento Campaign Discovered

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    15 min
  • A look into the emotions and anxieties of the highest levels of decision-making.

    Guest Manuel Hepfer from ISTARI shares his research on cyber resilience which includes discussions with 37 CEOs to gain insight into how they manage cybersecurity risk. ISTARI and Oxford University's Saïd Business School dive into the minds and experiences of CEOs on how they manage cybersecurity risk.

    Ask any CEO to name the issues that keep them awake at night and cybersecurity risk is likely near the top of the list – with good reason. With the accelerating digitalisation of business models comes vulnerability to cyberattack. And while spending on cybersecurity increases every year, so does the number of serious incidents. Even the largest and most technologically advanced companies are not immune.

    CEOs must formally answer to regulators, shareholders and board members for their organisation’s cybersecurity. Yet the majority (72%) of CEOs we interviewed as part of our research said they were not comfortable making cybersecurity-related decisions.

    The research and associated article can be found here:

    • Research: The CEO Report on Cyber Resilience
    • Article: Make Cybersecurity a Strategic Asset
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      41 min
    • No honor in being a criminal.

      This week, our guest is Reece Baldwin from Kasada discussing their work on "No Honour Amongst Thieves: Unpacking a New OpenBullet Malware Campaign." The Kasada Threat Intelligence team has recently identified a malware campaign targeting users of OpenBullet, a tool popular within criminal communities to conduct credential stuffing attacks.

      This malware campaign was first uncovered when the team was digging around in a Telegram channel setup to share OpenBullet configurations. Reading through a few of the configurations they identified a function, ostensibly designed to bypass Google’s reCAPTCHA anti-bot solution. Th research states "While the versatility of OpenBullet’s configuration files enable complex attacks, they can also make it difficult for inexperienced attackers to fully understand what requests are being created and what data is being retrieved."

      The research can be found here:

      • No Honour Amongst Thieves: Unpacking a New OpenBullet Malware Campaign

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      18 min
    • Thwarting Muddled Libra.

      Kristopher Russo and Stephanie Regan from Palo Alto Networks Unit 42 join Dave to talk about Threat Group Assessment: Muddled Libra. With an intimate knowledge of enterprise information technology, this threat group presents a significant risk even to organizations with well-developed legacy cyber defenses.

      Posing threats to organizations in the software automation, BPO, telecommunications and technology industries, Muddled Libra is a threat group that favors targeting large outsourcing firms serving high-value cryptocurrency institutions and individuals.

      The research can be found here:

      • Threat Group Assessment: Muddled Libra

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      31 min
    • Google's not being ghosted from vulnerabilities.

      Tal Skverer from Astrix Security joins to discuss their work on "GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts." Astrix’s Security Research Group revealed a 0-day flaw in Google’s Cloud Platform (GCP) on June 19, 2022, which was found to affect all Google users.

      The research states "The vulnerability, dubbed “GhostToken”, could allow threat actors to change a malicious application to be invisible and unremovable, effectively leaving the victim’s Google account infected with a trojan app forever." Google issued a patch to this vulnerability in April of this year, but researchers explain why this can be severe.

      The research can be found here:

      • GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      18 min
    • Politicians targeted by RomCom.

      Dmitry Bestuzhev from Blackberry joins to discuss their work on "RomCom Resurfaces: Targeting Politicians in Ukraine and U.S.-Based Healthcare Providing Aid to Refugees from Ukraine." Research suggests that the RomCom threat team has been tracked carefully following the geopolitical events surrounding the war in Ukraine, and are now targeting politicians in Ukraine who are working closely with Western countries.

      This group is different from others in that their focus is more on secrets or information which can be useful in geopolitics and specifically the war in Ukraine, instead of financial gain. The research says "Although it is unclear at this point what initial infection vector was used to kick off the execution chain, previous RomCom attacks used targeted phishing emails to point a victim to a cloned website hosting Trojanized versions of popular software."

      The research can be found here:

      • RomCom Resurfaces: Targeting Politicians in Ukraine and U.S.-Based Healthcare Providing Aid to Refugees from Ukraine

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      23 min
    • It's raining credentials.

      Alex Delamotte from SentinelLabs joins Dave to discuss their work on "Cloudy With a Chance of Credentials | AWS-Targeting Cred Stealer Expands to Azure, GCP." As actors find more ways to profit from compromising services, SentinelLabs finds that cloud service credentials are becoming increasingly targeted.

      The lack of threats explicitly targeting Azure and GCP credentials up to this point means there are likely many fresh targets. The research states "These campaigns share similarity with tools attributed to the notorious TeamTNT cryptojacking crew. However, attribution remains challenging with script-based tools, as anyone can adapt the code for their own use."

      The research can be found here:

      • Cloudy With a Chance of Credentials | AWS-Targeting Cred Stealer Expands to Azure, GCP

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      19 min
    • Who is that stealing my credentials?

      Aleksandar Milenkoski from SentinelOne joins to discuss their work on "Kimsuky Strikes Again | New Social Engineering Campaign Aims to Steal Credentials and Gather Strategic Intelligence." Researchers have been tracking the North Korean APT group Kimsuky and their attempt at a social engineering campaign targeting experts in North Korean affairs.

      The research states "The campaign has the objective of stealing Google and subscription credentials of a reputable news and analysis service focusing on North Korea, as well as delivering reconnaissance malware." Kimsuky has been tracked engaging in extensive email correspondence using spoofed URLs and extensive email correspondence, along with Office documents weaponized with the ReconShark malware.

      The research can be found here:

      • Kimsuky Strikes Again | New Social Engineering Campaign Aims to Steal Credentials and Gather Strategic Intelligence

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      17 min
    • Phishing for leeches.

      Ashlee Benge from ReversingLabs discussing their research titled "Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks." Researchers recently discovered over a dozen malicious packages published to the npm open source repository. These packages are targeting Microsoft 365 users and appear to target application end users while also supporting email phishing campaigns.

      Research supports that the malicious campaign encompassed more than a dozen files designed to steal sensitive user credentials. The research states "This most recent campaign caught our attention because of a number of features and characteristics in related npm packages that correlate with malicious intent."

      The research can be found here:

      • Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min

    About Research Saturday

    From the publisher's feed

    Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

    More shows like Research Saturday

    Risky Business by Risky Business Media

    Risky Business

    375 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,028 Listeners

    ChinaPower by CSIS | Center for Strategic and International Studies

    ChinaPower

    206 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    317 Listeners

    Click Here by Recorded Future News

    Click Here

    420 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,058 Listeners

    Cybersecurity Today by David Shipley

    Cybersecurity Today

    179 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    314 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    191 Listeners

    Career Notes by N2K Networks

    Career Notes

    14 Listeners

    Pekingology by Center for Strategic and International Studies

    Pekingology

    141 Listeners

    Cybersecurity Headlines by CISO Series

    Cybersecurity Headlines

    138 Listeners

    The AI Fix by Mark Stockley

    The AI Fix

    32 Listeners

    The FAIK Files by Perry Carpenter | N2K Networks

    The FAIK Files

    18 Listeners